High severity7.1NVD Advisory· Published May 12, 2026· Updated May 13, 2026
CVE-2026-45430
CVE-2026-45430
Description
The Salesforce module before 1.x-1.0.1 for Backdrop CMS does not properly use a random state parameter to protect the authorization flow against CSRF attacks.
Affected products
1- Range: <1.0.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
37- The Boring Stuff is Dangerous NowDark Reading · May 18, 2026
- [Guest Diary] New Malware Libraries means New Signatures, (Fri, May 15th)SANS Internet Storm Center · May 15, 2026
- Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student dataThe Register Security · May 14, 2026
- Congress Puts Heat on Instructure After Canvas OutageDark Reading · May 14, 2026
- HYCU aiR detects insider risk and AI activity from backupsHelp Net Security · May 14, 2026
- Instructure reaches 'agreement' with ShinyHunters to stop data leakBleepingComputer · May 12, 2026
- 1 in 8 employees have sold company logins or know someone who hasMalwarebytes Labs · May 12, 2026
- Double Canvas breach acknowledged as ShinyHunters sets new pay-or-leak deadlineThe Register Security · May 11, 2026
- Zara data breach exposed personal information of 197,000 peopleBleepingComputer · May 8, 2026
- Canvas Breach Disrupts Schools & Colleges NationwideKrebs on Security · May 8, 2026
- Canvas login portals hacked in mass ShinyHunters extortion campaignBleepingComputer · May 7, 2026
- The Browser Is Breaking Your DLP: How Data Slips Past Modern ControlsBleepingComputer · May 7, 2026
- ThreatsDay Bulletin: Edge Plaintext Passwords, ICS 0-Days, Patch-or-Die Alerts and 25+ New StoriesThe Hacker News · May 7, 2026
- From Stuxnet to ChatGPT: 20 News Events That Shaped CyberDark Reading · May 6, 2026
- UiPath adds agentic AI capabilities to Automation Suite for government agenciesHelp Net Security · May 6, 2026
- Real estate giant confirms vishing incident as ShinyHunters and Qilin both come knockingThe Register Security · May 5, 2026
- Real estate giant confirms vishing incident as ShinyHunters and Qilin both come knockingThe Register Security · May 5, 2026
- Vimeo data breach exposes personal information of 119,000 peopleBleepingComputer · May 5, 2026
- The Back Door Attackers Know About — and Most Security Teams Still Haven’t ClosedThe Hacker News · May 5, 2026
- One in four MCP servers opens AI agent security to code execution riskHelp Net Security · May 5, 2026
- Cybersecurity M&A Roundup: 33 Deals Announced in April 2026SecurityWeek · May 4, 2026
- DigiCert Revokes Certificates After Support Portal HackSecurityWeek · May 4, 2026
- Edtech Firm Instructure Discloses Data Breach Amid Hacker Leak ThreatsSecurityWeek · May 4, 2026
- Your work apps are quietly handing 19 data points to someoneHelp Net Security · May 4, 2026
- Instructure confirms data breach, ShinyHunters claims attackBleepingComputer · May 3, 2026
- Edu tech firm Instructure discloses cyber incident, probes impactBleepingComputer · May 1, 2026
- In Other News: Scattered Spider Hacker Arrested, SOC Effectiveness Metrics, NSA Tool VulnerabilitySecurityWeek · May 1, 2026
- Cybercrime Groups Using Vishing and SSO Abuse in Rapid SaaS Extortion AttacksThe Hacker News · May 1, 2026
- Have I Been Pwned claims Pitney Bowes hit by 8.2M email address leakThe Register Security · Apr 28, 2026
- Have I Been Pwned claims Pitney Bowes hit by 8.2M email address leakThe Register Security · Apr 28, 2026
- Burglar alarm biz burgled: ADT confirms cyber intrusion after ShinyHunters extortion attemptThe Register Security · Apr 27, 2026
- BlackFile Group Targets Retail and Hospitality with Vishing AttacksInfosecurity Magazine · Apr 27, 2026
- AI Phishing Is No. 1 With a Bullet for CyberattackersDark Reading · Apr 24, 2026
- 20th April – Threat Intelligence ReportCheck Point Research · Apr 20, 2026
- European Commission Confirms Cloud Data BreachInfosecurity Magazine · Mar 30, 2026
- ShinyHunters Targets Hundreds of Websites in New Salesforce CampaignInfosecurity Magazine · Mar 10, 2026
- Risky Business #826 -- A week of AI mishaps and skulduggeryRisky Business · Feb 25, 2026