• Sources: Proofpoint research, NVD CVE-2026-42897, BleepingComputer
  • Summary: Proofpoint reports a Russian state-aligned actor it tracks as TA488 exploiting CVE-2026-42897, a cross-site scripting flaw in Outlook Web Access, since 2026-07-22. The persistence sits on the server and in the browser rather than in the account: mailbox folder permissions and Outlook add-in tokens in OWA storage. NVD scores the flaw 6.1 and Microsoft scores it 8.1. Microsoft's patch has been available since 2026-05-14 and CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2026-05-15. The MSRC update guide entry returned page chrome only during this run, so the fixed builds are taken from the NVD record, which carries Microsoft's CNA data: Exchange 2016 CU23 below 15.01.2507.069, Exchange 2019 CU14 below 15.02.1544.041, Exchange 2019 CU15 below 15.02.1748.046, and Subscription Edition RTM below 15.02.2562.043.
  • Why it matters: Rotating credentials and re-imaging the workstation do not evict this actor, so remediation means auditing Default-user folder permissions and Outlook add-in tokens on the Exchange server itself.
  • Follow-up: Track whether Microsoft publishes remediation guidance for the mailbox-permission and add-in-token persistence rather than the patch alone.

send feedback on this story