Microsoft Exchange Zero-Day Under Attack, No Patch Available
2026-05-19T08:51:40Z•15fe04472e6c2fd42c05d81868ce70cd768b4daad3b508571b971c0d8236ec5b
CVE-2026-42897OWAai-agentschrome-abe-bypasscisco-sd-wancredential-theftcvss-10dirty-fragexchangehugging-faceinstructurenpmopenclawpcpjackprivilege-escalationshai-huludshinyhunterssupply-chainteampcptokenizer-manipulationtrustfall-code-execution','ot-ics','fuel-tank-atg','foxconn','r-voidstealerwormxsszero-day
What happened
A broad set of active and emerging threats reported across enterprise, cloud, supply-chain and OT environments: an unpatched Microsoft Exchange OWA XSS zero-day (CVE-2026-42897) is being exploited in the wild; a CVSS 10.0 Cisco SD‑WAN vulnerability is likewise under active exploitation; the public release of Shai‑Hulud worm source and follow-on npm/package infections are expanding supply‑chain risk; AI agents and LLMs are being weaponized for exploit development, automated attacks, and bespoke malware; OpenClaw agent-framework flaws (now patched) allowed credential theft, privilege escalation,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 15fe04472e6c2fd42c05d81868ce70cd768b4daad3b508571b971c0d8236ec5b
- Enrichment time
- 2026-05-19T08:51:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.