In partnership with

PatchDay Alert: 2026-05-18
|
|
DAILY BRIEF · MAY 18, 2026
|
|
Nothing's burning, but don't sleep on this batch. PostgreSQL, NGINX, and the Linux kernel SMB server (ksmbd) all have CVSS 8.1+ bugs out today, none exploited in the wild yet. If you run any of those three, carve out time to patch before someone writes a proof of concept.
|
| |
SECURE BOOT CERTIFICATE DEADLINE
37 days until Microsoft Secure Boot certificates begin expiring (June 24, 2026).
How to remediate →
|
|
|
TOP THREAT TODAY
|
|
When you run `apm install`, the tool follows symlinks placed under `.apm/prompts/` or `.apm/agents/` and copies whatever those links point to into your project tree. An attacker who can commit a crafted symlink to a shared repo could exfiltrate sensitive host files (think SSH keys, cloud credentials, `/etc/shadow`) into the project directory where they become readable or even committed back upstream. Exploitation requires a developer to clone a malicious repo and run `apm install`, so there is a user interaction step.
Who's affected: Developers and CI/CD pipelines using Microsoft APM (installed via pip)
| |
Patch this week.
Upgrade the `apm` pip package to the patched version, and audit any existing `.apm/prompts/` and `.apm/agents/` directories for unexpected symlinks.
|
NVD
Ref 1
Ref 2
|
|
|
CVE-2026-6637
CVSS 8.8
EPSS 0.04%
|
HIGH
|
The `refint` (referential integrity) module in PostgreSQL has a stack buffer overflow and a SQL injection path. An authenticated database user who can define or trigger referential integrity constraints could exploit this to execute arbitrary SQL or potentially crash the server. CVSS 8.8 reflects the high impact, but exploitation does require an authenticated session.
Affects: Anyone running PostgreSQL 16.12 on Azure Linux 3.0, or any PostgreSQL deployment using the refint contrib module
| |
Patch within 24 hours.
Update the `postgresql` package to the patched version on Azure Linux 3.0 using `tdnf update postgresql` and restart the service.
|
NVD
MSRC
Ref 1
|
|
CVE-2026-42945
CVSS 8.1
EPSS 0.15%
|
HIGH
|
A vulnerability in NGINX's `ngx_http_rewrite_module` could let an attacker manipulate rewrite rules to bypass access controls or cause unexpected behavior. Details are sparse, but the CVSS 8.1 score and the fact that the rewrite module is enabled by default in virtually every NGINX deployment make this one worth prioritizing. Exploitation is likely network-based with no authentication required.
Affects: Anyone running NGINX 1.28.3 on Azure Linux 3.0, or any NGINX deployment using the rewrite module (which is almost all of them)
| |
Patch within 24 hours.
Update NGINX to the patched version on Azure Linux 3.0 via `tdnf update nginx`, then reload the service with `nginx -s reload`.
|
NVD
MSRC
Ref 1
|
|
CVE-2026-31717
CVSS 8.8
EPSS 0.04%
|
HIGH
|
The in-kernel SMB server (ksmbd) fails to validate the owner of a durable file handle when a client reconnects. An attacker on the network could hijack another user's open file handle after a reconnect, potentially reading or modifying files they shouldn't have access to. CVSS 8.8 and no authentication is required beyond network access to the SMB share.
Affects: Anyone running ksmbd (the in-kernel SMB server) on Azure Linux 3.0 with kernel 6.6.137.x through 6.6.139.x, or any Linux system using ksmbd with durable handles enabled
| |
Patch within 24 hours.
Update the kernel package on Azure Linux 3.0 to the patched version via `tdnf update kernel` and reboot. If you can't reboot immediately, consider disabling ksmbd or switching to Samba as a temporary workaround.
|
NVD
MSRC
|
|
CVE-2026-42009
CVSS 7.5
|
HIGH
|
A bug in GnuTLS's DTLS packet reordering logic means that packets with duplicate sequence numbers cause unstable sorting or undefined behavior. A remote attacker can send crafted DTLS packets to crash the service, causing a denial of service. No authentication or user interaction is needed. This only affects applications using DTLS (UDP-based TLS), not standard TLS over TCP.
Affects: Anyone running applications that use GnuTLS for DTLS connections (VPN gateways, VoIP servers, IoT services using DTLS)
| |
Patch this week.
Update the gnutls package to the latest patched version through your distribution's package manager.
|
NVD
Ref 1
Ref 2
|
|
Community Signal Check
|
NGINX CVE-2026-42945 heap buffer overflow exploited in the wild with automated scanning
CVE-2026-42945 is already in today's digest, and now VulnCheck confirms attackers are exploiting it in the wild. Unauthenticated heap buffer overflow in ngx_http_rewrite_module (CVSS 9.2) lets attackers crash NGINX workers or get RCE when ASLR is off. Attackers are using AI-powered scanning tools to find vulnerable instances and drop PHP web shells, so patch NGINX to 1.30.1+ now.
The Hacker News
•
active_exploitation
|
|
Exchange Server CVE-2026-42897 XSS zero-day exploited, no patch yet
Attackers are exploiting CVE-2026-42897 in Exchange Server to run arbitrary JavaScript inside Outlook Web Access sessions. Microsoft confirmed active exploitation but hasn't shipped a patch yet, only temporary mitigations. If you run on-prem Exchange (Subscription Edition, 2016, or 2019), apply the mitigations today and watch for the out-of-band fix.
Security Affairs
•
active_exploitation
|
|
Linux Dirty Frag privilege escalation chain (CVE-2026-43284 + CVE-2026-43500) exploited in the wild
Microsoft Defender caught in-the-wild exploitation of the Dirty Frag chain on May 11. Attackers combined CVE-2026-43284 and CVE-2026-43500 to get root on Linux boxes, then tampered with GLPI LDAP auth files and grabbed PHP session data. If you run Linux hosts with xfrm or RxRPC in your kernel config, prioritize patching and audit for unexpected changes to LDAP configs.
Microsoft Security Blog
•
active_exploitation
|
|
KB5089549 fails at 35% reboot with 0x800f0922 on low EFI partition space
The May 2026 Windows 11 cumulative update (KB5089549) blows up at the reboot phase if your EFI System Partition has 10 MB or less free. You'll see error 0x800f0922 and the install rolls back at about 35%. Microsoft is pushing a Known Issue Rollback fix that auto-propagates to unmanaged devices. If you manage your fleet through Group Policy, you'll need to pull the KIR policy manually.
Microsoft Learn
•
broken_patch
|
|
|
That's your patch day digest.
|
|
patchdayalert.com
|
|
Master Claude AI (Free Guide)
The professionals pulling ahead aren't working more. They're using Claude.
Configure Claude to be the perfect assistant
Master AI-powered content creation
Transform complex data into actionable strategies
Harness Claude’s full potential