In Brief: Russian actors are exploiting an OWA vulnerability to execute JavaScript in emails—immediate patches required.
A security vulnerability in Outlook Web Access (OWA) enables attackers to execute JavaScript code when opening emails. Russian actors have already actively exploited this weakness.
The vulnerability exists in Microsoft’s Outlook Web Access and is triggered by displaying manipulated emails. When opening such messages, OWA executes embedded JavaScript code without properly validating or sanitizing it.
For CISOs, this vulnerability is critical because it resides in the email client—one of the most common attack vectors—and requires no additional user interaction. The executed code can enable access to user accounts, email content, or other systems if OWA is deployed in the enterprise infrastructure.
The active exploitation by Russian threat actors underscores the immediate priority. It is recommended to promptly deploy security updates from Microsoft and monitor OWA deployment. Web proxy and email filtering systems should be reviewed to verify they can detect relevant indicators.
Source: www.heise.de · Published 31 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification through Lumi News Pipeline v1.7.3.