Russian hackers turn Exchange flaw into ‘half-click’ mailbox takeover

Summary

A Russia-aligned threat group, TA488 (also known as Void Blizzard and Laundry Bear), exploited a cross-site scripting vulnerability (CVE-2026-42897) in Microsoft Exchange's Outlook Web Access to install a backdoor. This 'half-click' exploit allowed malicious JavaScript to execute simply by viewing a specially crafted email, bypassing the need for users to click links or open attachments.

IFF Assessment

FOE

This article details a successful exploit by a threat actor against a widely used email system, posing a direct threat to organizations and their data.

Severity

8.1 High

The vulnerability is a cross-site scripting (XSS) flaw in Outlook Web Access, allowing remote code execution without user interaction beyond viewing an email. This suggests a high attack vector and significant impact, warranting a high CVSS score.

CISA KEV: Listed as actively exploited. Federal patch due: May 29, 2026. Known ransomware use: Unknown.

Defender Context

Defenders should be aware of TA488's exploitation of Exchange vulnerabilities and ensure their systems are patched against CVE-2026-42897. The 'half-click' nature of this exploit highlights the importance of robust email filtering and user education, as even passive viewing can lead to compromise.

Read Full Story →