U.S. CISA adds Daemon Tools, TanStack, and Nx Console flaws to its Known Exploited Vulnerabilities catalog
2026-05-28T14:51:47Z•450ea9668c6cf79db735f005b39144310b2508310042421d2e78ae9166021de4
CISACVE-2026-45659CVE-2026-48172CVE-2026-8398ConnectWiseDaemon ToolsGlasswormIran MOISKnown Exploited VulnerabilitiesLiteSpeedMicrosoft SharePointbotnet takedowncPanelcloud misconfigurationdata exposureexposed databasesexposed passportsransomwareremote code executionstate-sponsored
What happened
SecurityAffairs roundup: U.S. CISA added multiple flaws to its Known Exploited Vulnerabilities (KEV) list including CVE-2026-8398 (Daemon Tools/TanStack/Nx Console), CVE-2026-48172 (LiteSpeed cPanel plugin, CVSS 10.0) and Microsoft SharePoint RCE CVE-2026-45659 (CVSS 8.8). Major data-exposure stories include a third‑party UK visa site leaking ~100,000 passports and selfies, and a report finding 19.6 billion files exposed in misconfigured cloud buckets. Other notable items: a coordinated takedown of the Glassworm botnet (supply‑chain infection via poisoned developer tools), forensic links tying
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 450ea9668c6cf79db735f005b39144310b2508310042421d2e78ae9166021de4
- Enrichment time
- 2026-05-28T14:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.