Skip to main content

// WEEKLY_RECAP

Week 20, 2026

May 11, 2026 – May 17, 2026

Severity mix (143 articles)

  • CRITICAL 14
  • HIGH 71
  • MEDIUM 23
  • LOW 1
  • INFO 34

Top stories

  1. CRITICAL

    NGINX CVE-2026-42945: Heap Buffer Overflow Exploited — Patch Now

    May 17, 2026

  2. CRITICAL

    Funnel Builder Plugin Exploited for WooCommerce Checkout Skimming

    May 16, 2026

  3. CRITICAL

    CVE-2026-42897: Microsoft Exchange XSS Under Active Exploitation

    May 15, 2026

  4. CRITICAL

    Funnel Builder WordPress Plugin Exploited for Credit Card Skimming

    May 15, 2026

  5. CRITICAL

    CVE-2026-42897: Microsoft Exchange Server Zero-Day Exploited in Wild

    May 15, 2026

  6. CRITICAL

    CVE-2024-49040: Microsoft Exchange Server Spoofing Vulnerability

    May 15, 2026

  7. CRITICAL

    Cisco SD-WAN RCE via CVE-2026-20182 — Mitigation Guide

    May 15, 2026

  8. CRITICAL

    Cisco Catalyst SD-WAN Authentication Bypass: CVE-2026-20182 Exploit

    May 15, 2026

  9. CRITICAL

    CVE-2026-42897: How Attackers Exploit Microsoft Exchange Server

    May 15, 2026

  10. CRITICAL

    CVE-2024-7109: Burst Statistics WordPress Plugin Auth Bypass Exploited

    May 15, 2026

+ 133 more in the archive.

CVEs tracked this week (33)

Get this in your inbox weekly — subscribe to the newsletter.