View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

SharePoint RCE added to CISA KEV after active exploitation

🚨 ACTIVE EXPLOITS & INCIDENTS

  • SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation — The U.S. CISA has added CVE-2026-45659 (CVSS 8.8) to its Known Exploited Vulnerabilities catalog following confirmed active exploitation. The flaw allows remote code execution via deserialization of untrusted data in Microsoft SharePoint Server, requiring urgent patching to prevent compromise.
  • FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations — The FortiBleed vulnerability campaign is tied directly to ransomware groups INC and Lynx, with stolen FortiGate credentials used for follow-on intrusions and ransomware deployment. Operators were observed negotiating ransom payments, confirming this as a critical vector for ongoing ransomware attacks.
  • Alleged Scattered Spider Hacker Extradited to the United States — A dual US-Estonian citizen suspected of involvement with the Scattered Spider hacking collective has been extradited to the U.S. to face charges. This may impact ongoing investigations into high-profile ransomware and intrusion campaigns linked to the group.

🔓 VULNERABILITIES & CVEs

🕵️ THREAT RESEARCH & DEEP DIVES

📋 VENDOR BULLETINS & ADVISORIES

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check