🚨 ACTIVE EXPLOITS & INCIDENTS
- CVE-2026-20182: Critical Cisco Catalyst SD-WAN Auth Bypass Under Active Exploitation (Tenable) CVE-2026-20182 (CVSS 10.0) is a critical authentication bypass in Cisco Catalyst SD-WAN Controller/Manager actively exploited by a sophisticated threat actor (UAT-8616) since 2023. Multiple additional threat clusters have joined exploitation following public PoC release. Patches are available; CISA mandates immediate remediation. All SD-WAN deployments must prioritize patching and monitoring for related IOCs.
🔓 VULNERABILITIES & CVEs
- Mini Shai-Hulud: Self-Propagating Supply Chain Worm Compromising npm & PyPI Packages (Tenable) TeamPCP’s Mini Shai-Hulud worm has compromised 170+ npm and PyPI packages, including those with valid SLSA Build Level 3 provenance attestations, breaching OpenAI and Mistral AI environments. It steals developer and cloud credentials, fully compromising any system that installed affected packages. Immediate audit and rebuild from clean sources recommended.
- CVE-2026-9082: Highly Critical SQL Injection in Drupal Core Affecting PostgreSQL Sites (Tenable) Unauthenticated attackers can exploit this SQL injection in Drupal’s database abstraction layer on PostgreSQL-backed sites. No in-the-wild exploitation reported yet, but PoC and patch diff were published simultaneously with advisory SA-CORE-2026-004. Patches cover six supported branches plus two EOL versions; urgent patching required for PostgreSQL users.
- CVE-2026-46300 “Fragnesia”: New Linux Kernel Local Privilege Escalation with Public PoC (Tenable) Targets Linux kernel XFRM ESP-in-TCP subsystem, distinct from but related to Dirty Frag. Confirmed working exploit on Ubuntu; no reported in-the-wild attacks. Patch released May 13; existing Dirty Frag mitigations do not cover this. Linux hosts should apply kernel updates immediately.
- Dirty Frag (CVE-2026-43284 & CVE-2026-43500): Linux Kernel Privilege Escalation Chain with Public Exploit (Tenable) Two chained Linux kernel vulnerabilities enable local root escalation. Public exploit code is available prior to patch release. This extends the class of Copy Fail-like kernel LPEs. Patch expected imminently; Linux admins should prepare for rapid deployment.
- Copy Fail (CVE-2026-31431): Widespread Linux Kernel Local Privilege Escalation with Reliable Public Exploit (Tenable) Affects nearly all major Linux distros since 2017. Public exploit code is reliable and actively tested in labs. Patches exist but not yet widely deployed. Immediate kernel patching and monitoring for LPE attempts advised.
🕵️ THREAT RESEARCH & DEEP DIVES
- Verizon DBIR 2026: Vulnerability Exploitation Surges as Leading Initial Access Vector (Tenable) Vulnerability exploitation accounts for 31% of breaches, overtaking phishing and credential theft. Median patching time increased by 11 days year-over-year. AI-driven vulnerability discovery and exploitation accelerate risk exposure. Organizations must adopt continuous attack surface management and automated remediation orchestration to keep pace.
📋 VENDOR BULLETINS & LAW ENFORCEMENT
- Microsoft May 2026 Patch Tuesday: 118 CVEs, 16 Critical, No New Zero-Days Exploited (Tenable) Includes fixes across .NET, Azure, M365, and Edge Copilot Chat. Notably, no zero-days exploited in the wild or publicly disclosed this month, a positive shift since June 2024. Critical patches should be prioritized in enterprise environments.
- Oracle April 2026 CPU: 241 CVEs, 34 Critical Across 28 Product Families (Tenable) Second quarterly CPU of 2026 delivers 481 patches, with Oracle Communications hardest hit (139 patches). Critical updates affect core infrastructure components. Oracle customers should expedite patching to reduce attack surface.
📰 LESSER-KNOWN / UNDER-REPORTED
(No significant under-reported items this cycle.)