Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
Overview
Russian hackers have been exploiting a vulnerability in Microsoft Outlook Web Access (OWA) to maintain access to mailboxes even after users change their passwords. This campaign, which started on July 22, 2026, has targeted various sectors including U.S. and European government entities, telecommunications, finance, hospitality, and aerospace. The attackers are using this flaw to bypass credential rotation, which is a common security measure. The exploitation of this vulnerability poses significant risks, as it allows unauthorized access to sensitive information and communication. Organizations need to ensure that they are aware of this issue and take steps to protect their systems against such attacks.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Microsoft Outlook Web Access (OWA), U.S. government entities, European government entities, telecommunications, financial sector, hospitality sector, aerospace sector
- Action Required: Patches for the vulnerability have been released; users should ensure their OWA systems are updated to the latest version.
- Timeline: Ongoing since July 22, 2026
Original Article Summary
The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors. The activity, which began on July 22, 2026, involves the
Impact
Microsoft Outlook Web Access (OWA), U.S. government entities, European government entities, telecommunications, financial sector, hospitality sector, aerospace sector
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Ongoing since July 22, 2026
Remediation
Patches for the vulnerability have been released; users should ensure their OWA systems are updated to the latest version.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Microsoft, Exploit, Vulnerability, and 1 more.