Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own

2026-05-15T19:23:36Z2ebc45bee77d7693a8f74639e195b0afea18893e36e99dfeff20fdfd5a0b04b2
Avada BuilderCiscoDoSEdgeMicrosoft ExchangeNGINXOpenAIPwn2OwnRCESD-WANTanStackWindows 11WordPresscredential-theftinfostealernode-ipcnpmsession-theftsocial-engineeringsource-code-leaksupply-chainzero-day

What happened

A roundup of active high-impact security incidents: Pwn2Own Berlin 2026 disclosures and exploits against Windows 11, Edge, Microsoft Exchange and other products; multiple supply-chain compromises (notably node-ipc/npm and the TanStack incident that impacted OpenAI, prompting code-signing rotations); credential- and session-stealing campaigns (REMUS infostealer and node-ipc backdoor); WordPress plugin vulnerabilities (Avada Builder and Burst Statistics) enabling credential/database theft and full admin takeover; a critical, actively exploited Cisco Catalyst SD‑WAN authentication bypass (CVE-202

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
2ebc45bee77d7693a8f74639e195b0afea18893e36e99dfeff20fdfd5a0b04b2
Enrichment time
2026-05-15T19:23:36Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.