{
 "description": "Evidence-bound MITRE ATT&CK techniques observed in ctipilot.ch entries referencing Microsoft Exchange Server Outlook Web Access stored XSS (CWE-79, CVSS 3.1 8.1, Microsoft CNA) \u2014 exploited in the wild by TA488/LAUNDRY BEAR to deliver the OWAReaper browser implant; CISA KEV 2026-05-15; permanent fix is the July 2026 Exchange SU (SE RTM; 2019 CU14/CU15 and 2016 CU23 via ESU Period 2), which does not remove earlier mitigations. Score = number of published entries mapping the technique. Pinned dataset: ATT&CK v19.2.",
 "domain": "enterprise-attack",
 "gradient": {
  "colors": [
   "#ffe766",
   "#ff6666"
  ],
  "maxValue": 2,
  "minValue": 0
 },
 "hideDisabled": false,
 "layout": {
  "layout": "side",
  "showID": true,
  "showName": true
 },
 "legendItems": [],
 "metadata": [
  {
   "name": "source",
   "value": "ctipilot.ch"
  },
  {
   "name": "entity",
   "value": "CVE-2026-42897"
  },
  {
   "name": "attack_version",
   "value": "19.2"
  }
 ],
 "name": "Microsoft Exchange Server Outlook Web Access stored XSS (CWE-79, CVSS 3.1 8.1, Microsoft CNA) \u2014 exploited in the wild by TA488/LAUNDRY BEAR to deliver the OWAReaper browser implant; CISA KEV 2026-05-15; permanent fix is the July 2026 Exchange SU (SE RTM; 2019 CU14/CU15 and 2016 CU23 via ESU Period 2), which does not remove earlier mitigations \u2014 ctipilot.ch coverage",
 "sorting": 3,
 "techniques": [
  {
   "comment": "entries: 2026-07-31/ta488-exchange-owa-cve-2026-42897-owareaper-implant",
   "score": 1,
   "techniqueID": "T1027"
  },
  {
   "comment": "entries: 2026-05-16/microsoft-exchange-cve-2026-42897-active-exploitation-withou",
   "score": 1,
   "showSubtechniques": true,
   "techniqueID": "T1059"
  },
  {
   "comment": "entries: 2026-05-16/microsoft-exchange-cve-2026-42897-active-exploitation-withou",
   "score": 1,
   "techniqueID": "T1059.007"
  },
  {
   "comment": "entries: 2026-07-31/ta488-exchange-owa-cve-2026-42897-owareaper-implant",
   "score": 1,
   "techniqueID": "T1071.001"
  },
  {
   "comment": "entries: 2026-07-31/ta488-exchange-owa-cve-2026-42897-owareaper-implant",
   "score": 1,
   "techniqueID": "T1071.004"
  },
  {
   "comment": "entries: 2026-05-16/microsoft-exchange-cve-2026-42897-active-exploitation-withou",
   "score": 1,
   "techniqueID": "T1078"
  },
  {
   "comment": "entries: 2026-07-31/ta488-exchange-owa-cve-2026-42897-owareaper-implant",
   "score": 1,
   "techniqueID": "T1098.002"
  },
  {
   "comment": "entries: 2026-07-31/ta488-exchange-owa-cve-2026-42897-owareaper-implant",
   "score": 1,
   "techniqueID": "T1102.001"
  },
  {
   "comment": "entries: 2026-05-16/microsoft-exchange-cve-2026-42897-active-exploitation-withou, 2026-07-31/ta488-exchange-owa-cve-2026-42897-owareaper-implant",
   "score": 2,
   "techniqueID": "T1185"
  },
  {
   "comment": "entries: 2026-07-31/ta488-exchange-owa-cve-2026-42897-owareaper-implant",
   "score": 1,
   "techniqueID": "T1203"
  },
  {
   "comment": "entries: 2026-05-16/microsoft-exchange-cve-2026-42897-active-exploitation-withou",
   "score": 1,
   "techniqueID": "T1534"
  },
  {
   "comment": "entries: 2026-07-31/ta488-exchange-owa-cve-2026-42897-owareaper-implant",
   "score": 1,
   "techniqueID": "T1552"
  },
  {
   "comment": "entries: 2026-05-16/microsoft-exchange-cve-2026-42897-active-exploitation-withou, 2026-07-31/ta488-exchange-owa-cve-2026-42897-owareaper-implant",
   "score": 2,
   "showSubtechniques": true,
   "techniqueID": "T1566"
  },
  {
   "comment": "entries: 2026-05-16/microsoft-exchange-cve-2026-42897-active-exploitation-withou",
   "score": 1,
   "techniqueID": "T1566.001"
  },
  {
   "showSubtechniques": true,
   "techniqueID": "T1071"
  },
  {
   "showSubtechniques": true,
   "techniqueID": "T1098"
  },
  {
   "showSubtechniques": true,
   "techniqueID": "T1102"
  }
 ],
 "versions": {
  "attack": "19",
  "layer": "4.5",
  "navigator": "5.1.0"
 }
}