CISA has added four actively exploited security vulnerabilities to its Known Exploited Vulnerabilities catalog, covering Microsoft Windows, SharePoint, VMware vCenter and Apple macOS.
The inclusion matters because CISA only adds vulnerabilities when there is evidence that attackers are using them in real world attacks. That means these flaws should be treated as immediate patching priorities rather than theoretical risks.
The affected vulnerabilities include two critical issues with CVSS scores of 9.8, along with serious flaws in SharePoint and macOS.
Four actively exploited vulnerabilities need attention
The most urgent Windows flaw is CVE 2026 33824, which affects Microsoft’s Internet Key Exchange service extensions.
The vulnerability is caused by a double free memory error. Under the right conditions, an unauthenticated attacker can exploit it remotely and execute code on an affected system.
Microsoft already fixed the issue in its April security updates, so PCs and servers that have not installed those patches remain at risk.
| Vulnerability | Product | Severity | Main risk |
|---|---|---|---|
| CVE 2026 33824 | Windows IKE | 9.8 | Remote code execution |
| CVE 2026 55040 | Microsoft SharePoint | 9.1 | Security feature bypass |
| CVE 2026 59310 | VMware vCenter | 9.8 | Path traversal and code execution |
| CVE 2026 65400 | macOS | 7.1 originally | Screen Sharing authentication bypass |
The Windows issue affects several versions of Windows 10, Windows 11 and Windows Server.
If your system has not received the April security updates, installing current patches should be a priority.
SharePoint and VMware flaws carry major enterprise risk
CVE 2026 55040 affects SharePoint Enterprise Server 2016, SharePoint Server 2019 and the Subscription Edition.

It allows an unauthenticated attacker to bypass a security feature over the network. Microsoft has already released fixed builds.
The issue is particularly concerning because publicly available exploit code was reportedly circulating before CISA added the vulnerability to its catalog.
VMware vCenter is affected by CVE 2026 59310, a path traversal vulnerability in its syslog server.
An attacker with network access can potentially access files outside the expected directories and then execute arbitrary code.
The flaw carries a critical CVSS score of 9.8.
Reports indicate that attackers have already used the vulnerability to establish persistent access in VMware environments, with ransomware also linked to some attacks.
Because vCenter controls large virtualized environments, compromising it can give attackers access to multiple connected systems.
macOS Screen Sharing flaw can bypass authentication
Apple systems are affected by CVE 2026 65400.
The flaw involves macOS Screen Sharing and can allow an attacker on the network to bypass authentication under certain conditions.
Apple fixed the issue with improved state management in updates released on August 6.
The patched versions include macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9.
Reports indicate that the flaw has been used to install malware that mines the Monero cryptocurrency on compromised Macs.
The risk is highest on systems where Screen Sharing is enabled and exposed to the network.
Installing patches may not be enough after compromise
For home users, the main action is simple: install the latest available security updates for Windows or macOS.
Organizations should go further.
Administrators should update SharePoint and VMware vCenter systems, check whether vulnerable services were exposed to the internet and look for signs of compromise such as unusual login attempts, unknown accounts or suspicious processes.
A system that was already breached before patching may still contain persistent access mechanisms even after the vulnerability itself has been fixed.
CISA’s warning does not mean every Windows PC, Mac or server is automatically compromised. It does mean these vulnerabilities are being actively used by attackers, making delayed patching much more dangerous than usual.



Discussion (0)
Be the first to comment.