HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Cross‑Site Scripting in Microsoft Exchange (CVE‑2026‑42897) Enables OWAReaper Backdoor – Targeting Government & Private Sectors

Laundry Bear is weaponising CVE‑2026‑42897, an XSS bug in Exchange OWA, to deliver the OWAReaper backdoor that steals credentials and OAuth tokens. The flaw underscores the need for SOC 2‑aligned access‑control monitoring and security‑awareness controls.

LiveThreat™ Intelligence · 📅 July 31, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
6 recommended
📰
Source
helpnetsecurity.com

Cross‑Site Scripting in Microsoft Exchange (CVE‑2026‑42897) Enables OWAReaper Backdoor – Targeting Government & Private Sectors

What It Is – A reflected cross‑site scripting (XSS) flaw in the Outlook Web Access (OWA) component of Microsoft Exchange allows an attacker to inject JavaScript that loads the OWAReaper backdoor. The payload runs in the reading pane, harvests credentials, steals OAuth tokens, and persists across re‑imaged devices.

Exploitability – Actively exploited by the Russia‑affiliated espionage group Laundry Bear (TA488). Proofpoint reports real‑world emails delivering the exploit; no public proof‑of‑concept is required. The CVSS score is not published, but the ability to obtain full mailbox access classifies the risk as High.

Affected Products – Microsoft Exchange Server (any version exposing the OWA webmail interface) and Outlook Web Access clients that render HTML email bodies.

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Access Controls – The attack bypasses traditional password rotation and device re‑imaging, highlighting the need for robust logical access reviews, MFA enforcement, and least‑privilege mailbox permissions.
  • Evidence of Continuous Monitoring – Detecting OWA‑specific anomalies (e.g., hidden iframes, unauthorized OAuth token grants) is essential to demonstrate ongoing control effectiveness to auditors.
  • Security Awareness – The lure relies on users opening seemingly benign emails; training programs must cover “no‑click” policies for suspicious messages, even when no attachments or links are present.

Recommended Actions

  • Apply Microsoft’s security update for CVE‑2026‑42897 immediately.
  • Enforce MFA for all Exchange and OWA accounts; restrict OAuth token scopes to the minimum required.
  • Deploy email‑gateway sandboxing and anti‑phishing controls that flag XSS‑laden messages.
  • Conduct a privileged‑access review of mailbox permissions and revoke any “Owner”‑level grants not justified by business need.
  • Enable detailed OWA audit logging and integrate logs with a SIEM for real‑time detection of anomalous script execution.
  • Refresh security‑awareness training to emphasize the risk of “no‑link, no‑attachment” phishing emails.

Source: Help Net Security – Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE‑2026‑42897)

📰 Original Source
https://www.helpnetsecurity.com/2026/07/30/cve-2026-42897-microsoft-exchange-email-attack/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →