Microsoft Exchange Server zero-day exploited via crafted email
… CVE-2026-42897 arrived just two days after May's Patch Tuesday, which patched 120 vulnerabilities but disclosed no zero-days in its release notes. …
… CVE-2026-42897 arrived just two days after May's Patch Tuesday, which patched 120 vulnerabilities but disclosed no zero-days in its release notes. …
… Notebookcheck covered Google's confirmation of the first known zero-day exploit developed by AI, used in a planned mass exploitation campaign targeting a 2FA bypass in a widely used web administration tool Source s Microsoft Defense at Speed Help Net Security The Hacker News ⟨ Previous article Ear … …
… Security fixes and what is new The release preview builds integrate fixes for two zero-day vulnerabilities from the May 2026 Patch Tuesday: CVE-2026-1127, a kernel elevation of privilege flaw, and CVE-2026-1139, a remote code execution vulnerability in the Windows graphics component. …
… The security side of May's update arrives at a critical moment. Today, May 12, is the CISA deadline for federal agencies to apply the fix for CVE-2026-32202 , the Windows Shell zero-day that Notebookcheck covered last month and that was confirmed as actively exploited. …
… This restores backup functionality but removes the April 2026 security patches, including the fix for the actively exploited CVE-2026-32202 Windows Shell zero-day that Notebookcheck covered last week. …