logo

U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog

ID: 8ceec2cb-e363-5a21-8003-c85da30d1943

STIX ID: report--8ceec2cb-e363-5a21-8003-c85da30d1943

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2026-08-19

Date Updated: 2026-08-19

Author: Pierluigi Paganini

...
...

CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog—CVE-2026-33824 (Windows IKE double free, RCE), CVE-2026-55040 (SharePoint JWT authentication bypass), CVE-2026-59310 (Broadcom/VMware vCenter path traversal leading to code execution), and CVE-2026-65400 (macOS Screen Sharing improper authentication). The advisory notes high CVSS scores (up to 9.8), evidence of active exploitation (macOS confirmed exploited; SharePoint POC used against honeypots), recommends immediate patching and mitigations (e.g., blocking UDP 500/4500 for IKE), and directs federal agencies to remediate by August 21, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.