Jump to the main content block

【Vulnerability Alert】CISA Added 2 Known Exploited Vulnerabilities to the KEV Catalog (2026/05/11-2026/05/17)

publish date : 2026-05-22 update date : 2026-05-22

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026051910053939 Publication Time 2026-05-19 10:21:39
Incident Type ANA-Vulnerability Alert Discovery Time 2026-05-19 10:21:39
Impact Level Low  
[Subject]
【Vulnerability Alert】CISA Added 2 Known Exploited Vulnerabilities to the KEV Catalog (2026/05/11-2026/05/17)
[Content]

Forwarded from TWCERTCC Information Security Alert TWCERTCC-200-202605-00000012

【CVE-2026-20182】Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability (CVSS v3.1: 10.0)
【Whether exploited by ransomware: Unknown】Cisco Catalyst SD-WAN Controller & Manager has an authentication bypass vulnerability. An unauthenticated remote attacker may exploit this vulnerability to bypass authentication and obtain administrator privileges on the affected system.

【CVE-2026-42897】Microsoft Exchange Server Cross-Site Scripting Vulnerability (CVSS v3.1: 8.1)
【Whether exploited by ransomware: Unknown】Microsoft Exchange Server has a cross-site scripting vulnerability when Outlook Web Access generates webpages. Under specific interaction conditions, an attacker may execute arbitrary JavaScript code in the browser environment.

Information sharing level: WHITE (the intelligence content is information that can be publicly disclosed)

[Affected Platform]

【CVE-2026-20182】Please refer to the affected versions listed by the official source: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW

【CVE-2026-42897】Please refer to the affected versions listed by the official source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42897

[Recommended Actions]

【CVE-2026-20182】The official source has released a fix update for the vulnerability. Please update to the relevant version: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW

【CVE-2026-42897】The official source has released a fix update for the vulnerability. Please update to the relevant version: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42897

[Reference]

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center
Click Num: