On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email
2026-05-15T07:24:09Z•7fe5a5966ff7bc1b0d1b161178120e6ab32ca838ec073d2c6dd8b4098fd2a176
CISA-KEVactive-exploitationai-frameworkauthentication-bypasscisco-sd-wanexchange-servereximlinux-kernelnginxnpm-malwarephishingprivilege-escalationremote-code-executionrubygemssupply-chainzero-day
What happened
Multiple high-impact vulnerabilities and active attacks were reported across enterprise and open-source software: a spoofing/XSS bug in on-prem Microsoft Exchange (CVE-2026-42897) is being exploited; a maximum-severity authentication bypass in Cisco Catalyst SD‑WAN Controller (CVE-2026-20182, CVSS 10.0) is actively exploited and added to CISA KEV; Exim BDAT memory-corruption/possible RCE (CVE-2026-45185, "Dead.Letter") and an 18‑year NGINX rewrite-module heap overflow (CVE-2026-42945) allow high‑severity remote code execution; a Linux kernel page‑cache LPE (CVE-2026-46300) grants local root; a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 7fe5a5966ff7bc1b0d1b161178120e6ab32ca838ec073d2c6dd8b4098fd2a176
- Enrichment time
- 2026-05-15T07:24:09Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.