SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation
2026-07-02T07:24:10Z•22e2e5e2bfbd8a98690e6fd2be52206527eae9de9310123e8d0e902bf31075b9
AI-securityAdobeArgo CDCISA-KEVCitrixCursorKemp LoadMasterLangflowSharePointSimpleHelpactive-exploitationbotnetmalwarephishingransomwareremote-code-executionsupply-chainvulnerability
What happened
A batch of high-impact security stories: CISA added a SharePoint deserialization RCE (CVE-2026-45659, CVSS 8.8) to its KEV list citing active exploitation. Multiple critical and actively exploited flaws were reported across products — SimpleHelp (CVE-2026-48558, CVSS 10.0) used to deliver TaskWeaver/Djinn, Progress Kemp LoadMaster (CVE-2026-8037, CVSS 9.6) under attack, and Langflow RCE (CVE-2026-33017, CVSS 9.3) leveraged to deploy a Monero miner. Adobe released patches for several CVSS 10.0 bugs in ColdFusion and Campaign Classic. New and emerging threats include an unpatched Argo CD repo‑se
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 22e2e5e2bfbd8a98690e6fd2be52206527eae9de9310123e8d0e902bf31075b9
- Enrichment time
- 2026-07-02T07:24:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.