Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

All IT Services security alert — patch Microsoft Exchange zero-day CVE-2026-42897

OWA Exploit Persists Through Password Resets — Patch Exchange Now

Russian state-linked hackers are actively exploiting a vulnerability in Outlook Web Access (OWA) that lets them maintain full mailbox access even after you reset passwords and reimage devices. If your business runs Exchange on-premises with OWA exposed to the internet, you need to check this now.

Proofpoint reported via The Hacker News on 30 July that threat group TA488 (also known as Laundry Bear) has been exploiting CVE-2026-42897, a cross-site scripting flaw in OWA with a CVSS score of 8.1, since 22 July. The attack is a “half-click” exploit — opening the email is enough. No links to click, no attachments to open. The email looks like a routine informational message about supply chains or market data.

Once triggered, the exploit deploys a JavaScript implant called OWAReaper that harvests credentials, steals OAuth tokens, and grants itself full access to the victim’s mailbox at the server level. The standard incident response playbook of rotating credentials and reimaging machines won’t remove it. The implant has to be cleaned directly from the Exchange server.

Microsoft released a patch for this vulnerability in May 2026. Any Exchange 2016, 2019, or Subscription Edition server that hasn’t applied it is exposed. Targets so far include government, telecommunications, financial services, hospitality, and aerospace organisations.

What to Do Right Now

Check whether your Exchange server has the May 2026 cumulative update installed. If OWA is internet-facing and unpatched, apply the update immediately. If you don’t actively need OWA, disable external access. If you suspect compromise, resetting passwords alone won’t help — the Exchange server itself needs to be inspected for the OWAReaper implant.

We regularly see Australian businesses — particularly hospitality groups and financial services firms — still running Exchange on-premises with OWA wide open to the internet, often because it was set up years ago and never locked down. If that’s your situation, this one is urgent.

Contact All IT Services for an Exchange security review, or see our cybersecurity services and managed IT support.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →