Carnival Data Breach Exposes Personal Data of Nearly 6 Million Customers

2026-05-29T02:51:44Z8eb419d6e82ce0164de313f6c6fdd956285057365d80f83962ba0e4f68bbc5c8
CISA-KEVCVEactive-exploitationbotnet-takedowncloud-misconfigurationcode-signingcredential-exposuredata-breachdigital-crimes-unitinformation-stealerrcestate-linked-attackvulnerability

What happened

Collection of May 28, 2026 security incidents: Carnival disclosed a data breach affecting ~5.99M customers via social-engineered employee account access; a critical FortiClient EMS RCE (CVE-2026-35616, CVSS 9.1) is being actively exploited to deploy information-stealing malware; CISA added multiple flaws to its KEV list including LiteSpeed cPanel Plugin (CVE-2026-48172, CVSS 10.0) and Windows Shell/other entries (e.g., CVE-2026-8398); a third‑party UK visa site exposed ~100k passports on a public AWS server; researchers found 19.6 billion files exposed in misconfigured cloud buckets; Microsoft

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
8eb419d6e82ce0164de313f6c6fdd956285057365d80f83962ba0e4f68bbc5c8
Enrichment time
2026-05-29T02:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Carnival Data Breach Exposes Personal Data of Nearly 6 Million Customers · Baitaphish