Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild

2026-05-15T13:24:06Z77af51ba14e0e5865aa945b3bd35342d4c2856090fded926160dacf69e984eae
UAT-8616american-lending-centerchrome-148ciscocredential-theftcve-2026-20182cve-2026-42897cve-2026-46300data-breachexchange-serverfragnesialinux-kernelmicrosoftopenaipatchesprivilege-escalationransomwaresd-wanshai-huludsupply-chaintanstackteamPCPwormzero-day

What happened

This collection highlights multiple high-impact security events: Microsoft disclosed mitigations for an Exchange Server zero-day (CVE-2026-42897) being exploited in the wild pending a patch; Cisco fixed an exploited SD‑WAN zero-day (CVE-2026-20182) tied to threat actor UAT-8616; and a new Linux kernel privilege-escalation bug dubbed "Fragnesia" (CVE-2026-46300) was publicized. Other notable items include a supply-chain incident affecting OpenAI via a TanStack compromise (employee devices and repository credentials stolen), a ransomware-driven data breach at American Lending Center impacting ~

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
77af51ba14e0e5865aa945b3bd35342d4c2856090fded926160dacf69e984eae
Enrichment time
2026-05-15T13:24:06Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild · Baitaphish