🚨 ACTIVE EXPLOITS & INCIDENTS
- CVE-2026-20182: Critical Cisco Catalyst SD-WAN Authentication Bypass Under Active Exploitation (Tenable) A critical CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN Controller and Manager is actively exploited by a sophisticated threat actor (UAT-8616) since 2023, alongside 10 other clusters leveraging public PoCs. Immediate patching is mandatory as CISA has mandated remediation.
🔓 VULNERABILITIES & CVEs
- CVE-2026-9082: Highly Critical SQL Injection in Drupal Core (SA-CORE-2026-004) (Tenable) Unauthenticated SQL injection in Drupal’s database abstraction layer affects PostgreSQL-backed sites. CVSS 9.8, with public PoC and patch diff released simultaneously with advisory. No in-the-wild exploitation reported yet, but urgent patching is advised across all supported branches including select EOL versions.
- CVE-2026-31431 “Copy Fail”: Linux Kernel Local Privilege Escalation (Tenable) A high severity LPE affecting virtually all major Linux distros since 2017 with reliable public exploit code. Patched kernels exist but many distros lag on updates. Immediate kernel patching or mitigations recommended to prevent local root compromise.
- CVE-2026-43284 & CVE-2026-43500 “Dirty Frag”: Linux Kernel Privilege Escalation Chain (Tenable) New chained LPE vulnerabilities with public exploits extending the “Copy Fail” attack class. High severity, affecting Linux kernel subsystems. Patches pending but public exploit code is circulating; prioritize kernel updates once available.
- CVE-2026-46300 “Fragnesia”: Linux Kernel Privilege Escalation (Tenable) Latest Linux kernel LPE with public PoC targeting XFRM ESP-in-TCP subsystem, distinct from Dirty Frag. Confirmed working on Ubuntu; no active exploitation reported. Patch released May 13; existing Dirty Frag mitigations partially effective.
🕵️ THREAT RESEARCH & DEEP DIVES
- Mini Shai-Hulud: Self-Propagating Supply Chain Worm Compromising npm & PyPI (Tenable) TeamPCP group compromised 170+ npm and PyPI packages, bypassing SLSA Build Level 3 provenance attestations—a first demonstrating process integrity control failures. Targets include OpenAI and Mistral AI developer/cloud credentials. Any system installing affected packages should be treated as fully compromised.
- Verizon DBIR 2026: Vulnerability Exploitation Surges as Leading Initial Access Vector (Tenable) Exploit-driven breaches now account for 31% of incidents, outpacing phishing and credential theft. Median patch times increased by 11 days year-over-year amid AI-accelerated discovery and exploitation. Emphasizes urgent need for continuous attack surface management and automated remediation.
📋 VENDOR BULLETINS & LAW ENFORCEMENT
- Microsoft May 2026 Patch Tuesday: 118 CVEs, No Zero-Days Exploited in the Wild (Tenable) Includes 16 critical and 102 important fixes across Azure, .NET, M365, and Edge Copilot Chat components. Notably, no zero-days exploited in the wild for the first time since June 2024. Organizations should prioritize patching critical Azure and cloud agent components.
- Oracle April 2026 CPU: 241 CVEs Fixed, 34 Critical (Tenable) Second quarterly CPU of 2026 delivers 481 patches across 28 product families. Oracle Communications leads with 139 patches. Critical fixes require immediate attention, especially in telecom and cloud infrastructure environments.