CVE-2026-42897: A Quick Reality Check
Kremlin-linked hackers are using the CVE-2026-42897 flaw to breach unpatched Exchange Servers. Is your system at risk?
CVE-2026-42897 is a critical threat to your email security
CVE-2026-42897 is the technical identifier for a maximum-severity flaw currently under active exploitation by attackers linked to the Kremlin. This vulnerability targets Microsoft Outlook Exchange Server, allowing hackers to compromise your account with minimal interaction. It is not just a theoretical risk. It is happening now.
How the half-click attack works
The attackers, known as TA488, are exploiting what researchers call a half-click technique. It's brutal. You don't need to click a link, download an attachment, or enter a password for the compromise to initiate, which means the usual defenses are useless. So simply opening a malicious email in your Outlook Web Access account is enough to trigger the entire attack.

The vulnerability exists because the software fails to properly filter HTML embedded in emails. This oversight allows malicious JavaScript to execute the moment the email appears in your reading pane. Once triggered, the code installs a custom browser-based implant known as OWAReaper, which gains persistent access to your account.
Why this breach is different
This isn't a standard malware infection. You can't just wipe your computer and call it a day. The backdoor lives on the server side, meaning your local device isn't the primary point of control, so even a full re-image of your laptop or a fresh password won't shake the attackers loose. They keep their foothold. And that's the real problem.
OWAReaper is highly sophisticated. Once it runs in your browser, it takes several aggressive actions to hide its presence and extract your data:
- It rewrites the email on the server to remove the exploit content.
- It disables pop-ups and right-click functionality while it runs.
- It waits for your browser autofill to capture your saved credentials.
- It saves an encrypted version of itself in your browser local storage to ensure it reloads every time you open Outlook.
TA488 is doubling down on the use of half-click exploits, where opening the email is enough to trigger compromise, with significantly improved loading mechanisms, techniques, and malware, signaling an improvement in the group’s tradecraft and capability.
Taking control of your account
If you are wondering how to defend your network, you must act beyond standard password rotations. Because the backdoor persists on the server side, you need to conduct a thorough audit. Microsoft provided mitigation advice in May and released a formal patch in July. If you have not updated your systems, your environment is at risk.
Steps to secure your environment
Securing your email takes blunt, decisive action. It's not enough to simply change your password and hope the intruder wanders off, because these attackers often leave behind backdoors, forwarding rules, and recovery options that let them stroll right back in whenever they please. But you can't stop there. So prioritize these immediate steps: revoke all active sessions, audit every forwarding rule, and check recovery phone numbers and emails for anything you don't recognize. Do it now.
- Revoke and audit all Exchange Web Services tokens for unauthorized add-ins.
- Remove folder permissions granted to default users.
- Clear the OWA indexDB and the specific PageDataPayload.owaUserDefaultSettings local storage key.
- Block outbound connections to known command-and-control domains, including asecdns.com, acocdn.com, dnsrecursive.eu, and tdndns.com.
The path forward
CVE-2026-42897 represents a high-stakes scenario for anyone using Exchange Server. The attackers have shown a clear ability to improve their tradecraft, and their persistent access model means they are not going away on their own. Verify your patch status today. If you suspect your account has been accessed, do not assume a simple password reset will clean your system.
Frequently Asked Questions
What is CVE-2026-42897 and why is it considered a critical threat?
CVE-2026-42897 is the technical identifier for a maximum-severity flaw in Microsoft Outlook Exchange Server that is currently under active exploitation by attackers linked to the Kremlin. It is considered critical because it allows hackers to compromise your account with minimal interaction, as simply opening a malicious email in Outlook Web Access can trigger the attack.
How does the 'half-click' attack work, and what triggers it?
The half-click attack is a technique used by the attackers TA488, where you don't need to click a link, download an attachment, or enter a password for the compromise to initiate. The vulnerability exists because the software fails to properly filter HTML embedded in emails, allowing malicious JavaScript to execute the moment the email appears in your reading pane, even just by opening it in Outlook Web Access.
Why is this breach different from a standard malware infection?
This breach is different because the backdoor lives on the server side, meaning your local device isn't the primary point of control, so wiping your computer or changing your password won't remove the attackers. The backdoor persists on the server, allowing attackers to keep their foothold, and OWAReaper, the implant, takes actions like rewriting emails to hide its presence and extracting data.
What steps should be taken to secure your environment against CVE-2026-42897?
To secure your environment, you must revoke all active sessions, audit every forwarding rule, and check recovery phone numbers and emails for anything unrecognized. Additionally, you should revoke and audit all Exchange Web Services tokens for unauthorized add-ins, remove folder permissions granted to default users, clear the OWA indexDB and specific local storage keys, and block outbound connections to known command-and-control domains like asecdns.com and acocdn.com.
When did Microsoft provide mitigation advice and release a patch for this vulnerability?
Microsoft provided mitigation advice in May and released a formal patch in July. If you have not updated your systems, your environment is at risk, so it is crucial to verify your patch status today and act beyond standard password rotations.
💬 Comments (0)
No comments yet. Be the first!













