Exploits

CISA Adds 4 Critical Vulnerabilities to KEV Catalog

Published  ·  6 min read

The U.S. Cybersecurity and Infrastructure Security Agency just added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog. And here's the kicker: all of them are being actively exploited right now.

If you use Apple macOS, Microsoft SharePoint, VMware vCenter, or Microsoft Internet Key Exchange Service Extensions, this affects you. Patches are available, but attackers are already taking advantage of unpatched systems.

Federal agencies have until August 21, 2026, to patch. But don't wait. Attackers are scanning for vulnerable systems as you read this.

Let me walk you through exactly what these vulnerabilities are, how they're being exploited, and what you need to do right now.

What Is the CISA KEV Catalog?

The CISA Known Exploited Vulnerabilities list contains all security flaws that are being actively used in real-world attacks. Every time when CISA modifies its Known Exploited Vulnerabilities list, that becomes an indicator that patching should be done immediately or facing compromise.

The 4 Critical Vulnerabilities

1. CVE-2026-65400 – Apple macOS Screen Sharing (CVSS 9.8)

This is an improper authentication vulnerability in the macOS Screen Sharing component. An attacker on the same network as your Mac can log in without needing a password.

Attackers are using this flaw to install Monero cryptocurrency miners on vulnerable Macs. The Netherlands NCSC confirmed active exploitation across multiple systems.

Who's affected: all macOS up to version 26.6.1 for Tahoes, 15.7.9 for Sequoias, and 14.8.9 for Sonomas.

The fix: Apple patched this in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.

The scary part: More than 40,000 hosts with the Screen Sharing are exposed online. Almost half of the hosts are based in the United States.

What to do: Update to the newest macOS version. In case an Update is not possible, turn off the Screen Sharing.

2. CVE-2026-55040 – Microsoft SharePoint Authentication Bypass (CVSS 9.1)

This is a weak authentication flaw in Microsoft SharePoint. The attackers will exploit the vulnerability to bypass security features via the network and gain access to the SharePoint data.

The attackers have used the proof-of-concept exploit developed by Rapid7. There have been 12 exploitation attempts since July 19, 2026, out of which eight attempts occurred post-release of the PoC.

Attack origins: Hong Kong, Japan, Netherlands, Taiwan, and the United States.

What to do: Install the Patch Tuesday update of July 2026 as soon as possible.

3. CVE-2026-59310 – VMware vCenter Path Traversal (CVSS 9.8)

It is the path traversal vulnerability of Broadcom VMware vCenter. Attackers with network access can execute arbitrary code on your vCenter server.

A suspected China-nexus APT group is exploiting this flaw. They're deploying backdoors and reverse_ssh binaries for persistent access. In at least one case, Babuk-derived ransomware was deployed.

The scale: 361 unique victim IP addresses from 47 different countries. The countries which are most impacted by this are Germany (55), USA (41), Turkey (38), Iran (26), and France (25).

What to do: The patch should be applied from Broadcom on 29th July 2026. Be careful about any administrator accounts not authorized.

4. CVE-2026-33824 – Microsoft IKE Service Extensions (CVSS 9.8)

This is a double free vulnerability in Microsoft Internet Key Exchange Service Extensions. Attackers can execute code over your network without authorization.

Palo Alto Networks Unit 42 observed exploitation by a Chinese-speaking threat actor. The actor launched a campaign involving AI-powered hack using DeepSeek as well as exploiting vulnerabilities through manual hacking attacks.

What to do: Install all the new security updates from Microsoft.

Why Are These Vulnerabilities Being Exploited?

Attackers are moving fast. Here's why:

Vulnerability

How It's Being Exploited

The Risk

CVE-2026-65400 (macOS)

Monero crypto miner

Unauthorized network access to your Mac

CVE-2026-55040 (SharePoint)

PoC exploit from Rapid7

Complete SharePoint compromise

CVE-2026-59310 (VMware)

China-nexus APT group

Backdoor and ransomware deployment

CVE-2026-33824 (IKE)

AI-powered hacking

Remote code execution

What happens when you don’t patch?

This is what can happen to you:

  • macOS users: The attacker from within your network can gain unauthorized access to your Mac and deploy crypto miners.
  • SharePoint administrators: The attackers will be able to bypass the authentication process and steal sensitive data.
  • VMware vCenter administrators: The attackers will be able to execute arbitrary code and deploy ransomware.
  • Microsoft IKE users: Attackers could execute code over your network.

CISA's Urgent Warning

CISA has made it clear: these vulnerabilities are being actively exploited right now.

FCEB agencies have been allotted up to August 21, 2026, for securing their systems. This has been specified under Binding Operational Directive 26-04.

Don't wait. Patch now.

What Should You Do Immediately

For Apple macOS Users:

  • Upgrade to macOS Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9
  • Disable Screen Sharing if not needed
  • Watch for unauthorized access attempts

For Microsoft SharePoint Admins:

  • Implement July 2026 Patch Tuesday Patches
  • Focus on CVE-2026-55040
  • Watch for signs of compromise

For VMware vCenter Admins:

  • Apply Broadcom’s July 29, 2026 patch
  • Look for unauthorized admin accounts
  • Monitor for reverse_ssh binaries

For Microsoft IKE Users:

Apply latest security patches from Microsoft

Detect remote code execution attacks

What Should You Do if You Are Under Attack?

For macOS Users:

  • Watch out for strange activities on Terminal
  • See whether there is any Screen Sharing session
  • Identify any crypto mining processes

For SharePoint Admins:

  • Review authentication logs for unusual access
  • Check for unexpected admin accounts
  • Monitor for data exfiltration

For VMware vCenter Admins:

  • Check for malformed cron files
  • Look for reverse_ssh binaries
  • Monitor for unauthorized accounts

The Bottom Line

Four critical vulnerabilities. All actively exploited. All with patches available.

CISA added these to the KEV catalog for a reason. Attackers are already using them. If you don't patch, you're at risk.

  • Federal agencies: Patch by August 21, 2026.
  • Everyone else: Patch as soon as possible.

FAQ Section

What is the CISA KEV catalog?

The CISA Known Exploited Vulnerabilities Catalog is an official list of known security vulnerabilities that are currently exploited by attackers. This catalog enables prioritization of patches for organizations.

Which vulnerabilities were added to the KEV catalog?

CISA added CVE-2026-65400 (macOS Screen Sharing), CVE-2026-55040 (SharePoint), CVE-2026-59310 (VMware vCenter), and CVE-2026-33824 (Microsoft IKE Service Extensions).

Are these vulnerabilities being exploited?

Yes. All four are being actively exploited right now.

What is the deadline for federal agencies?

Federal agencies have until August 21, 2026, to patch their systems as per Binding Operational Directive 26-04.

What steps should I take if I am using these products?

Apply patches immediately. Watch out for signs of compromise. Look out for unauthorized access.

Source: The Hacker News
Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067