A Russia-aligned threat actor known as TA488 has launched a new campaign exploiting a cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA). Key takeaways of the TA488 Outlook Web Access attackTA488 is exploiting CVE-2026-42897 in Microsoft Outlook Web Access (OWA) to execute malicious JavaScript when users simply open a specially crafted email. TA488 exploits Microsoft Outlook Web Access vulnerability CVE-2026-42897According to Proofpoint, the campaign began on Jul. Reduce unnecessary exposure by restricting internet-facing Outlook Web Access access where possible and limiting access based on trusted devices, locations, or risk signals. by restricting internet-facing Outlook Web Access access where possible and limiting access based on trusted devices, locations, or risk signals.