U.S. CISA adds a flaw in Microsoft Exchange Server to its Known Exploited Vulnerabilities catalog

2026-05-16T20:51:44Z3b8f19357ad6709fb66990730242896dfb5cbf69c7712912037dc0d7ba6dcbfd
BitLockerCISA KEVCTFMONCVE-2026-20182CVE-2026-42897CVE-2026-46300Cisco Catalyst SD‑WANFragnesiaFrostyNeighborGhostwriterGreenPlasmaKazuarLinux kernelMicrosoft ExchangeOpenAIP2P botnetPwn2OwnTanStackTurlaYellowKeyactive exploitationprivilege escalationsupply chainzero-day

What happened

Multiple high-impact vulnerabilities and active campaigns were reported: CISA added Microsoft Exchange Server vulnerability CVE-2026-42897 (CVSS 8.1, XSS) to its Known Exploited Vulnerabilities catalog and Microsoft confirmed active exploitation. CISA also added a Cisco Catalyst SD‑WAN flaw (CVE-2026-20182, CVSS 10.0) to KEV. OpenAI was hit by a TanStack supply‑chain attack that compromised two employee devices and exposed repository credentials. Russia-linked Turla evolved its Kazuar backdoor into a modular P2P botnet for stealthy, long-term access. Pwn2Own Berlin 2026 revealed many zero-days

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
3b8f19357ad6709fb66990730242896dfb5cbf69c7712912037dc0d7ba6dcbfd
Enrichment time
2026-05-16T20:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.