Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild
2026-05-15T13:24:06Z•77af51ba14e0e5865aa945b3bd35342d4c2856090fded926160dacf69e984eae
UAT-8616american-lending-centerchrome-148ciscocredential-theftcve-2026-20182cve-2026-42897cve-2026-46300data-breachexchange-serverfragnesialinux-kernelmicrosoftopenaipatchesprivilege-escalationransomwaresd-wanshai-huludsupply-chaintanstackteamPCPwormzero-day
What happened
This collection highlights multiple high-impact security events: Microsoft disclosed mitigations for an Exchange Server zero-day (CVE-2026-42897) being exploited in the wild pending a patch; Cisco fixed an exploited SD‑WAN zero-day (CVE-2026-20182) tied to threat actor UAT-8616; and a new Linux kernel privilege-escalation bug dubbed "Fragnesia" (CVE-2026-46300) was publicized. Other notable items include a supply-chain incident affecting OpenAI via a TanStack compromise (employee devices and repository credentials stolen), a ransomware-driven data breach at American Lending Center impacting ~
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 77af51ba14e0e5865aa945b3bd35342d4c2856090fded926160dacf69e984eae
- Enrichment time
- 2026-05-15T13:24:06Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.