ThreatCluster

TA488 Exploits Outlook Web Access CVE-2026-42897 in New Campaign

First seen 30 Jul 2026, 08:49 UTC GbhackersCybersecuritynews 85% similarity 72

Article Content

Browse articles
ThreatCluster

TA488 has launched a campaign exploiting CVE-2026-42897, a cross-site scripting flaw in Outlook Web Access (OWA). This vulnerability, disclosed by Microsoft on May 14, 2026, allows attackers to deploy a persistent JavaScript backdoor known as OWAReaper. The backdoor can survive credential rotations, browser restarts, and even full host re-imaging. Targeted entities include government bodies and organizations, indicating a significant scope of impact. The operation was confirmed to have exploited the flaw before Microsoft issued an emergency patch. The ongoing campaign raises concerns about the security of OWA users. As of July 30, 2026, the threat remains active.

Key Points: • TA488 exploits CVE-2026-42897, a cross-site scripting flaw in OWA. • The campaign deploys OWAReaper, a persistent JavaScript backdoor. • Targeted organizations include government bodies, indicating a serious threat.

ThreatCluster AI How this analysis works

Timeline

2026-05-14
CVE-2026-42897 published
Microsoft disclosed a cross-site scripting vulnerability in Outlook Web Access.
Gbhackers
2026-05-15
CVE-2026-42897 added to CISA KEV
CISA confirmed active exploitation of the vulnerability shortly after its disclosure.
Gbhackers
2026-07-30
TA488 campaign confirmed
TA488 linked to exploitation of CVE-2026-42897, targeting government organizations.
Cybersecuritynews

Community

Browse all →