Security Roundup: Exchange Zero-Day, GitHub Breach, Cisco SD-WAN, Defender Zero-Days — Week of May 21, 2026

Weekly briefing: Microsoft Exchange OWA zero-day XSS, TeamPCP GitHub breach (3.8K repos), Cisco SD-WAN UAT-8616, and Defender zero-days.

Security Roundup: Exchange Zero-Day, GitHub Breach, Cisco SD-WAN, Defender Zero-Days — Week of May 21, 2026

A busy week: an unpatched Microsoft Exchange zero-day being actively exploited with no remediation date in sight, confirmation of GitHub’s largest internal breach in years via a poisoned VS Code extension, a CVSS 10.0 Cisco SD-WAN authentication bypass tied to a nation-state actor, and two Microsoft Defender zero-days added to CISA’s KEV with a June 3 federal deadline.


Microsoft Exchange OWA XSS Zero-Day — CVE-2026-42897 (CVSS 8.1, No Patch)

CVE-2026-42897 is a stored XSS vulnerability in Exchange Server’s Outlook Web Access. An attacker sends a specially crafted email; when the recipient opens it in OWA, arbitrary JavaScript executes in their authenticated browser session — enabling session token theft, silent inbox rule creation, and mailbox impersonation. Microsoft confirmed active exploitation on May 14 but has not provided a remediation timeline. Exchange Online is not affected.

Affected: Exchange Server 2016, 2019, and Subscription Edition (all update levels) with OWA enabled.
CVSS: 8.1 (no auth required from attacker, user interaction required).
Status: No permanent patch. Temporary mitigations published May 14 — apply immediately.

What to do

Apply Microsoft’s interim mitigation from the Exchange Team Blog. Audit inbox forwarding rules with Get-InboxRule across all mailboxes. Restrict OWA to trusted IPs if internet-facing. Monitor IIS logs for anomalous OWA API calls following email open events.

→ Deep Dive: CVE-2026-42897 — Exchange OWA Zero-Day Technical Breakdown


GitHub Internal Breach: 3,800 Repos Stolen via Poisoned VS Code Extension

GitHub confirmed on May 20 that TeamPCP exfiltrated approximately 3,800 internal repositories by exploiting a GitHub employee who installed a backdoored version of the Nx Console VS Code extension. The malicious extension was live on the VS Code Marketplace for just 18 minutes on May 18, during which it stole developer credentials including GitHub tokens, AWS IAM keys, and 1Password vault contents. Stolen repos include GitHub Actions configs, Copilot internal tooling, CodeQL security rules, Dependabot, and Codespaces implementation code. TeamPCP is the same group behind last week’s Mini Shai-Hulud supply chain worm (CVE-2026-45321, CVSS 9.6).

What to do

Developers who had Nx Console installed should rotate all GitHub tokens, AWS keys, and vault credentials immediately. Audit installed VS Code extensions. Enforce extension allowlisting in developer environments.

→ Deep Dive: GitHub Breach — TeamPCP Attack Chain and Full Impact Analysis


Cisco SD-WAN Auth Bypass — CVE-2026-20182 (CVSS 10.0, CISA KEV)

CVE-2026-20182 is a critical unauthenticated authentication bypass in Cisco Catalyst SD-WAN Controller and Manager, exploitable via UDP port 12346. The bug lives in the vdaemon DTLS service: when a connecting peer claims to be a vHub device, certificate verification is skipped but authentication is still granted. CISA added it to KEV on May 14. Cisco Talos attributes active exploitation to UAT-8616, with post-exploitation including SSH key persistence and NETCONF fabric manipulation.

What to do

Upgrade to SD-WAN Controller/Manager 20.12.4 immediately. Restrict UDP/12346 to trusted sources. Audit /home/vmanage-admin/.ssh/authorized_keys for unauthorized entries. Review NETCONF configuration history against a baseline.

→ Deep Dive: CVE-2026-20182 — Cisco SD-WAN Auth Bypass Technical Analysis


Microsoft Defender Zero-Days — CVE-2026-41091 & CVE-2026-45498 (CISA KEV, June 3 Deadline)

CISA added two actively exploited Microsoft Defender vulnerabilities to KEV on May 20 with a federal remediation deadline of June 3, 2026.

CVE-2026-41091 (CVSS 7.8): Local privilege escalation to SYSTEM via symlink following in the Microsoft Malware Protection Engine. A low-privilege user triggers SYSTEM-level file operations by crafting a symbolic link MMPE follows without adequate path validation.
CVE-2026-45498 (CVSS 6.5): Denial of service that crashes the Defender engine — particularly dangerous when chained to first blind Defender, then execute otherwise-detected payloads.

Both are fixed in MMPE version 1.1.26040.8, auto-distributed via Windows Update. The May 20 KEV batch also included four ancient Windows/browser CVEs (2008–2010) still being actively exploited — including MS08-067 (CVE-2008-4250, the Conficker vulnerability).

What to do

Run Get-MpComputerStatus | Select AMEngineVersion and confirm version ≥ 1.1.26040.8 on all endpoints. Force Update-MpSignature where auto-update is deferred. Hunt for Defender service crashes and symlink abuse via Windows Event ID 4663.

→ Deep Dive: CVE-2026-41091 & CVE-2026-45498 — Microsoft Defender Zero-Days


Deep Dives

Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther