🚨 ACTIVE EXPLOITS & INCIDENTS
- CVE-2026-20182: Critical Cisco Catalyst SD-WAN Authentication Bypass Under Active Exploitation — Tenable A critical (CVSS 10.0) auth bypass in Cisco Catalyst SD-WAN Controller/Manager is actively exploited by a sophisticated threat actor (UAT-8616) since 2023, with 10+ additional clusters leveraging PoC code after public disclosure on May 14. Immediate patching is mandated by CISA; all supported versions have fixes available. Networks using Cisco SD-WAN must prioritize remediation to prevent unauthorized access and lateral movement.
🔓 VULNERABILITIES & CVEs
- CVE-2026-9082: Highly Critical SQL Injection in Drupal Core — Tenable Unauthenticated attackers can exploit this SQLi in Drupal’s database abstraction layer on PostgreSQL-backed sites. CVSS details not explicitly stated but rated highly critical. No in-the-wild exploitation yet, but public PoC and patch diff released simultaneously with advisory (SA-CORE-2026-004). Patches cover six supported branches plus select EOL versions. Urgent patching advised for all PostgreSQL Drupal deployments.
- CVE-2026-31431 “Copy Fail”: Linux Kernel Local Privilege Escalation — Tenable A high-severity LPE affecting nearly all major Linux distros since 2017, with reliable public exploit code available. Kernel patches exist but many distros lag in deployment. This flaw allows local users to escalate to root, increasing risk in multi-tenant or shared environments. Review kernel versions and patch urgently.
- CVE-2026-43284 & CVE-2026-43500 “Dirty Frag”: Linux Kernel Privilege Escalation Chain — Tenable New chained LPE vulnerabilities with public exploits extending the “Copy Fail” attack class. Patches pending release, but exploit code is circulating. Immediate monitoring and patching recommended once updates are available.
- CVE-2026-46300 “Fragnesia”: Linux Kernel Privilege Escalation — Tenable A new local privilege escalation with public PoC targeting the XFRM ESP-in-TCP subsystem, distinct from Dirty Frag but in the same kernel area. Confirmed working on Ubuntu; no in-the-wild exploitation reported yet. Patch released May 13; existing mitigations (module blacklist) help reduce risk.
🕵️ THREAT RESEARCH & DEEP DIVES
- Mini Shai-Hulud: Self-Propagating Worm Compromises 170+ npm & PyPI Packages — Tenable TeamPCP group’s supply chain campaign defeated SLSA Build Level 3 provenance attestation, compromising developer and cloud credentials across npm and PyPI ecosystems, including OpenAI and Mistral AI packages. Any system installing affected packages should be treated as fully compromised. This marks a critical evolution in supply chain attacks, emphasizing the need for continuous provenance validation and credential hygiene.
- Verizon DBIR 2026: Vulnerability Exploitation Surges as Leading Breach Vector — Tenable Vulnerability exploitation now accounts for 31% of initial breach access, overtaking phishing. Median patch time increased by 11 days year-over-year, exacerbated by AI-driven vulnerability discovery and exploitation. Organizations must accelerate exposure management and automate remediation to keep pace with attacker capabilities.
📋 VENDOR BULLETINS & LAW ENFORCEMENT
- Microsoft May 2026 Patch Tuesday: 118 CVEs, 16 Critical — Tenable No zero-days exploited in the wild this month, a positive shift since June 2024. Patches cover a broad range of Microsoft products including .NET, Azure services, and Edge components. Critical patches should be prioritized to maintain defense-in-depth.
- Oracle April 2026 CPU: 241 CVEs, 34 Critical — Tenable Second quarterly update for 2026 includes 481 patches across 28 product families. Oracle Communications products received the most patches (139). Critical patches represent 7.1% of total fixes. Immediate review and patching recommended for Oracle environments.
📰 LESSER-KNOWN / UNDER-REPORTED
- No significant under-reported items this cycle.