GCS Threat Briefing
Threat Landscape

Two Zero-Days, One Lesson: Attackers Are Coming for Your Control Plane

G
Jonathan Garzon
Founder & CEO, Garzon Cyber Solutions
30 July 2026 · 7 min read
Two Zero-Days, One Lesson: Attackers Are Coming for Your Control Plane - GCS Threat Briefing cover

Two actively exploited zero-days were confirmed this week. One gives Russian state-sponsored attackers long-term access to corporate mailboxes through Outlook Web Access. The other hands unauthenticated attackers a way into the console that manages Cisco firewalls. Different vendors, different techniques, identical strategy: do not attack the endpoints, attack the systems that everything else trusts.

Half-clickOpening an email in OWA is enough to trigger CVE-2026-42897
CVSS 5.3The actively exploited Cisco FMC flaw, still rated High severity
72 hrsICO notification window once a mailbox compromise is confirmed

What Happened

Proofpoint researchers have confirmed that Laundry Bear, the Russian state-sponsored group Microsoft tracks as Void Blizzard, is actively exploiting CVE-2026-42897, a cross-site scripting vulnerability in Microsoft Exchange Outlook Web Access. The exploit is what researchers call "half-click": the victim does not need to click a link or open an attachment. Opening the email in OWA is enough to run attacker-controlled JavaScript in the browser session.

The payload is OWAReaper, described by researchers as the most sophisticated backdoor yet delivered through half-click exploitation. It is an evolution of ZimReaper, the implant used against Zimbra email servers earlier this year, and it is built for one purpose: persistent, long-term mailbox access that survives password resets and credential rotation. Targets so far include government entities across the US and Europe and organisations in telecommunications, financial services, hospitality and aerospace.

In the same window, Cisco confirmed active exploitation of CVE-2026-20316, a static credential vulnerability in Secure Firewall Management Center. Credentials for a low-privilege account are built into the software itself. An unauthenticated remote attacker can simply log in. Affected releases span 7.0 through 10.0, and CISA has added the flaw to its Known Exploited Vulnerabilities catalogue.

Timeline of the OWAReaper campaign from Zimbra to Exchange alongside the Cisco FMC disclosure, July 2026
From Zimbra to Exchange in weeks: the OWAReaper campaign timeline alongside the Cisco FMC disclosure.

Why This One Is Different

Most security programmes are built around a simple assumption: if credentials are compromised, rotate them and the attacker is out. OWAReaper breaks that assumption. Its persistence mechanisms are designed to keep mailbox access after the password changes. The remediation playbook most organisations would reach for first does not work.

The Cisco flaw carries its own uncomfortable lesson. On paper, CVSS 5.3 is a medium. In practice, it grants a foothold inside the platform that manages your firewall estate, from which further vulnerabilities can be chained into privilege escalation. Any organisation that triages patching purely by CVSS score would have deprioritised the exact vulnerability attackers chose to exploit.

Severity scores describe technical characteristics. They do not describe business risk.

The Pattern: Trusted Infrastructure as the Target

Comparison of the Exchange OWA zero-day CVE-2026-42897 and the Cisco FMC static credential flaw CVE-2026-20316
Two zero-days, one strategy: both attacks target the layer that everything else trusts.

The mailbox platform is where credentials are reset, invoices are approved and board papers circulate. The firewall management console is where network defences are configured, logged and, if an attacker holds access, quietly weakened. Neither is an endpoint. Both are control planes. Compromise either and the attacker does not need to defeat your defences, because they are operating from inside the systems that define them.

This is consistent with the broader 2026 pattern: ransomware operators and state actors alike are concentrating on edge devices, identity platforms, management consoles and internet-facing applications, the connective tissue of enterprise IT, rather than user devices protected by mature endpoint tooling.

Commercial Exposure for UK Organisations

Regulatory. A compromised mailbox estate is a personal data breach the moment attacker access is confirmed, which puts organisations on the ICO's 72-hour notification clock under UK GDPR. Firms in scope of DORA or NIS2 through EU operations face parallel incident reporting duties, and FCA and PRA regulated firms must consider operational resilience obligations if a security management platform is affected.

Financial. Long-term mailbox access is the raw material of invoice fraud, payment redirection and executive impersonation. The cost of a mailbox compromise is rarely the incident response bill. It is the mispaid invoice, the leaked negotiation position and the regulatory penalty that follow.

Contractual. Most enterprise contracts now carry security warranties and breach notification clauses. An attacker reading commercial correspondence for weeks before discovery creates disclosure obligations to counterparties, and in some cases termination rights against you.

Governance. Directors are expected to demonstrate oversight of material cyber risk. "We patched by CVSS score" is not a defensible answer when the exploited flaw was a 5.3 that the vendor itself flagged as High. Boards need assurance that patch prioritisation reflects exploitation intelligence and business criticality, not raw scores.

What To Do Now

Response priorities infographic listing immediate actions for Exchange OWA and Cisco FMC, ordered by urgency
Response priorities: patch, hunt, then reassess how you prioritise.

Immediate actions: apply Microsoft's mitigation guidance for CVE-2026-42897 and patch Cisco Secure FMC against CVE-2026-20316 within 24 hours. Hunt, do not just patch: review OWA logs for indicators associated with OWAReaper, because credential rotation alone will not evict it, and audit FMC access logs for unfamiliar logins from the built-in account. Enforce phishing-resistant MFA on all webmail access. Then step back and ask the structural question: which of your management consoles, identity platforms and email systems are internet-facing, and who is accountable for each one?

Three Questions for Leadership

First: if an attacker held silent access to our executive mailboxes for a month, how would we know? Second: is our patching prioritised by exploitation intelligence and business impact, or by CVSS score? Third: who in our organisation owns the security of the security tools themselves, the consoles, the identity platform and the email estate that everything else depends on?

The Strategic Takeaway

Security spend has poured into endpoints and user awareness for a decade, and attackers have responded rationally: they moved to the layer above. The organisations that absorb this week's lesson will treat mailbox platforms and management consoles as tier-one critical assets with their own threat models, monitoring and accountability. The ones that do not will keep discovering that the breach came through the system they trusted most.

Who owns the security of your security tools?

A focused discussion about your control plane exposure: patch governance, mailbox threat hunting, and board-level cyber risk reporting.

Discuss More →
Sources: Cisco Security Advisory (Secure Firewall Management Center Static Credential Vulnerability) · Proofpoint Threat Insight, July 2026 · BleepingComputer, July 2026 · The Hacker News, July 2026 · CISA Known Exploited Vulnerabilities catalogue · Infosecurity Magazine, July 2026
Zero-Day Microsoft Exchange Cisco FMC State-Sponsored Threats Patch Governance UK GDPR Board Governance