Vulnerability intelligence
CVE-2026-42897 — Security Advisory
A backdoor called OWAReaper is keeping mailbox access alive on on-premises Exchange servers long after CVE-2026-42897 was fixed and federally flagged.
2026
What WebPulse reported · 2 analyses
Microsoft Patched This Exchange Flaw in May. Attackers Were Still Inside in July.
A backdoor called OWAReaper is keeping mailbox access alive on on-premises Exchange servers long after CVE-2026-42897 was fixed and federally flagged.
July 30, 2026
Microsoft Exchange Server Zero-Day Patched: Legacy Email Infrastructure Is the Web's Quiet Attack Surface
CVE-2026-42897. Actively exploited zero-day in Exchange Server — spoofing and cross-site scripting affecting Subscription Edition, 2016, and 2019. Organizations
June 13, 2026
Related vulnerabilities