PoC Code Published for Critical NGINX Vulnerability
2026-05-16T13:24:28Z•088545131a8bc3e808f0bd8fd14699a56d90aea85de92933e1474baf32769a10
american-lending-centerchrome-148ciscocve-2026-20182cve-2026-42897cve-2026-46300data-breachexchange-serverexploitfragnesialinux-kernelnginxnginx-plusopenaiproof-of-conceptsd-wanshai-huludsupply-chaintanstackteampcpuat-8616zero-day
What happened
Multiple high-impact vulnerabilities and active exploits were reported across widely used infrastructure and software. A critical NGINX flaw (introduced in 2008) was patched and PoC code published; Microsoft disclosed mitigations for an Exchange Server zero-day (CVE-2026-42897) being exploited in the wild; Cisco patched an actively exploited SD‑WAN zero-day (CVE-2026-20182) tied to threat actor UAT-8616; and a new Linux kernel local root escalation (Fragnesia, CVE-2026-46300) was disclosed. Other notable incidents include OpenAI being impacted by a TanStack supply‑chain attack (employee device
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 088545131a8bc3e808f0bd8fd14699a56d90aea85de92933e1474baf32769a10
- Enrichment time
- 2026-05-16T13:24:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.