Two Zero-Days, One Lesson: Attackers Are Coming for Your Control Plane
Two actively exploited zero-days were confirmed this week. One gives Russian state-sponsored attackers long-term access to corporate mailboxes through Outlook Web Access. The other hands unauthenticated attackers a way into the console that manages Cisco firewalls. Different vendors, different techniques, identical strategy: do not attack the endpoints, attack the systems that everything else trusts.
What Happened
Proofpoint researchers have confirmed that Laundry Bear, the Russian state-sponsored group Microsoft tracks as Void Blizzard, is actively exploiting CVE-2026-42897, a cross-site scripting vulnerability in Microsoft Exchange Outlook Web Access. The exploit is what researchers call "half-click": the victim does not need to click a link or open an attachment. Opening the email in OWA is enough to run attacker-controlled JavaScript in the browser session.
The payload is OWAReaper, described by researchers as the most sophisticated backdoor yet delivered through half-click exploitation. It is an evolution of ZimReaper, the implant used against Zimbra email servers earlier this year, and it is built for one purpose: persistent, long-term mailbox access that survives password resets and credential rotation. Targets so far include government entities across the US and Europe and organisations in telecommunications, financial services, hospitality and aerospace.
In the same window, Cisco confirmed active exploitation of CVE-2026-20316, a static credential vulnerability in Secure Firewall Management Center. Credentials for a low-privilege account are built into the software itself. An unauthenticated remote attacker can simply log in. Affected releases span 7.0 through 10.0, and CISA has added the flaw to its Known Exploited Vulnerabilities catalogue.
Why This One Is Different
Most security programmes are built around a simple assumption: if credentials are compromised, rotate them and the attacker is out. OWAReaper breaks that assumption. Its persistence mechanisms are designed to keep mailbox access after the password changes. The remediation playbook most organisations would reach for first does not work.
The Cisco flaw carries its own uncomfortable lesson. On paper, CVSS 5.3 is a medium. In practice, it grants a foothold inside the platform that manages your firewall estate, from which further vulnerabilities can be chained into privilege escalation. Any organisation that triages patching purely by CVSS score would have deprioritised the exact vulnerability attackers chose to exploit.
Severity scores describe technical characteristics. They do not describe business risk.
The Pattern: Trusted Infrastructure as the Target
The mailbox platform is where credentials are reset, invoices are approved and board papers circulate. The firewall management console is where network defences are configured, logged and, if an attacker holds access, quietly weakened. Neither is an endpoint. Both are control planes. Compromise either and the attacker does not need to defeat your defences, because they are operating from inside the systems that define them.
This is consistent with the broader 2026 pattern: ransomware operators and state actors alike are concentrating on edge devices, identity platforms, management consoles and internet-facing applications, the connective tissue of enterprise IT, rather than user devices protected by mature endpoint tooling.
Commercial Exposure for UK Organisations
Regulatory. A compromised mailbox estate is a personal data breach the moment attacker access is confirmed, which puts organisations on the ICO's 72-hour notification clock under UK GDPR. Firms in scope of DORA or NIS2 through EU operations face parallel incident reporting duties, and FCA and PRA regulated firms must consider operational resilience obligations if a security management platform is affected.
Financial. Long-term mailbox access is the raw material of invoice fraud, payment redirection and executive impersonation. The cost of a mailbox compromise is rarely the incident response bill. It is the mispaid invoice, the leaked negotiation position and the regulatory penalty that follow.
Contractual. Most enterprise contracts now carry security warranties and breach notification clauses. An attacker reading commercial correspondence for weeks before discovery creates disclosure obligations to counterparties, and in some cases termination rights against you.
Governance. Directors are expected to demonstrate oversight of material cyber risk. "We patched by CVSS score" is not a defensible answer when the exploited flaw was a 5.3 that the vendor itself flagged as High. Boards need assurance that patch prioritisation reflects exploitation intelligence and business criticality, not raw scores.
What To Do Now
Immediate actions: apply Microsoft's mitigation guidance for CVE-2026-42897 and patch Cisco Secure FMC against CVE-2026-20316 within 24 hours. Hunt, do not just patch: review OWA logs for indicators associated with OWAReaper, because credential rotation alone will not evict it, and audit FMC access logs for unfamiliar logins from the built-in account. Enforce phishing-resistant MFA on all webmail access. Then step back and ask the structural question: which of your management consoles, identity platforms and email systems are internet-facing, and who is accountable for each one?
Three Questions for Leadership
First: if an attacker held silent access to our executive mailboxes for a month, how would we know? Second: is our patching prioritised by exploitation intelligence and business impact, or by CVSS score? Third: who in our organisation owns the security of the security tools themselves, the consoles, the identity platform and the email estate that everything else depends on?
The Strategic Takeaway
Security spend has poured into endpoints and user awareness for a decade, and attackers have responded rationally: they moved to the layer above. The organisations that absorb this week's lesson will treat mailbox platforms and management consoles as tier-one critical assets with their own threat models, monitoring and accountability. The ones that do not will keep discovering that the breach came through the system they trusted most.
Who owns the security of your security tools?
A focused discussion about your control plane exposure: patch governance, mailbox threat hunting, and board-level cyber risk reporting.
Discuss More →