Max-Severity Microsoft Exchange CVE-2026-42897 Actively Exploited by Laundry Bear
Email open, half-click, mailbox held after password reset — Exchange on the wire this week.
Key Takeaways
|
A max-severity Exchange flaw that reportedly fires on message open and holds a mailbox through a password reset — the same Russian actor's Zimbra playbook, now aimed at Outlook.
REDMOND, WASHINGTON — Security researchers and multiple outlets on July 30, 2026 reported that CVE-2026-42897, a max-severity flaw in Microsoft Exchange, is under active exploitation by the Russian threat actor known as Laundry Bear, with the attack reportedly triggering when a target opens a crafted message in Outlook Web Access (OWA) — no attachment to run and no link to follow.
The campaign carries two details that should command a defender's attention. First, according to Help Net Security, the technique fires on email open, and reporting has attached the name "OWAReaper" to the implant it delivers. Second, The Hacker News reports that Russian operators are abusing an OWA weakness to keep access to a mailbox even after credential rotation — the step defenders normally treat as the reset button on an account takeover. The Register frames the shift bluntly: Russian spies have carried their "half-click" email attack from Zimbra to Outlook, a direct continuation of the Russian zero-click Zimbra campaign The CyberSignal covered in July. This piece summarizes what the disclosure documents and what remains unconfirmed, without reconstructing the technique.
| At a Glance | |
|---|---|
| Field | Details |
| What | Active exploitation of CVE-2026-42897, a max-severity Microsoft Exchange flaw |
| Attributed actor | Laundry Bear (Russia); also reported as Void Blizzard and, per Proofpoint, TA488 |
| Trigger | Reportedly opening a crafted message in Outlook Web Access (OWA) — email open, not a click |
| Reported implant | "OWAReaper," per reporting |
| Persistence | Access reportedly survives credential rotation |
| Continuity | Reported pivot of the "half-click" technique from Zimbra to Outlook |
| Disclosure | July 30, 2026 (multiple outlets) |
| CVSS / fixed version / CISA KEV | Not established in the reporting reviewed — open questions |
What Microsoft and Researchers Disclosed
The disclosure landed across several security outlets on July 30, 2026 — among them Ars Technica, Help Net Security, The Hacker News and The Register — each describing active, in-the-wild exploitation of CVE-2026-42897 against Microsoft Exchange. Ars Technica characterizes the flaw as max-severity and attributes the intrusions to Kremlin-linked operators tracked as Laundry Bear. Microsoft's own advisory is the primary reference point for affected products and remediation, and The CyberSignal is treating the vendor guidance, not the news coverage, as the authoritative source once operators sit down to act.
What reporting agrees on is the shape of the problem rather than every number attached to it. The flaw reportedly stems from how Exchange handles message content surfaced in Outlook Web Access, and the exploitation reportedly requires nothing more from the target than opening a message. Beyond that, several specifics — the CVSS base score behind the "max-severity" label, the exact range of affected Exchange builds, and the fixed version — are not firmly established in the coverage reviewed, and this piece does not guess at them.
The Email-Open Trigger and OWA Persistence
Two properties make CVE-2026-42897 more dangerous than a routine server bug. The first is the trigger. Help Net Security reports the attack fires on email open, not on a click — there is reportedly no attachment to detonate and no link a cautious recipient could decline to follow. The Register captures the same idea with the phrase it has used for the campaign: a "half-click" attack, where the ordinary act of reading a message in webmail is enough. The distinction matters for awareness training, which leans heavily on teaching people not to click; a trigger that fires on open sidesteps that advice entirely.
The second property is persistence. The Hacker News reports that Russian operators are exploiting an OWA weakness to retain mailbox access after credential rotation — the control defenders reach for first when they suspect an account is compromised. If resetting a password does not evict the intruder, the standard incident-response reflex is blunted, and the reported implant, which coverage refers to as "OWAReaper," is described as surviving that reset. The CyberSignal is not reproducing how the persistence is achieved; the defender-relevant fact is that credential rotation alone should not be assumed sufficient here.
Continuation Context: The Russian Zimbra-to-Outlook Pivot
This is not a standalone event so much as the next move in a campaign The CyberSignal has been tracking. In July, the UK's NCSC and partners across roughly 16 nations published a joint alert on a Russian state-supported zero-click Zimbra campaign attributed to the same cluster — Laundry Bear, also tracked as Void Blizzard — which abused a Zimbra Collaboration flaw to read mailboxes and harvest two-factor codes. The Register frames the new activity as that identical playbook carried from Zimbra to Outlook: the same actor, the same "half-click" tradecraft, a different webmail platform.
