Skip to content
Security & Trust

Microsoft Patched This Exchange Flaw in May. Attackers Were Still Inside in July.

A backdoor called OWAReaper is keeping mailbox access alive on on-premises Exchange servers long after CVE-2026-42897 was fixed and federally flagged.

K
Kannan SP
· 4 min read
Share on X LinkedIn
Microsoft Patched This Exchange Flaw in May. Attackers Were Still Inside in July.
Key finding

Time from patch to KEV listing: 1 day (May 14 → May 15, 2026) (Source: CISA Known Exploited Vulnerabilities Catalog (May 15, 2026))

A Patch Shipped. The Access Didn't Close.

On May 14, 2026, Microsoft patched a cross-site scripting flaw in Outlook Web Access, the browser-based front end for on-premises Exchange Server. The next day, CISA added it to the federal Known Exploited Vulnerabilities catalog as CVE-2026-42897, confirming it was already being used in the wild. Eleven weeks later, security researchers at Proofpoint were still tracking active campaigns exploiting the same flaw — this time delivering a persistence tool called OWAReaper, attributed to a Russia-linked group tracked as Laundry Bear, Void Blizzard, and TA488. The patch closed the entry point. It did not close the access that had already been established through it.

1 day (May 14 → May 15, 2026)
Time from patch to KEV listing
Source: CISA Known Exploited Vulnerabilities Catalog (May 15, 2026)

The federal remediation window was set at 14 days — CISA's Binding Operational Directive 22-01 required U.S. federal civilian agencies to mitigate by May 29, 2026. That deadline applies only to federal agencies, not to the telecom, financial services, hospitality, and aerospace organizations Proofpoint found still exposed. For everyone outside that federal mandate, remediation was a recommendation, not a clock. On-premises Exchange Server 2016, 2019, and Subscription Edition were all affected; Exchange Online was not, since the exploit path required an unauthenticated user to simply open a crafted email inside a self-hosted OWA session.

Government (US/EU), telecom, financial services, hospitality, aerospace
Sectors with active campaigns detected
Source: Proofpoint research cited in BleepingComputer (July 29, 2026)

What Makes OWAReaper Different

The backdoor doesn't depend on the original XSS flaw staying open. Once inside, it modifies Outlook add-in permissions and Exchange mailbox permission sets directly — changes that survive a password reset or a full credential rotation, because the access no longer runs through the credential at all. It runs through permission objects the attacker planted before anyone noticed. Command instructions arrive through a GitHub repository polled once every 24 hours, with a second exfiltration channel over DNS as fallback. Nothing about that infrastructure looks unusual to a network monitor — a mailbox occasionally reaching GitHub is not an anomaly worth a ticket.

1,655 entries
Federally cataloged actively-exploited vulnerabilities, all products
Source: CISA KEV Catalog snapshot via WebPulse Threat Intelligence (July 27, 2026)

Why a Mailbox Is Worth an 11-Week Campaign

A compromised mailbox used to mean stolen correspondence. It increasingly means something closer to a standing feed: calendars, contact graphs, attached documents, and message history are exactly the context that copilots, scheduling agents, and internal automation are built to read and act on. Persistent access of the kind OWAReaper is designed for doesn't need to be re-established after each defensive response — it's built to survive them. That durability is what makes it worth the engineering: a low-touch foothold that keeps producing usable context for as long as it goes unnoticed, regardless of whether the reader on the other end is a human analyst or an automated pipeline. This is the throughline WebPulse tracks across the framework layer and the infrastructure layer alike — as more of what gets read is read by machines, the value of quietly staying inside a mailbox goes up, not down.

For budget-signers, the relevant fact isn't the CVE number. It's the gap between when a vendor patches, when a federal catalog confirms exploitation, and when an organization outside that federal mandate actually applies the fix. In this case that gap ran past eleven weeks in at least five industry categories, on infrastructure that only requires an employee to open an email to be affected.

CVEs in this analysis
CVE-2026-42897
Share this insight