CISA on May 15, 2026 added CVE-2026-42897, a Microsoft Exchange Server cross-site scripting vulnerability, to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation. Under BOD 22-01, federal civilian agencies must remediate by CISA's due date, and CISA urged all organizations to prioritize patching KEV-listed flaws.
2026.07.30
90% relevant
This article directly updates the same underlying event: active exploitation of CVE-2026-42897 in on-premises Exchange Server OWA. It adds attribution to TA488/Laundry Bear, says the campaign targeted government, telecom, finance, hospitality, and aerospace organizations in the US and Europe, and describes the OWAReaper browser implant and the possibility that exploitation began as early as March, before disclosure and patching.
Ionut Ilascu
2026.07.29
94% relevant
This article adds concrete attribution and exploitation details to the same CVE-2026-42897 event: Proofpoint says Russia-linked Laundry Bear used the Exchange OWA XSS zero-day to deliver the OWAReaper backdoor, target U.S. and European organizations, and maintain long-term mailbox access through Outlook add-ins even after password rotation or system rebuilds.
2026.07.29
77% relevant
This provides attacker attribution and tradecraft for the already tracked exploitation of CVE-2026-42897, identifying Laundry Bear as using the Outlook Web Access flaw in a half-click email theft campaign and deploying the OWAReaper browser implant for persistence.
Arctic Wolf Labs
2026.06.11
63% relevant
The article notes that CVE-2026-42897 was the actively exploited zero-day in this Patch Tuesday cycle and reiterates Microsoft's Exchange Emergency Mitigation Service guidance, connecting this patch release to the previously tracked active exploitation.
Eduard Kovacs
2026.06.11
95% relevant
This article updates the same underlying event by adding that Microsoft has now released patches for the previously mitigations-only zero-day CVE-2026-42897 affecting Exchange Server Subscription Edition, 2016, and 2019.
Sergiu Gatlan
2026.06.10
96% relevant
This article is a direct update to the same CVE-2026-42897 event, adding that Microsoft has now released June 2026 security updates to patch the actively exploited Exchange Server flaw after earlier warning of exploitation and temporary mitigations.
CISA
2026.05.15
100% relevant
This article is the first tracked item here establishing the specific KEV event for CVE-2026-42897 and its active exploitation status.