Skip to content
TA488 Exploits Outlook Web Access CVE-2026-42897 in New Campaign

TA488 Exploits Outlook Web Access CVE-2026-42897 in New Campaign

First seen 30 Jul 2026, 08:49 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 30, 2026 at 22:28 UTC
  • TA488 exploits CVE-2026-42897, a cross-site scripting flaw in OWA.
  • The campaign deploys OWAReaper, a persistent JavaScript backdoor.
  • Targeted organizations include government bodies, indicating a serious threat.

TA488 has launched a campaign exploiting CVE-2026-42897, a cross-site scripting flaw in Outlook Web Access (OWA). This vulnerability, disclosed by Microsoft on May 14, 2026, allows attackers to deploy a persistent JavaScript backdoor known as OWAReaper. The backdoor can survive credential rotations, browser restarts, and even full host re-imaging. Targeted entities include government bodies and organizations, indicating a significant scope of impact. The operation was confirmed to have exploited the flaw before Microsoft issued an emergency patch. The ongoing campaign raises concerns about the security of OWA users. As of July 30, 2026, the threat remains active.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 52d ago How this analysis works

Timeline

2026-05-14
CVE-2026-42897 published
Microsoft disclosed a cross-site scripting vulnerability in Outlook Web Access.
Gbhackers
2026-05-15
CVE-2026-42897 added to CISA KEV
CISA confirmed active exploitation of the vulnerability shortly after its disclosure.
Gbhackers
2026-07-30
TA488 campaign confirmed
TA488 linked to exploitation of CVE-2026-42897, targeting government organizations.
Cybersecuritynews

More articles in this cluster (3)

Following this threat?

Track Laundry Bear, OWAReaper and CVE-2026-42897 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed