type: incident ยท created: 2026-07-30 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: not-rated ยท affected_sectors: [] ยท au_impact: false
Max-Severity Exchange Server Flaw Under Active Exploitation by Kremlin Hackers
Summary
Ars Technica's Dan Goodin reported a maximum-severity Microsoft Exchange vulnerability under active exploitation by Kremlin-aligned hackers. The exploit provides persistent server access that survives credential rotation and disk re-imaging.
Key Details
- Date: 2026-07-30
- Source: Ars Technica
- Reliability: Tier 2/4 โ Established cyber journalism
- Threat Actor: Kremlin-aligned hackers (Russian state-sponsored)
- Affected Product: Microsoft Exchange Server
- Severity: Maximum severity
- Capability: Persistent server access surviving credential rotation and disk re-imaging
- Status: Active exploitation in the wild
Significance
The persistence capability (surviving credential rotation and disk re-imaging) makes this particularly dangerous for enterprise environments. The flaw and its exploitation were disclosed by researchers tracking Russian state-sponsored cyber operations.