Russian hackers turn Exchange flaw into ‘half-click’ mailbox takeover
Summary
A Russia-aligned threat group, TA488 (also known as Void Blizzard and Laundry Bear), exploited a cross-site scripting vulnerability (CVE-2026-42897) in Microsoft Exchange's Outlook Web Access to install a backdoor. This 'half-click' exploit allowed malicious JavaScript to execute simply by viewing a specially crafted email, bypassing the need for users to click links or open attachments.
IFF Assessment
This article details a successful exploit by a threat actor against a widely used email system, posing a direct threat to organizations and their data.
Severity
The vulnerability is a cross-site scripting (XSS) flaw in Outlook Web Access, allowing remote code execution without user interaction beyond viewing an email. This suggests a high attack vector and significant impact, warranting a high CVSS score.
CISA KEV: Listed as actively exploited. Federal patch due: May 29, 2026. Known ransomware use: Unknown.
Defender Context
Defenders should be aware of TA488's exploitation of Exchange vulnerabilities and ensure their systems are patched against CVE-2026-42897. The 'half-click' nature of this exploit highlights the importance of robust email filtering and user education, as even passive viewing can lead to compromise.