PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-45321 @tanstack CVE debrief

A critical-severity vulnerability in TanStack has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog with confirmed known ransomware campaign use. The vulnerability is currently unspecified in publicly available details. CISA has established a remediation due date of June 10, 2026. Organizations should prioritize mitigation efforts in accordance with vendor guidance and applicable Binding Operational Directive 22-01 requirements for cloud services.

Vendor
@tanstack
Product
arktype-adapter
CVSS
CRITICAL 9.6
CISA KEV
Listed
Original CVE published
2026-05-27
Original CVE updated
2026-05-27
Advisory published
2026-05-27
Advisory updated
2026-05-27

Who should care

Organizations using TanStack libraries or frameworks in production environments, particularly those subject to CISA BOD 22-01 compliance requirements or operating in sectors targeted by ransomware campaigns.

Technical summary

CVE-2026-45321 represents an unspecified critical vulnerability in TanStack products. CISA has confirmed known ransomware campaign use and assigned a remediation due date of June 10, 2026. The vulnerability carries a CVSS score of 9.6. Specific technical details regarding the vulnerability class, affected versions, and attack vectors are not available in the disclosed sources. Organizations using TanStack components should consult vendor security advisories for definitive patching guidance.

Defensive priority

CRITICAL

Recommended defensive actions

  • Apply vendor-provided mitigations as soon as possible, per CISA KEV required action guidance
  • Follow applicable Binding Operational Directive 22-01 guidance for cloud services where TanStack components are deployed
  • Discontinue use of affected TanStack products if vendor mitigations are unavailable
  • Monitor TanStack security advisories for specific patch availability and version guidance
  • Review environments for TanStack component usage to determine exposure scope

Evidence notes

CISA KEV entry confirms active exploitation with known ransomware campaign use. CVSS 9.6 CRITICAL severity. Specific vulnerability type and affected component versions are not detailed in available sources.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-45321 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-45321

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-45321 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45321

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.