CVE-2026-42897: Microsoft confirms active exploitation of Exchange Server zero-day

2026-05-15T14:51:49Z1f054f7a5449e676e0bc13b3f31cff18d4b2f5476b8e7fa09623605870ff2b32
CVE-2026-20182CVE-2026-41702CVE-2026-42897CVE-2026-42945CVE-2026-46300aptbitlockercisa-kevcisco-catalyst-sd-wancriticalctfmonexchange-serverfamoussparrowfoxconnfragnesiaghostwritergreenplasmanginx-riftnitrogen-ransomwarepwn2ownransomwarevmware-fusionxssyellowkeyzero-day

What happened

Multiple high-impact security incidents and disclosures were reported: Microsoft confirmed active exploitation of an Exchange Server zero-day (CVE-2026-42897, XSS, CVSS 8.1). CISA added a Cisco Catalyst SD‑WAN vulnerability (CVE-2026-20182, CVSS 10.0) to its Known Exploited Vulnerabilities catalog. Researchers disclosed two Windows zero-days dubbed YellowKey and GreenPlasma affecting BitLocker and the CTFMON framework. A critical 18-year-old NGINX heap overflow (NGINX Rift, CVE-2026-42945) was revealed. Privilege-escalation/local-root flaws were published for the Linux kernel (Fragnesia, CVE-0

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
1f054f7a5449e676e0bc13b3f31cff18d4b2f5476b8e7fa09623605870ff2b32
Enrichment time
2026-05-15T14:51:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CVE-2026-42897: Microsoft confirms active exploitation of Exchange Server zero-day · Baitaphish