U.S. CISA adds Daemon Tools, TanStack, and Nx Console flaws to its Known Exploited Vulnerabilities catalog

2026-05-28T14:51:47Z450ea9668c6cf79db735f005b39144310b2508310042421d2e78ae9166021de4
CISACVE-2026-45659CVE-2026-48172CVE-2026-8398ConnectWiseDaemon ToolsGlasswormIran MOISKnown Exploited VulnerabilitiesLiteSpeedMicrosoft SharePointbotnet takedowncPanelcloud misconfigurationdata exposureexposed databasesexposed passportsransomwareremote code executionstate-sponsored

What happened

SecurityAffairs roundup: U.S. CISA added multiple flaws to its Known Exploited Vulnerabilities (KEV) list including CVE-2026-8398 (Daemon Tools/TanStack/Nx Console), CVE-2026-48172 (LiteSpeed cPanel plugin, CVSS 10.0) and Microsoft SharePoint RCE CVE-2026-45659 (CVSS 8.8). Major data-exposure stories include a third‑party UK visa site leaking ~100,000 passports and selfies, and a report finding 19.6 billion files exposed in misconfigured cloud buckets. Other notable items: a coordinated takedown of the Glassworm botnet (supply‑chain infection via poisoned developer tools), forensic links tying

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
450ea9668c6cf79db735f005b39144310b2508310042421d2e78ae9166021de4
Enrichment time
2026-05-28T14:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.