The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four critical security vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, warning that the flaws are being actively exploited in the wild.
The vulnerabilities affect products from Apple, Microsoft, and Broadcom VMware. Although security updates have been released by the respective vendors, organizations are urged to apply the available patches immediately to reduce the risk of compromise.
Four Critical Vulnerabilities Added to CISA’s KEV Catalog
The newly listed vulnerabilities are:
- CVE-2026-65400 (CVSS 9.8): An improper authentication vulnerability in Apple macOS that could allow a network-based attacker to authenticate to Screen Sharing without valid credentials.
- CVE-2026-55040 (CVSS 9.1): A weak authentication vulnerability in Microsoft SharePoint that could enable an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-59310 (CVSS 9.8): A path traversal vulnerability in Broadcom VMware vCenter that could allow an attacker with network access to execute arbitrary code.
- CVE-2026-33824 (CVSS 9.8): A double-free vulnerability in Microsoft Internet Key Exchange (IKE) Service Extensions that could allow an unauthorized attacker to execute code remotely over a network.
CISA’s decision to add the flaws to its KEV catalog highlights the urgency of addressing them, as vulnerabilities in the catalog are known to have been exploited by threat actors.
Apple macOS Vulnerability Exploited to Deploy Cryptominer
The Apple macOS vulnerability, CVE-2026-65400, has reportedly been exploited to deliver a Monero cryptocurrency miner to compromised systems.
The flaw allows attackers on the network to bypass authentication protections for Screen Sharing, potentially providing unauthorized access to vulnerable macOS systems.
Organizations using affected macOS versions should prioritize vendor-provided security updates and review systems for signs of unauthorized access or cryptocurrency-mining activity.
Microsoft SharePoint Flaw Exploited After PoC Release
The Microsoft SharePoint vulnerability, CVE-2026-55040, has also come under active exploitation.
According to public reports, unknown threat actors began exploiting the vulnerability after proof-of-concept (PoC) code became publicly available. The flaw could allow attackers to bypass an authentication-related security mechanism over a network.
Because SharePoint servers are frequently exposed to internal and external networks, unpatched systems could present an attractive target for attackers seeking initial access to enterprise environments.
VMware vCenter Flaw Linked to China-Nexus Activity
The VMware vCenter vulnerability, CVE-2026-59310, has been linked to activity attributed to a suspected China-nexus advanced persistent threat (APT) actor.
Threat actors reportedly exploited the path traversal flaw to deploy a backdoor and reverse_ssh binaries, enabling persistent access to compromised vCenter instances.
In at least one incident, the activity reportedly resulted in the deployment of a Babuk-derived ransomware strain.
Researchers have identified 361 unique victim IP addresses across 47 countries associated with the activity. Germany recorded the highest number of affected IP addresses with 55, followed by the United States with 41, Turkey with 38, Iran with 26, and France with 25.
Microsoft IKE Vulnerability Used in AI-Assisted Campaign
The fourth vulnerability, CVE-2026-33824, affects Microsoft’s Internet Key Exchange (IKE) Service Extensions.
According to Palo Alto Networks Unit 42, the vulnerability has been exploited by a Chinese-speaking threat actor. The activity reportedly occurred alongside an AI-enabled autonomous hacking campaign involving DeepSeek, as well as more conventional hands-on exploitation of known vulnerabilities.
The combination of automated and manual techniques demonstrates how threat actors are increasingly combining emerging AI capabilities with established vulnerability-exploitation methods.
CISA Urges Federal Agencies to Patch Immediately
Federal Civilian Executive Branch (FCEB) agencies have been given until August 21, 2026, to address the affected vulnerabilities and bring vulnerable systems up to the latest available versions in accordance with Binding Operational Directive (BOD) 26-04 patching requirements.
While the deadline specifically applies to FCEB agencies, private-sector organizations using the affected products should also treat the vulnerabilities as high-priority security issues given the evidence of active exploitation.
Key Takeaway
The addition of these four vulnerabilities to CISA’s KEV catalog underscores the growing risk posed by security flaws that have moved beyond theoretical or proof-of-concept exploitation into real-world attacks.
Organizations should apply the latest security updates, review exposed systems for signs of compromise, and monitor authentication and network activity associated with the affected products. Rapid patching is particularly important for internet-facing or otherwise network-accessible systems.
