Week in review: Cisco patches SD-WAN 0-day, unpatched Microsoft Exchange Server flaw exploited

2026-05-17T08:51:49Z344ee4c9d2e6081d6ac017a8a45d0f2da9506cdebdeb3dc341fc30cd05f2dbce
AI agentsAkamaiCiscoContext‑Aware AccessExchangeGoogle WorkspaceKeycardLayerXMicrosoftRocky LinuxSAMLSD‑WANTelegramXSSauthentication bypassdeepfake detectionexpired domainsgenerative modelsiPhone theftsecure enterprise browsersecurity repositorysupply chain/trustunlocking toolszero‑dayzombie linkages

What happened

This week’s roundup highlights multiple actively exploited vulnerabilities and notable security industry moves. Cisco patched an actively exploited Catalyst SD‑WAN authentication bypass (CVE‑2026‑20182) impacting on‑prem and cloud SD‑WAN Controller/Manager deployments. Microsoft warned that a critical XSS in on‑prem Exchange Server (CVE‑2026‑42897) is being exploited; mitigations are available while a permanent fix is developed. Other items: Google Workspace added a default Context‑Aware Access policy for SAML apps; Akamai agreed to acquire LayerX to extend secure/browser‑based AI controls; a​

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
344ee4c9d2e6081d6ac017a8a45d0f2da9506cdebdeb3dc341fc30cd05f2dbce
Enrichment time
2026-05-17T08:51:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.