What is CVE-2026-42897?
CVE-2026-42897 is a cross-site scripting vulnerability in Microsoft Exchange exploited by the Russia-linked group Laundry Bear, triggering attacks upon email opening. The vulnerability targets US and European government entities and private organizations. Users are advised to apply security updates for email exchange and avoid suspicious messages.
Azərbaycanca: CVE-2026-42897, Microsoft Exchange-də aşkarlanmış cross-site scripting (XSS) zəifliyidir. 'Laundry Bear' adlı Rusiya bağlantılı qrup bu boşluqdan istifadə edərək e-poçt açıldıqda hücumu işə salır və ABŞ ilə Avropa dövlət qurumlarını hədəf alır. İstifadəçilərə e-poçt mübadiləsi üçün təhlükəsizlik yeniləmələrini tətbiq etmək və şübhəli mesajlardan qaçmaq tövsiyə olunur.
Related CVEs
link basis: shared threat actors: Laundry Bear, TA488, Void Blizzard; shared vendor: Proofpoint
FAQ2
On which platform was the CVE-2026-42897 vulnerability exploited by the ‘Laundry Bear’ group discovered?
The CVE-2026-42897 vulnerability is a cross-site scripting flaw discovered in Microsoft Exchange.
What is the main recommendation for entities targeted by CVE-2026-42897?
Users are advised to apply security updates for email exchange and avoid suspicious messages.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.