The vulnerability: CVE-2026-42897, a cross-site scripting (XSS) flaw in Outlook Web Access (OWA), the browser-based interface for on-premises Microsoft Exchange Server. CVSS score: 8.1 (High).
Affected systems: On-premises Exchange Server 2016, 2019, and Subscription Edition (SE).
How the attack works:
- An unauthenticated attacker sends a “half-click” phishing email — no links, no attachments, no action required beyond opening the message.
- 15Just opening the email in OWA is enough to fire the exploit: an onload handler parses the message body, reassembles a Base64-encoded payload hidden inside the social media icon images, and executes it as JavaScript in the victim’s authenticated browser session.
- The payload deploys a JavaScript implant called OWAReaper, which runs entirely inside the browser (no files touch the host).
Who’s behind it
Proofpoint attributes the campaign to a group tracked as Laundry Bear (aka CL-STA-1114, TA488, UNK_PitStop, Void Blizzard), the same actor that exploited a similar Zimbra XSS bug (CVE-2025-66376) starting in mid-2025. Targets span U.S. and European government, telecom, finance, hospitality, and aerospace sectors. Attack infrastructure dates back to March 2026, two months before Microsoft’s disclosure, suggesting possible zero-day use before the public CVE.
Why OWAReaper is dangerous
- Rewrites the malicious email on the Exchange server to erase the exploit after execution.
- Harvests OWA saved credentials via injected invisible form fields and the browser’s autofill.
- Abuses Outlook add-ins with mailbox read/write permissions to steal OAuth tokens and grant itself Owner-level access to every mail folder for the default org user, giving it mailbox access across the organization.
- Persists via localStorage (re-runs every time OWA is opened) and via a hidden iframe planted in OWA’s offline IndexedDB cache (re-infects even after device re-imaging).
- Survives credential rotation and full device re-imaging because persistence lives server-side in Exchange, not on the endpoint.
- Uses two C2 channels: polling GitHub’s commit-search API for encoded commands, or parsing commands from attacker-sent emails.
- Exfiltrates data over HTTPS (AES-CTR encrypted URIs) with DNS tunneling as a fallback.
What to do
- Patch immediately if still unpatched: Exchange SE RTM SU7 (KB5094139), or confirm ESU coverage for 2016/2019.
- Confirm EEMS mitigation M2.1 is applied (Get-ExchangeServer -Identity <ServerName> | Format-List Name,MitigationsApplied).
- If compromise is suspected, credential rotation and re-imaging are not sufficient — the persistence lives on the Exchange server side and must be removed there directly.
- Audit Outlook add-ins with ReadWriteMailbox permissions and mailbox folder permissions for unexpected Owner-level grants.
- Review OWA’s IndexedDB message cache for planted iframe content.
For more information see: Addressing Exchange Server May 2026 vulnerability CVE-2026-42897
Fortify Your Server with Messageware Security
Data breaches have increased by 72%, servers are compromised in under 90 minutes. Ensure you have multiple layers of security software protecting your Windows Servers.
Server Threat Guard (STG) for All Windows Servers: Next-gen server protection, providing detection, alerting, and response (MDR) to zero-day and server penetration cyber-attacks. No need to research complicated deployments and no learning curve to install and manage.
EPG Guard for Exchange Servers: Real-time security. Stop AD account lockouts, eliminate password attacks, intelligent GEO blocking, and prevent Exchange Server vulnerability probing.
Don’t leave your critical infrastructure vulnerable, be proactive and stay ahead of evolving threats.