Four Exploited Flaws Enter CISA KEV Catalog
CISA adds four actively exploited vulnerabilities affecting macOS, SharePoint, vCenter, and Windows IKE to its KEV catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on Tuesday, warning that all four are under active exploitation in the wild. The flaws span Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft's Internet Key Exchange (IKE) Service Extensions, with each carrying a high or critical severity score.
KEV Catalog Additions
CISA's KEV catalog tracks vulnerabilities that have been confirmed as exploited, providing a federal mandate for patching. The four additions are:
- CVE-2026-65400 (CVSS 9.8) - An improper authentication vulnerability in Apple macOS that could allow a network attacker to authenticate to Screen Sharing without valid credentials.
- CVE-2026-55040 (CVSS 9.1) - A weak authentication vulnerability in Microsoft SharePoint that could allow an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-59310 (CVSS 9.8) - A path traversal vulnerability in Broadcom VMware vCenter that could allow a threat actor with network access to execute arbitrary code.
- CVE-2026-33824 (CVSS 9.8) - A double free vulnerability in Microsoft Internet Key Exchange (IKE) Service Extensions that could allow an unauthorized attacker to execute code over a network.
All four have been patched by their respective vendors, but public reports indicate active exploitation continues.
MacOS Flaw Used for Cryptocurrency Mining
The Apple macOS vulnerability has been exploited to deliver a Monero cryptocurrency miner. Monero is a privacy-focused cryptocurrency often favored in illicit mining operations because of its untraceable nature. The attack leverages the Screen Sharing authentication flaw to gain unauthorized access.
SharePoint Exploitation After PoC Release
Microsoft SharePoint's vulnerability has been exploited by unknown actors following the release of a proof-of-concept (PoC) code. The weak authentication flaw allows attackers to bypass security features over the network, potentially leading to unauthorized access to sensitive data.
VMware vCenter Backdoor and Ransomware
The VMware vCenter vulnerability is assessed to have been exploited by a suspected China-nexus advanced persistent threat (APT) actor. The attackers deployed a backdoor along with reverse_ssh binaries to maintain persistent access to compromised instances. In at least one case, the campaign led to the deployment of a Babuk-derived ransomware.
Global Scope of Attacks
In total, the activity compromised 361 unique victim IP addresses across 47 countries. The most infections were concentrated in Germany (55), the U.S. (41), Turkey (38), Iran (26), and France (25).
IKE Vulnerability Exploited with AI
CVE-2026-33824, per Palo Alto Networks Unit 42, has been observed being exploited by another Chinese-speaking threat actor. This actor is said to have simultaneously launched an AI-enabled autonomous hacking campaign using DeepSeek and conducted manual operations using known vulnerabilities, including Microsoft Internet Key Exchange.
Federal Deadline for Patching
Federal Civilian Executive Branch (FCEB) agencies have until August 21, 2026, to update vulnerable systems to the latest version and adhere to BOD 26-04 patching guidelines for optimal protection.
What This Means for Defenders
The addition of these vulnerabilities to CISA's KEV catalog underscores the urgency for organizations to patch. The breadth of techniques — from cryptocurrency miners to ransomware — suggests that adversaries are actively leveraging these flaws for various malicious ends. The involvement of suspected state-sponsored actors and the use of AI-enabled tools could mean that future exploitation will be even more sophisticated and harder to detect. For defenders, patching these known exploited flaws is not just a best practice but an immediate necessity to avoid falling victim to these active threats.
Sources
- The Hacker News Original source
Continue Reading
US Charges 17 in Iran Academic Hack, $10M Bounties
US charges 17 Iran-linked hackers for global academic data theft, offers $10M rewards for five.
Quest data leak exposes years of guest records
Australian apart-hotel chain Quest warns guests of a data breach via a third-party provider, risking identity fraud.
When Ransomware Victims Get a Rescue Offer From a Stranger
A ransomware affiliate is contacting victims, offering to delete stolen data for $20,000–$60,000. Experts call it a scam.