Microsoft Exchange Zero-Day Under Attack, No Patch Available
2026-05-19T02:52:00Z•d478d1565c7359d6d735c4c6055a41b14d63feea610d7f1570d7fb6728d9f56b
ATGCVE-2026-42897OWAXSSactive-exploitationai-agent-frameworkcisco-sd-wancode-releasecredential-theftcvss-10.0data-dead-dropfuel-tankhugging-faceics-ot-security','foxconn','nitrogen-ransomware','ransomware','fmicrosoft-exchangeno-patchopenclawpersistenceprivilege-escalationruby-gemsshai-huludsupply-chaintokenizerwormzero-day
What happened
A batch of high-risk incidents and disclosures is highlighted: a Microsoft Exchange zero-day (CVE-2026-42897) — an XSS in Outlook Web Access — is under active attack with no patch available and can enable mailbox compromise; a separate, CVSS 10.0 Cisco SD‑WAN vulnerability is being actively exploited in the wild; several supply-chain and AI-related flaws were disclosed including weaponized Hugging Face tokenizer files and malicious RubyGems packages used as data dead drops; the OpenClaw AI agent framework had now-patched flaws that could enable credential theft, privilege escalation, and persi
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- d478d1565c7359d6d735c4c6055a41b14d63feea610d7f1570d7fb6728d9f56b
- Enrichment time
- 2026-05-19T02:52:00Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.