Max-severity Exchange server flaw under active exploitation by Kremlin hackers

← Back to the feed

Max-severity Exchange server flaw under active exploitation by Kremlin hackers

Ars Technica · 19 hours ago

Russian state-linked group TA488 is actively exploiting a maximum-severity Microsoft Exchange Server vulnerability to compromise unpatched Outlook Web Access accounts. The flaw allows an attack to begin when a recipient merely opens a malicious email, enabling the group to install a persistent backdoor and steal credentials and confidential information.

The vulnerability, CVE-2026-42897, is an HTML-filtering cross-site scripting flaw that Microsoft advised customers to mitigate in May and patched in July. Proofpoint says the attackers’ OWAReaper implant can hide its activity, capture browser-autofilled credentials and potentially steal OAuth tokens to access other authenticated mailboxes; removing it requires deliberate server-side action, not simply resetting credentials or rebuilding a user’s device.

  • Kremlin-linked hackers exploit a critical Exchange Server flaw.
  • Opening a malicious email can trigger compromise.
  • Server-side backdoor may survive device rebuilding.

Cybersecurity Technology

Read the full article at the source →