🚨 ACTIVE EXPLOITS & INCIDENTS
- CVE-2026-20182: Critical Cisco Catalyst SD-WAN Auth Bypass Under Active Exploitation (Tenable) A critical CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN Controller/Manager is actively exploited by a sophisticated actor (UAT-8616) since 2023, with 10+ other clusters leveraging public PoCs post-disclosure (May 14). Immediate patching is mandated by CISA; unpatched systems are fully compromised.
- Mini Shai-Hulud: Self-Propagating Supply Chain Worm Hits npm & PyPI (Tenable) TeamPCP’s worm compromised 170+ npm/PyPI packages, including those with valid SLSA Level 3 provenance, stealing developer and cloud credentials. Systems with these packages must be treated as fully compromised. This is a new class of supply chain attack defeating build integrity controls—urgent audit and remediation required.
🔓 VULNERABILITIES & CVEs
- CVE-2026-9082: Highly Critical SQL Injection in Drupal Core (SA-CORE-2026-004) (Tenable) Unauthenticated SQLi in Drupal’s database abstraction layer affects PostgreSQL-backed sites, CVSS 9.8. No in-the-wild exploitation yet, but PoC and patch diff published simultaneously with advisory (May 20). Patch immediately if running affected Drupal versions, including some EOL branches.
- CVE-2026-31431 “Copy Fail”: Linux Kernel Local Privilege Escalation (Tenable) A high-severity LPE affecting virtually all major Linux distros since 2017, with reliable public exploit code. Patched kernels exist but many distros lag in updates. Treat exposed Linux hosts as high risk until patched.
- CVE-2026-43284 & CVE-2026-43500 “Dirty Frag”: Linux Kernel Privilege Escalation Chain (Tenable) New chained LPE vulnerabilities with public exploits extend the “Copy Fail” bug class. Patches pending but imminent. Linux hosts should be prioritized for patching once updates are released.
- CVE-2026-46300 “Fragnesia”: Linux Kernel Privilege Escalation (Tenable) Latest Linux kernel LPE with public PoC targeting XFRM ESP-in-TCP subsystem, distinct from Dirty Frag. Patch released May 13; module blacklist mitigations help but patching is recommended. No in-the-wild exploitation reported yet.
📋 VENDOR BULLETINS & LAW ENFORCEMENT
- Microsoft May 2026 Patch Tuesday: 118 CVEs, 16 Critical (Tenable) No zero-days exploited in the wild this month, a positive shift since June 2024. Patches cover .NET, Azure services, M365 agents, and more. Critical to deploy promptly to maintain defense-in-depth and reduce attack surface.
- Oracle April 2026 CPU: 241 CVEs, 34 Critical Across 28 Product Families (Tenable) Second quarterly CPU for 2026 with 481 patches, including critical fixes in Oracle Communications (139 patches). Organizations running Oracle products should prioritize patching critical and high-severity updates immediately.
🕵️ THREAT RESEARCH & DEEP DIVES
- Verizon DBIR 2026: Vulnerability Exploitation Surges as Leading Breach Vector (Tenable) Vulnerability exploitation now accounts for 31% of breaches, overtaking phishing. Median patch time increased by 11 days YoY. AI-driven discovery and exploitation accelerate risk, underscoring the need for continuous exposure management and automated remediation orchestration.
📰 LESSER-KNOWN / UNDER-REPORTED
- No significant under-reported items this cycle.