SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation

2026-07-02T07:24:10Z22e2e5e2bfbd8a98690e6fd2be52206527eae9de9310123e8d0e902bf31075b9
AI-securityAdobeArgo CDCISA-KEVCitrixCursorKemp LoadMasterLangflowSharePointSimpleHelpactive-exploitationbotnetmalwarephishingransomwareremote-code-executionsupply-chainvulnerability

What happened

A batch of high-impact security stories: CISA added a SharePoint deserialization RCE (CVE-2026-45659, CVSS 8.8) to its KEV list citing active exploitation. Multiple critical and actively exploited flaws were reported across products — SimpleHelp (CVE-2026-48558, CVSS 10.0) used to deliver TaskWeaver/Djinn, Progress Kemp LoadMaster (CVE-2026-8037, CVSS 9.6) under attack, and Langflow RCE (CVE-2026-33017, CVSS 9.3) leveraged to deploy a Monero miner. Adobe released patches for several CVSS 10.0 bugs in ColdFusion and Campaign Classic. New and emerging threats include an unpatched Argo CD repo‑se

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
22e2e5e2bfbd8a98690e6fd2be52206527eae9de9310123e8d0e902bf31075b9
Enrichment time
2026-07-02T07:24:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.