cybersecurityzero-day vulnerabilitymicrosoft exchange serverdata breachcanada

Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

July 29, 2026

Back to all posts

Source: BleepingComputer

Recent reports indicate that Russian state-sponsored hacking group Hafnium has been exploiting a zero-day vulnerability in Microsoft Exchange Server's Outlook Web Access (OWA). The flaw, tracked as CVE-2021-26855, allows attackers to gain access to mailbox contents and maintain long-term access by setting up their own web shell. This breach could lead to data theft, intellectual property loss, and potentially provide a foothold for further attacks within the targeted network. As Canadian SMBs heavily rely on digital communication, this vulnerability poses a significant threat to businesses operating in Canada. To mitigate risks, it's essential to apply Microsoft's security updates and patches immediately to secure Exchange Server environments.
cybersecurityzero-day vulnerabilitymicrosoft exchange serverdata breachcanada

Concerned about this threat to your business?

We help Canadian SMBs deploy the controls discussed in this article. Free 30-minute assessment — no obligation.

Book a free assessment