High
KEV-listed
CVE-2026-42897
TA488 Half-Click OWA Exploit and Cisco FMC Zero-Day Active Exploitation
Vendor / product: Microsoft Exchange Outlook Web Access (OWA), Cisco Secure Firewall Management Center (FMC)
Event date: 2026-07-31
Victim organization: US and European government bodies and telecom, financial, hospitality, and aerospace firms
Public PoC: Yes
First tracked by RiskWire: 2026-07-28
CISA KEV catalog
Added to KEV
Federal remediation due
2026-05-29 (114 days overdue)
Ransomware campaign use
Unknown
CISA description
Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Named threat actors
TA488Silver Fox
Sources & citations (28)
- Ankura CTIX FLASH Update – July 31, 2026 mondaq.com:443 · 2026-08-03
- TA488 Exploits Outlook Half-Click Flaw to Deploy Persistent OWAReaper Backdoor gbhackers.com · 2026-07-30
- Laundry Bear's new Microsoft Exchange attack triggers on email open (CVE-2026-42897) helpnetsecurity.com · 2026-07-30
- Kremlin hackers are exploiting Exchange flaw to backdoor unpatched networks arstechnica.com · 2026-07-30
- Russian hackers exploit Exchange OWA zero-day for long-term mailbox access bleepingcomputer.com · 2026-07-29
- Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation thehackernews.com · 2026-07-30
- Laundry Bear pivots to new exploit days after Zimbra alert computerweekly.com · 2026-07-29
- TA488 May Have Exploited Outlook Web Access 0-Day Flaw Before Microsoft's Emergency Patch cybersecuritynews.com · 2026-07-30
- Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit proofpoint.com · 2026-07-29
- Laundry Bear's webmail hackers had more in store after February, report says therecord.media · 2026-07-29
- RussianTA488 Returns With Persistent Outlook Web Access Attack infosecurity-magazine.com · 2026-07-29
- Russian hackers turn Exchange flaw into ‘half-click' mailbox takeover csoonline.com · 2026-07-30
- TA488 Exploits Outlook Web Access Flaw with Half-Click Attack esecurityplanet.com · 2026-07-30
- OWAReaper Backdoor Targets Microsoft Exchange Users windowsreport.com · 2026-07-30
- Russian Espionage Group Expands Tactical Scope to Exploit Microsoft Outlook Web Access Vulnerability uk.headtopics.com · 2026-07-30
- Russian actors attack via Outlook Web Access vulnerability heise.de · 2026-07-31
- Russian state hackers deploy persistent Exchange backdoor that survives disk reimaging betanews.com · 2026-07-31
- Russian spies take their half-click email attack from Zimbra to Outlook theregister.com · 2026-07-30
- TA488 OWAReaper: A "Half-Click" Attack that Adds Persistence Inside OWA Just by Opening an Email dev.to · 2026-07-31
- Russian Hackers Breached Exchange Servers With OWAReaper: Implant Survives Re-Imaging techtimes.com · 2026-07-30
+8 more sources
References
See CVE-2026-42897 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →