CISA Adds Four Critical Exploited Vulnerabilities to Catalog
CISA adds four critical vulnerabilities affecting Apple macOS, Microsoft SharePoint, VMware vCenter, and Microsoft IKE to its exploited vulnerabilities catalog due to active, in-the-wild exploitation.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four critical vulnerabilities affecting Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE to its catalog of Known Exploited Vulnerabilities. This inclusion comes after confirmation that these flaws are being actively exploited in the wild.
Among the vulnerabilities cataloged are CVE-2026-65400, an authentication bypass in Apple macOS Screen Sharing, and CVE-2026-55040, a weakness in Microsoft SharePoint’s authentication. CISA urges immediate patching for these and other listed vulnerabilities, as federal civilian executive branch agencies are required to address them by August 21, 2026, under specific guidelines as reported by SecurityWeek.
The catalog also includes CVE-2026-59310, a path traversal vulnerability in VMware vCenter, and CVE-2026-33824, a double-free vulnerability in Microsoft IKE. The latter has a CVSS score of 9.8, indicating a critical severity, as does the VMware vCenter flaw according to The Hacker News.
Exploitation details reveal that the macOS flaw has been abused to distribute a Monero cryptocurrency miner. The Microsoft SharePoint vulnerability saw exploitation after a proof-of-concept was released. In a more sophisticated attack, the VMware vCenter flaw was reportedly leveraged by a suspected China-nexus Advanced Persistent Threat (APT) group to deploy a backdoor and Babuk-derived ransomware, impacting 361 unique victim IP addresses across 47 countries as detailed by The Hacker News.
CISA’s directive emphasizes the urgency of securing systems against these actively exploited threats. The inclusion in the Known Exploited Vulnerabilities catalog signifies that CISA has credible, often public, information about active exploitation. Organizations are strongly encouraged to prioritize the mitigation of these vulnerabilities to prevent potential compromise as noted by SecurityWeek.
The Common Vulnerabilities and Exposures (CVE) system provides a standardized naming convention for publicly known information security vulnerabilities. Each vulnerability is assigned a unique CVE identifier, facilitating easier communication and sharing of threat intelligence across different security tools and organizations learn more.
The vulnerabilities, with their respective CVSS scores, are CVE-2026-33824 (Microsoft IKE, CVSS 9.8), CVE-2026-55040 (SharePoint, CVSS 9.1), CVE-2026-59310 (VMware vCenter, CVSS 9.8), and CVE-2026-65400 (macOS, CVSS 7.5) as detailed by SecurityWeek.
This action by CISA underscores the continuous need for vigilance and prompt patching in maintaining robust cybersecurity defenses against evolving threats targeting widely used software and operating systems.