Breaking
Cyber CrimeConfirmed

Four Exploited Flaws Enter CISA KEV Catalog

CISA adds four actively exploited vulnerabilities affecting macOS, SharePoint, vCenter, and Windows IKE to its KEV catalog.

··2 hours ago·3 min read
Green computer code text scrolling on a dark screen during a software installation
Photo by Jake Walker on Unsplash

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on Tuesday, warning that all four are under active exploitation in the wild. The flaws span Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft's Internet Key Exchange (IKE) Service Extensions, with each carrying a high or critical severity score.

KEV Catalog Additions

CISA's KEV catalog tracks vulnerabilities that have been confirmed as exploited, providing a federal mandate for patching. The four additions are:

  • CVE-2026-65400 (CVSS 9.8) - An improper authentication vulnerability in Apple macOS that could allow a network attacker to authenticate to Screen Sharing without valid credentials.
  • CVE-2026-55040 (CVSS 9.1) - A weak authentication vulnerability in Microsoft SharePoint that could allow an unauthorized attacker to bypass a security feature over a network.
  • CVE-2026-59310 (CVSS 9.8) - A path traversal vulnerability in Broadcom VMware vCenter that could allow a threat actor with network access to execute arbitrary code.
  • CVE-2026-33824 (CVSS 9.8) - A double free vulnerability in Microsoft Internet Key Exchange (IKE) Service Extensions that could allow an unauthorized attacker to execute code over a network.

All four have been patched by their respective vendors, but public reports indicate active exploitation continues.

MacOS Flaw Used for Cryptocurrency Mining

The Apple macOS vulnerability has been exploited to deliver a Monero cryptocurrency miner. Monero is a privacy-focused cryptocurrency often favored in illicit mining operations because of its untraceable nature. The attack leverages the Screen Sharing authentication flaw to gain unauthorized access.

SharePoint Exploitation After PoC Release

Microsoft SharePoint's vulnerability has been exploited by unknown actors following the release of a proof-of-concept (PoC) code. The weak authentication flaw allows attackers to bypass security features over the network, potentially leading to unauthorized access to sensitive data.

VMware vCenter Backdoor and Ransomware

The VMware vCenter vulnerability is assessed to have been exploited by a suspected China-nexus advanced persistent threat (APT) actor. The attackers deployed a backdoor along with reverse_ssh binaries to maintain persistent access to compromised instances. In at least one case, the campaign led to the deployment of a Babuk-derived ransomware.

Global Scope of Attacks

In total, the activity compromised 361 unique victim IP addresses across 47 countries. The most infections were concentrated in Germany (55), the U.S. (41), Turkey (38), Iran (26), and France (25).

IKE Vulnerability Exploited with AI

CVE-2026-33824, per Palo Alto Networks Unit 42, has been observed being exploited by another Chinese-speaking threat actor. This actor is said to have simultaneously launched an AI-enabled autonomous hacking campaign using DeepSeek and conducted manual operations using known vulnerabilities, including Microsoft Internet Key Exchange.

Federal Deadline for Patching

Federal Civilian Executive Branch (FCEB) agencies have until August 21, 2026, to update vulnerable systems to the latest version and adhere to BOD 26-04 patching guidelines for optimal protection.

What This Means for Defenders

The addition of these vulnerabilities to CISA's KEV catalog underscores the urgency for organizations to patch. The breadth of techniques — from cryptocurrency miners to ransomware — suggests that adversaries are actively leveraging these flaws for various malicious ends. The involvement of suspected state-sponsored actors and the use of AI-enabled tools could mean that future exploitation will be even more sophisticated and harder to detect. For defenders, patching these known exploited flaws is not just a best practice but an immediate necessity to avoid falling victim to these active threats.

#cve#cisa#kev#exploitation#ransomware#vulnerability

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories