🚨 ACTIVE EXPLOITS & INCIDENTS
- Cisco Catalyst SD-WAN Vulnerabilities Under Active Exploitation (CVE-2026-20182) — Tenable Critical (CVSS 10.0) authentication bypass in Cisco Catalyst SD-WAN Controller/Manager is actively exploited by multiple threat clusters, including a sophisticated actor UAT-8616 since 2023. Public PoCs have accelerated exploitation post-disclosure (May 14). Immediate patching is mandatory; CISA has issued a remediation directive.
- Netherlands Seizes 800 Servers of Hosting Firm Enabling Cyberattacks — BleepingComputer Dutch FIOD arrested two suspects and seized 800 servers linked to a hosting provider facilitating cyberattacks, interference ops, and disinformation campaigns. This disruption impacts infrastructure used by multiple threat actors for ransomware, DDoS, and data theft operations.
- Global Takedown of Criminal VPN Used by 25 Ransomware Groups — The Hacker News Law enforcement in Europe and North America dismantled a criminal VPN service used extensively by ransomware gangs for anonymizing attacks, data theft, and scanning. The operation led by France and the Netherlands disrupts a key enabler of ransomware campaigns since Dec 2025.
🔓 VULNERABILITIES & CVEs
- CVE-2026-9082: Critical SQL Injection in Drupal Core (SA-CORE-2026-004) — Tenable A highly critical SQLi (CVSS 9.8) affects Drupal core’s database abstraction layer on PostgreSQL sites, exploitable without authentication. Detection PoCs and patch diffs were publicly released immediately after advisory (May 20). Thousands of sites are reportedly targeted in early exploitation attempts. Patch immediately.
- CVE-2026-31431 “Copy Fail”: Linux Kernel Local Privilege Escalation — Tenable A high severity LPE affecting Linux kernels since 2017 with reliable public exploits is confirmed. This flaw allows local users root access on virtually all major distros. Patch status varies; unpatched systems remain fully compromised if exploited.
- “Dirty Frag” Linux Kernel Privilege Escalation Chain (CVE-2026-43284, CVE-2026-43500) — Tenable Following Copy Fail, this chained LPE vulnerability also has public exploit code available pre-patch release. It targets the same kernel subsystem and enables local root escalation. Urgent patching advised once updates are available.
- CVE-2026-46300 “Fragnesia”: New Linux Kernel LPE with Public PoC — Tenable A new high severity local privilege escalation in Linux kernel’s XFRM ESP-in-TCP subsystem, distinct from Dirty Frag, with a public exploit confirmed on Ubuntu. Patch released May 13; module blacklist mitigations help but full patching is recommended.
🕵️ THREAT RESEARCH & DEEP DIVES
- Mini Shai-Hulud: Self-Propagating Worm Compromising npm and PyPI Packages — Tenable TeamPCP’s worm has infected 170+ npm and PyPI packages, bypassing SLSA Build Level 3 provenance attestations, stealing developer and cloud credentials, including from OpenAI and Mistral AI ecosystems. Any system installing affected packages should be treated as fully compromised. Review supply chain security urgently.
- Verizon DBIR 2026: Vulnerability Exploitation Surges as Leading Breach Vector — Tenable Vulnerability exploitation now accounts for 31% of breaches, surpassing phishing and credential theft. Median patch times have increased by 11 days year-over-year, exacerbated by AI-accelerated discovery and exploitation. Emphasizes need for continuous exposure management and automated remediation.
📋 VENDOR BULLETINS & LAW ENFORCEMENT
- Microsoft May 2026 Patch Tuesday: 118 CVEs, 16 Critical, No Zero-Days Exploited — Tenable Microsoft patched 118 CVEs including critical fixes across .NET, Azure, M365, and Edge components. Notably, no zero-days exploited in the wild were reported for the first time since June 2024. Prioritize patching critical updates to reduce attack surface.
- Oracle April 2026 CPU: 241 CVEs, 34 Critical — Tenable Oracle’s second quarterly CPU addresses 241 CVEs with 481 patches across 28 product families, including 34 critical vulnerabilities. Oracle Communications products received the highest patch volume. Review and deploy updates promptly.
📰 LESSER-KNOWN / UNDER-REPORTED
- No significant under-reported items this cycle.