TA488 Exploits Outlook Web Access CVE-2026-42897 in New Campaign
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
TA488 has launched a campaign exploiting CVE-2026-42897, a cross-site scripting flaw in Outlook Web Access (OWA). This vulnerability, disclosed by Microsoft on May 14, 2026, allows attackers to deploy a persistent JavaScript backdoor known as OWAReaper. The backdoor can survive credential rotations, browser restarts, and even full host re-imaging. Targeted entities include government bodies and organizations, indicating a significant scope of impact. The operation was confirmed to have exploited the flaw before Microsoft issued an emergency patch. The ongoing campaign raises concerns about the security of OWA users. As of July 30, 2026, the threat remains active.
Key Points: • TA488 exploits CVE-2026-42897, a cross-site scripting flaw in OWA. • The campaign deploys OWAReaper, a persistent JavaScript backdoor. • Targeted organizations include government bodies, indicating a serious threat.