CVE-2026-42897
Summary
A cross-site scripting flaw in Microsoft Outlook Web Access, scored CVSS 8.1, weaponised by the Russian state-sponsored group Laundry Bear (also tracked as Void Blizzard, CL-STA-1114 and Void PitStop).
Details
The group's use of CVE-2026-42897 is the notable part: an XSS in a webmail client is normally a credential-phishing primitive, but Laundry Bear applied it to retain mailbox access rather than to obtain it — the pattern of an actor already inside an environment looking for a route that survives a password reset. That places the flaw in the same operational family as token theft and device-code abuse: the durable asset is the session, not the password. Note the attribution is the reporting outlet's and the group's, not this wiki's assessment.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-42897 |
| CVSS | 8.1 |
| Vendor / product | Microsoft (Outlook Web Access) |
| Reported in the digest | 2026-07-30 |
Related Pages
Sources: raw/digests/Cyber-Digest-2026-07-30.md