Home · Wiki · Vulnerabilities & CVEs
type: cve · created: 2026-09-23 · updated: 2026-09-23 · tags: [cve] · confidence: high · severity: high · affected_sectors: [government, defence] · au_impact: false

CVE-2026-42897

Summary

A cross-site scripting flaw in Microsoft Outlook Web Access, scored CVSS 8.1, weaponised by the Russian state-sponsored group Laundry Bear (also tracked as Void Blizzard, CL-STA-1114 and Void PitStop).

Details

The group's use of CVE-2026-42897 is the notable part: an XSS in a webmail client is normally a credential-phishing primitive, but Laundry Bear applied it to retain mailbox access rather than to obtain it — the pattern of an actor already inside an environment looking for a route that survives a password reset. That places the flaw in the same operational family as token theft and device-code abuse: the durable asset is the session, not the password. Note the attribution is the reporting outlet's and the group's, not this wiki's assessment.

Attribute Detail
CVE CVE-2026-42897
CVSS 8.1
Vendor / product Microsoft (Outlook Web Access)
Reported in the digest 2026-07-30

Related Pages

Sources: raw/digests/Cyber-Digest-2026-07-30.md