CVE-2026-42897 is a Microsoft Exchange OWA cross-site scripting vulnerability reportedly exploited as a zero-day.
Proofpoint attributes the activity to Laundry Bear (Void Blizzard/TA488).
The campaign delivers OWAReaper, a browser-executed webmail backdoor.
Reported capabilities include OAuth token theft, mailbox permission abuse, and persistent mailbox access.
Remediation should extend beyond patching to include mailbox, token, and permission reviews.
CVE-2026-42897 is drawing attention because it affects Microsoft Exchange Outlook Web Access (OWA), a widely used enterprise webmail interface.
According to Proofpoint and reporting from BleepingComputer, the Russian state-sponsored threat group Laundry Bear, tracked by Microsoft as Void Blizzard and by Proofpoint as TA488, is exploiting the vulnerability to deploy OWAReaper, a browser-based backdoor designed to establish persistent access to Exchange mailboxes.
Proofpoint’s analysis indicates that OWAReaper combines mailbox permission abuse, OAuth token theft, and server-side persistence techniques that may allow access to survive password resets or endpoint replacement if the mailbox itself is not fully remediated. Organisations should independently verify whether these mechanisms were used in their own environments.
CVE-2026-42897 affects Microsoft Exchange Outlook Web Access (OWA) and is exploited within an authenticated user’s webmail session.
Proofpoint describes the vulnerability as a cross-site scripting (XSS) flaw that executes attacker-controlled JavaScript when a victim opens a specially crafted email in Outlook Web Access. Proofpoint describes the attack as a half-click exploit because the victim only needs to open the malicious email in Outlook Web Access for the JavaScript to execute.
Once the code executes within the user’s authenticated OWA session, attackers can interact with mailbox resources using the victim’s existing privileges.
How OWAReaper extends access beyond the Initial Exploit
Public reporting indicates that the exploit chain is designed to minimise visible indicators while establishing longer-term access. After execution inside the OWA reading pane, OWAReaper reportedly:
Removes exploit content from the message stored on the Exchange server.
Collects mailbox and account information.
Attempts credential theft using hidden browser DOM elements.
Obtains OAuth tokens through Outlook add-ins granted ReadWriteMailbox permissions.
Modifies mailbox folder permissions by assigning Owner access to the Default user.
Receives commands through GitHub commit messages and specially formatted emails.
Falls back to DNS-based exfiltration if HTTPS communication is unavailable.
Proofpoint attributes these behaviours to OWAReaper. Public reporting has not indicated that every observed compromise necessarily includes all of these capabilities.
Operational Snapshot
Observed activity
Why it matters
Priority
Browser-based JavaScript execution
Runs inside authenticated OWA sessions
High
Attempts to obtain OAuth tokens through Outlook add-ins
May allow continued access after password changes
High
Mailbox permission changes
Can create long-term mailbox persistence
High
Removal of exploit artefacts
Makes incident investigation more difficult
Medium
HTTPS with DNS fallback
Multiple potential data exfiltration channels
Medium
Why password resets may not fully remove access
One of the key reported characteristics of the campaign is its ability to establish mailbox persistence beyond credential theft.
According to Proofpoint’s analysis, attackers may establish continued access by modifying mailbox permissions and obtaining OAuth tokens through Outlook add-ins with ReadWriteMailbox permissions. If these mechanisms remain active, simply rotating passwords or rebuilding affected endpoints may not remove every avenue of access.
Rather than relying on credential resets alone, organisations should verify whether any persistence mechanisms remain in place by reviewing:
Mailbox folder permissions for unexpected Owner-level assignments.
Outlook add-ins with ReadWriteMailbox permissions.
Active OAuth authorisations associated with affected accounts.
Evidence of unauthorised mailbox changes following the suspected compromise.
Whether persistence exists in a particular environment depends on what actions were successfully completed during the compromise.
Top 10 Cybersecurity Challenges for Enterprises
Navigate enterprise cybersecurity challenges with practical strategies for resilience today.
What security teams should verify
Applying Microsoft’s security updates should be the starting point rather than the end of the response. Security teams should consider reviewing:
Verify that affected Exchange servers are patched for CVE-2026-42897 and review endpoint patch hygiene to ensure managed devices are running current security updates.
OAuth applications and Outlook add-ins with ReadWriteMailbox permissions.
Exchange and OWA logs for suspicious mailbox activity.
Indicators of unusual outbound HTTPS or DNS communications associated with suspected compromised OWA sessions or affected endpoints.
The appropriate scope of investigation should be based on each organisation’s exposure and available forensic evidence.
How Hexnode supports enterprise response
Vendor remediation and Exchange-specific investigation remain the primary response to CVE-2026-42897. Endpoint management and visibility can complement those activities by helping organisations maintain control over managed devices that access Exchange services.
Hexnode XDR can support investigations on managed Windows endpoints by helping security teams:
Review endpoint incidents and device posture.
Review supported remote response actions available for managed Windows devices.
Review endpoint incidents, device posture, and endpoint events to support broader security investigations.
Correlate endpoint events with broader security investigations.
Hexnode UEM complements these efforts by helping administrators:
Enforce device compliance and restrict access to corporate resources from trusted, managed endpoints.
Apply endpoint security configurations and hardening policies.
Manage trusted corporate devices remotely.
Enforce browser management policies and web filtering to restrict unauthorized browser extensions and enforce secure browsing configurations across endpoints.
These capabilities support broader incident response efforts alongside Exchange remediation, mailbox auditing, and identity reviews.
Featured resource
The Cybersecurity Blueprint
Learn how to adopt the right cybersecurity strategy with practical frameworks, implementation guidance for enterprises.
Does resetting a user’s password remove OWAReaper access?
Not necessarily. If mailbox permissions were modified or OAuth tokens were obtained through malicious Outlook add-ins, additional remediation may be required alongside a password reset.
Should organisations review Outlook add-ins after an incident?
Yes. Review installed Outlook add-ins and any granted ReadWriteMailbox permissions for unexpected or unauthorised access.
Are Exchange servers the only systems that should be investigated?
No. Incident response should also include affected user accounts, mailbox permissions, OAuth authorisations, and managed endpoints used to access OWA.
Conclusion
CVE-2026-42897 demonstrates that enterprise webmail compromise can extend beyond credential theft. Reported mailbox permission changes and OAuth token theft highlight how attackers may attempt to retain access even after password resets or endpoint remediation.
For organisations using Microsoft Exchange OWA, responding should include more than patch deployment. Reviewing mailbox permissions, OAuth authorisations, Exchange activity, and endpoint posture can help identify signs of remaining unauthorised access and strengthen remediation following exploitation of CVE-2026-42897.
Strengthen Exchange Security Today
Protect managed endpoints with unified visibility and policy-driven security controls.
A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions—without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable—politely.