Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)
highDetails
Russia-affiliated cyber espionage group Laundry Bear (aka Void Blizzard, TA488) is actively exploiting CVE-2026-42897, a cross-site scripting (XSS) vulnerability in Microsoft Exchange. The attack is delivered via email and triggers upon the message being opened.
Affected Systems
Microsoft Exchange
Potential Impact
Sustained, unauthorized access to sensitive email communications within government and private sector networks, leading to espionage, data exfiltration, and further network compromise.
Mitigations
Apply relevant Microsoft Exchange security updates immediately. Per CISA's KEV catalog, federal agencies must patch this vulnerability by 2026-05-29. Hunt for indicators of compromise associated with Laundry Bear/TA488.