Vulnerabilities & Exploits · Web App Attack

OWA Access Now Survives Resets and Reimaging

TA488 has moved past one-time mailbox compromise. The attacker now plants access inside OWA’s browser state, so resetting the password or rebuilding the device does not clear the foothold if the user opens webmail again.

Proofpoint says the group began this renewed activity on July 22 and is using CVE-2026-42897, a cross-site scripting flaw in Microsoft Exchange OWA, against U.S. and European government, telecom, financial, hospitality, and aerospace targets. The OWAReaper implant runs when a message is opened in the reading pane, then stores itself in OWA/browser storage so it can come back on later sessions.

The persistence is the point. The compromise lives at the mailbox session layer, so credential-only cleanup misses the part that keeps restoring access.

7 sources · Aug 1

CVE-2026-42897

NVD KEV

Known exploited · CISA KEV

CVSS 8.1 HIGH: improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server… Microsoft patch: 5094144.

Patch available KB5094144

CISA federal remediation date May 29 · date passed

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-07-29

Every edition of this story: OWA Access Now Survives Resets and Reimaging

More from today