CISA Warns of Active Exploitation of Critical Flaws in VMware vCenter, macOS, and SharePoint
The U.S. Cybersecurity and Infrastructure Security Agency has added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog, urging immediate patching across major enterprise platforms.
By Lila Morgan
- Federal Security Mandates
- CISA emphasizes strict compliance timelines and risk-based prioritization for government agencies.
- Threat Intelligence Analysts
- Security researchers focus on the rapid weaponization of vulnerabilities by advanced persistent threats.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming that attackers are actively leveraging flaws in Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft Windows Internet Key Exchange (IKE). The additions trigger a mandatory remediation deadline of August 21, 2026, for Federal Civilian Executive Branch agencies, while serving as a high-priority warning for private sector defenders.[1][2][3]
The common thread among the four vulnerabilities is not simply that vendors have shipped fixes, but that each flaw sits on a distinct, high-value operational trust boundary. VMware vCenter controls virtualization infrastructure, SharePoint manages enterprise content and identity, macOS Screen Sharing touches endpoint access, and IKE operates within core Windows network services. CISA's directive emphasizes that patching alone may not be sufficient; organizations must also verify whether threat actors compromised their systems before the updates were applied.[1][3]
The VMware vCenter vulnerability, tracked as CVE-2026-59310, is a path traversal bug carrying a maximum CVSS score of 9.8. It allows an attacker with network access to execute arbitrary code. Threat intelligence indicates that a suspected China-nexus advanced persistent threat actor has exploited this flaw to deploy backdoors and reverse SSH binaries, ensuring persistent access to compromised instances. In at least one observed campaign, the intrusion culminated in the deployment of a Babuk-derived ransomware strain, affecting hundreds of unique IP addresses globally.[1][2]
Microsoft's ecosystem faces dual threats from the recent KEV additions. The SharePoint vulnerability (CVE-2026-55040) is a weak authentication flaw that allows an unauthenticated remote attacker to bypass security features and forge valid JSON Web Tokens. Exploitation in the wild surged shortly after a proof-of-concept was published. Meanwhile, the Windows IKE Service Extensions vulnerability (CVE-2026-33824) is a critical double-free error that grants remote code execution. Security researchers observed a Chinese-speaking threat actor exploiting this IKE flaw as part of a broader, AI-enabled autonomous hacking campaign.[1][2][4]
Microsoft's ecosystem faces dual threats from the recent KEV additions.
Apple's macOS is also targeted through an improper authentication vulnerability (CVE-2026-65400) in its built-in Screen Sharing feature. The flaw allows an attacker on the same network to authenticate to the remote desktop tool without valid credentials. While Apple released a patch earlier in the month to improve how the system manages authentication states, attackers quickly weaponized the gap to gain root access and deploy Monero cryptocurrency miners on vulnerable machines.[1][2]
The mechanics of the SharePoint vulnerability illustrate the complexity of modern enterprise exploits. The flaw involves a chain of weaknesses within the JSON Web Token validation pipeline of SharePoint Server Subscription Edition. When these weaknesses are combined, they allow an attacker to forge valid tokens and impersonate any user, including high-level administrators. Because SharePoint frequently serves as the central repository for an organization's most sensitive documents and internal communications, this level of unauthorized access poses a severe risk to corporate data integrity.[1][2]
Similarly, the broader implications of the Windows IKE vulnerability highlight the fragility of perimeter defenses. The Internet Key Exchange protocol is fundamental to establishing secure IPsec virtual private network connections. Because VPN endpoints are inherently exposed to the public internet to facilitate remote workforce access, they represent a highly attractive target for initial access brokers. The observation that threat actors are now automating the exploitation of such perimeter devices using AI-assisted tools signals a significant shift in how rapidly organizations must respond to patch releases.[1][2][4]
For network defenders, the immediate priority is identifying exposed instances of these four services. Systems with IKE enabled are particularly at risk from external threats, though restricting UDP ports 500 and 4500 can reduce exposure. However, because internal attackers can still exploit the IKE flaw for lateral movement, rapid patching remains the only definitive mitigation. The active exploitation of these vulnerabilities underscores the necessity of risk-based patch management, prioritizing internet-facing assets that grant total control post-exploitation.[2][3]
Key points
- CISA added critical flaws in macOS, SharePoint, vCenter, and Windows IKE to its Known Exploited Vulnerabilities catalog.
- Federal agencies are mandated to apply patches for these vulnerabilities by August 21, 2026.
- The VMware vCenter flaw has been exploited to deploy backdoors and ransomware across hundreds of global targets.
- The macOS Screen Sharing vulnerability allows network attackers to bypass authentication and deploy cryptocurrency miners.
- Defenders are advised to check for signs of post-exploitation compromise even after systems are patched.
Why this matters
These vulnerabilities affect foundational infrastructure present in almost every enterprise environment. By confirming active exploitation, CISA is signaling that organizations must move these patches to the front of the queue to prevent immediate network compromise.
Sources
[1]The Hacker NewsThreat Intelligence AnalystsCritical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
Read on The Hacker News →
[2]Security AffairsThreat Intelligence AnalystsU.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog
Read on Security Affairs →
[3]Cybersecurity and Infrastructure Security AgencyFederal Security MandatesCISA Adds Four Known Exploited Vulnerabilities to Catalog
Read on Cybersecurity and Infrastructure Security Agency →
[4]National Vulnerability DatabaseFederal Security MandatesCVE-2026-33824 Detail
Read on National Vulnerability Database →
Comments
Every angle. Every day.
Get technology stories with full source coverage and perspective breakdowns delivered to your inbox.

