CVE-2026-42897: Microsoft confirms active exploitation of Exchange Server zero-day

2026-05-15T20:51:55Z60c6418f03278946d5ffe3bd31892b1b2f779159d96562e3120b65dae4abce41
active-exploitationbitlockercisa-kevcisco-sd-wanctfmonexchangefamoussparrowfoxconnfrostyneighborghostwritergreenplasmaincident-responselinux-fragnesiamicrosoftnginxnginx-riftnitrogen-ransomwarepatchingpwn2ownvmware-fusionvulnerability-managementyellowkeyzero-day

What happened

Multiple high-impact vulnerabilities and active campaigns were reported: Microsoft confirmed active exploitation of an Exchange Server zero‑day (CVE-2026-42897, CVSS 8.1). CISA added a critical Cisco Catalyst SD‑WAN flaw (CVE-2026-20182, CVSS 10.0) to its Known Exploited Vulnerabilities catalog. Researchers disclosed NGINX Rift (CVE-2026-42945), a critical 18-year-old heap buffer overflow, and Fragnesia (CVE-2026-46300), a Linux local privilege escalation. Broadcom released a VMware Fusion fix for CVE-2026-41702 (TOCTOU local root). Two new Windows zero-days (YellowKey and GreenPlasma) were 공개

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
60c6418f03278946d5ffe3bd31892b1b2f779159d96562e3120b65dae4abce41
Enrichment time
2026-05-15T20:51:55Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CVE-2026-42897: Microsoft confirms active exploitation of Exchange Server zero-day · Baitaphish