PoC Code Published for Critical NGINX Vulnerability

2026-05-16T13:24:28Z088545131a8bc3e808f0bd8fd14699a56d90aea85de92933e1474baf32769a10
american-lending-centerchrome-148ciscocve-2026-20182cve-2026-42897cve-2026-46300data-breachexchange-serverexploitfragnesialinux-kernelnginxnginx-plusopenaiproof-of-conceptsd-wanshai-huludsupply-chaintanstackteampcpuat-8616zero-day

What happened

Multiple high-impact vulnerabilities and active exploits were reported across widely used infrastructure and software. A critical NGINX flaw (introduced in 2008) was patched and PoC code published; Microsoft disclosed mitigations for an Exchange Server zero-day (CVE-2026-42897) being exploited in the wild; Cisco patched an actively exploited SD‑WAN zero-day (CVE-2026-20182) tied to threat actor UAT-8616; and a new Linux kernel local root escalation (Fragnesia, CVE-2026-46300) was disclosed. Other notable incidents include OpenAI being impacted by a TanStack supply‑chain attack (employee device

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
088545131a8bc3e808f0bd8fd14699a56d90aea85de92933e1474baf32769a10
Enrichment time
2026-05-16T13:24:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · PoC Code Published for Critical NGINX Vulnerability · Baitaphish