Russian state-sponsored hackers are exploiting a Microsoft Exchange Outlook Web Access vulnerability to deploy OWAReaper, a webmail backdoor designed for long-term mailbox access. Attack Exploits CVE-2026-42897The campaign exploits CVE-2026-42897, a cross-site scripting vulnerability in Outlook Web Access. Mailbox Permissions Create Server-Side PersistenceThe backdoor can grant Owner-level mailbox permissions to the Exchange Default user across every mail folder. Changing the user’s password may also fail to block access if the malicious mailbox permissions and stolen OAuth tokens remain active. OWAReaper creates another persistence mechanism through the Outlook Web Access offline cache.