Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
ID: cdf8472a-d458-53f8-b0cb-1a5b7db13f00
STIX ID: report--cdf8472a-d458-53f8-b0cb-1a5b7db13f00
Feed Name: The Hacker News
CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog after reports of active exploitation: an Apple macOS Screen Sharing authentication flaw (CVE-2026-65400), a Microsoft SharePoint weak-auth issue (CVE-2026-55040), a Broadcom VMware vCenter path traversal (CVE-2026-59310), and a Microsoft IKE double-free (CVE-2026-33824). Vendors have released patches, but public exploitation has resulted in Monero miners, backdoors with reverse_ssh for persistence, and a Babuk-derived ransomware deployment; activity has impacted 361 unique victim IPs across 47 countries and involves suspected China-linked APT activity. Federal civilian agencies were given an August 21, 2026 remediation deadline per BOD 26-04.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
