Patch Now: SharePoint Server Is Exploited, Federal Deadline July 4
CVE-2026-45659 is an actively exploited deserialization flaw in Microsoft SharePoint Server. CISA added it to KEV on July 1 with a federal deadline of July 4, 2026.
Category
9 posts tagged Zero-day.
CVE-2026-45659 is an actively exploited deserialization flaw in Microsoft SharePoint Server. CISA added it to KEV on July 1 with a federal deadline of July 4, 2026.
CVE-2026-48558, a CVSS 10 authentication bypass in SimpleHelp, is actively exploited and added to CISA KEV with a July 2 federal patch deadline.
CVE-2026-20230 is a server-side request forgery flaw in Cisco Unified CM and Unified CM SME added to CISA KEV on June 25. Federal deadline is June 28.
Ubiquiti UniFi OS and Lantronix EDS5000 reached CISA KEV on June 23 with unauthenticated root flaws, and Copy Fail (CVE-2026-31431) now hits B&R OT gear. Patch fast.
CISA added Splunk Enterprise CVE-2026-20253 to KEV on June 18, 2026. Unauthenticated file write via PostgreSQL sidecar, federal due date June 21. Who is affected and what to do.
CVE-2026-48907 in Joomla Content Editor lets unauthenticated attackers upload PHP webshells. CISA added it to KEV on June 16; patch to JCE 2.9.99.6 now.
Attackers are exploiting Cisco Catalyst SD-WAN Manager (CVE-2026-20262) and the LiteSpeed cPanel plugin (CVE-2026-54420), both added to CISA KEV on June 15, 2026. Patch now.
Oracle PeopleSoft PeopleTools CVE-2026-35273: active exploitation, known ransomware use, unauthenticated takeover, CVSS 9.8, on CISA KEV. Who is affected and what to do.
CISA added Ivanti Sentry CVE-2026-10520 to KEV on June 11, 2026. Unauthenticated root RCE, CVSS 10.0, federal due date June 14. Here is who is affected and what to do.
Ce site est aussi disponible en français.