Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own
2026-05-15T19:23:36Z•2ebc45bee77d7693a8f74639e195b0afea18893e36e99dfeff20fdfd5a0b04b2
Avada BuilderCiscoDoSEdgeMicrosoft ExchangeNGINXOpenAIPwn2OwnRCESD-WANTanStackWindows 11WordPresscredential-theftinfostealernode-ipcnpmsession-theftsocial-engineeringsource-code-leaksupply-chainzero-day
What happened
A roundup of active high-impact security incidents: Pwn2Own Berlin 2026 disclosures and exploits against Windows 11, Edge, Microsoft Exchange and other products; multiple supply-chain compromises (notably node-ipc/npm and the TanStack incident that impacted OpenAI, prompting code-signing rotations); credential- and session-stealing campaigns (REMUS infostealer and node-ipc backdoor); WordPress plugin vulnerabilities (Avada Builder and Burst Statistics) enabling credential/database theft and full admin takeover; a critical, actively exploited Cisco Catalyst SD‑WAN authentication bypass (CVE-202
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 2ebc45bee77d7693a8f74639e195b0afea18893e36e99dfeff20fdfd5a0b04b2
- Enrichment time
- 2026-05-15T19:23:36Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.