The attribution picture is worth stating carefully. Ars Technica and others use the name Laundry Bear; Infosecurity Magazine reports the OWA-persistence work under the name TA488, the designation Proofpoint uses for the group. On the reporting reviewed these describe one cluster rather than competing candidates — Proofpoint tracks Laundry Bear as TA488, and the activity has also been reported as Void Blizzard. The US Justice Department has already charged a Russian national tied to Void Blizzard, a reminder that this is an established, named adversary — one of several Russian nation-state operations The CyberSignal has tracked this year — rather than an opportunistic one.
What Exchange Operators Should Verify
For teams running Exchange, the immediate work is verification, in a specific order. First, confirm patch level against Microsoft's advisory for CVE-2026-42897 once the fixed build is identified there — the vendor page, not a news summary, is the source of truth for affected and remediated versions. Second, and unusually, do not treat credential rotation as closure. Because access is reported to survive password resets, hunt for persistence at the mailbox and OWA layer — anomalous inbox rules, add-ins, or lingering sessions — rather than assuming a reset ended the intrusion.
Identity monitoring deserves a second look for the same reason. Campaigns that defeat credential rotation tend to lean on tokens and sessions rather than passwords, a pattern The CyberSignal has seen elsewhere — including OAuth and device-code abuse that turns Microsoft's own login flows against M365 tenants. Reviewing OWA and Exchange session activity, and revoking tokens rather than only resetting passwords, is the kind of step that matches the reported behavior. None of this substitutes for the vendor's guidance; it complements it while operators confirm their exposure.
The KEV Catalog Watch
One open item worth watching is the US Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities (KEV) catalog. As of the reporting reviewed, it is not confirmed whether CVE-2026-42897 has been added to KEV, and The CyberSignal is not asserting that it has. A KEV listing would carry practical weight: it sets a federal remediation deadline under Binding Operational Directive 22-01 and functions, in practice, as a broad signal that a flaw is being exploited at scale. Given the active exploitation described across the reporting, a KEV addition would be an unsurprising next step — but operators should treat it as something to verify against CISA's catalog directly rather than assume.
Open Questions
Several specifics remain unresolved at publication, and The CyberSignal is not filling them in. The CVSS base score behind the "max-severity" label, the precise range of affected Exchange versions, and the fixed build are not firmly established in the coverage reviewed. Nor is the KEV status confirmed. Each will sharpen as Microsoft's advisory and independent analysis are read closely.
Other questions are about scope. The reporting names sectors and geographies at a high level but does not, in the material reviewed, quantify how many organizations were reached or how long access persisted before detection. And while the coverage converges on Laundry Bear, Void Blizzard and TA488 describing one cluster, readers should hold even a well-supported attribution as a reported judgment rather than a settled fact. The throughline is clear enough to act on: a max-severity Exchange flaw, a trigger that fires on open, and persistence that outlasts a password reset.
The CyberSignal Analysis
The reported facts above come from the disclosure and its reporting; what follows is The CyberSignal's editorial reading. None of the judgments below are new reported facts.
Signal 01 — Open Beats Click
The single most important detail for a defender is the one easiest to under-weight: the trigger reportedly fires on open, not on a click. Our reading is that this quietly invalidates a large slice of security-awareness guidance, which is built almost entirely around teaching people not to click links or open attachments. A message that acts the moment it is read leaves the user no decision to get right.
The consequence is that the control burden shifts back onto the platform and the defenders — patching, session hygiene, and detection — rather than the recipient. Organizations that have leaned on training as a primary line of defense for webmail risk should read this as a prompt to rebalance toward the technical controls they actually own.
Signal 02 — A Password Reset Is Not the Off Switch
The persistence claim is the detail we would flag hardest for incident responders. The reflex when a mailbox looks compromised is to rotate the credential and move on; here that reflex is reportedly insufficient, because access survives the reset. Our assessment is that treating rotation as closure is the specific mistake this campaign is built to exploit.
The practical adjustment is to widen the response from passwords to the whole session-and-persistence surface: tokens, mailbox rules, and add-ins. Defenders who already revoke sessions and hunt for mailbox-layer persistence as a matter of routine are positioned to handle this; those who stop at a password reset are not.
Signal 03 — Same Actor, New Platform
The continuity is the part we find most instructive. This is reportedly the same cluster, using the same "half-click" idea, that ran the Zimbra campaign — now aimed at Outlook. Our view is that the platform is almost incidental; the durable capability is a tradecraft pattern the group has now demonstrated against two different webmail stacks.
That argues for watching the technique rather than the product. An organization that patched and moved on after the Zimbra alert, treating it as a one-vendor problem, would have missed the more useful lesson: this actor reuses what works. Defenders who internalized the earlier campaign will meet this one already oriented.