CISA flags four actively exploited flaws in Microsoft, VMware and Apple products

The US cyber agency has told federal bodies to patch fast after seeing real attacks against SharePoint, vCenter, macOS and a Windows networking service.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
Multiple windows showing security patch notifications and system update dialogs stacked across a desktop environment, with warning badges highlighted in red and
Share

Key points

  • CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog, a public list of software flaws being used in real attacks.
  • The affected products are Microsoft SharePoint, Microsoft Windows IKE networking service, Broadcom VMware vCenter and Apple macOS.
  • Federal civilian agencies must patch these under Binding Operational Directive 26-04, which sets deadlines for fixing high-risk flaws on publicly exposed assets.
  • CISA is urging every organisation, not just government, to prioritise these four fixes.
  • The bugs cover authentication bypass, path traversal and memory corruption, all classic routes to full machine takeover.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added four more software bugs to its running list of flaws that criminals are actively abusing in the wild.

That list, the Known Exploited Vulnerabilities catalog, is the closest thing the industry has to a "patch these first" board. If a flaw lands on it, someone's already been caught using it against real victims.

This batch hits Microsoft, Broadcom's VMware and Apple.

What are the four flaws?

Two Microsoft bugs, one VMware bug, one Apple bug, all being exploited now. Each gives an attacker a foothold or full control if the target hasn't been patched.

Here is what CISA published:

CVE ID Product Type of flaw
CVE-2026-33824 Microsoft Windows IKE service Double free (memory corruption)
CVE-2026-55040 Microsoft SharePoint Weak authentication
CVE-2026-59310 Broadcom VMware vCenter Path traversal
CVE-2026-65400 Apple macOS Improper authentication

The SharePoint and macOS bugs let an attacker slip past login checks. The vCenter path traversal, a trick that lets an attacker read or write files outside the folder they're supposed to be in, is nasty because vCenter runs entire virtual data centres. The Windows IKE double free, a memory-handling bug in the service that negotiates encrypted network tunnels, can be pushed toward remote code execution by an attacker who knows what they're doing.

We covered the vCenter story on 12 August, when a directory-traversal bug rated 9.8 out of 10 was already under active attack and SEC and EU disclosure duties had landed squarely on affected firms. That context makes today's KEV listing feel overdue rather than surprising. Platform teams running VMware should treat this as the loudest alarm of the week: own vCenter, own the hypervisor, own every virtual machine sitting on top of it.

On SharePoint, our 11 August story showed researchers chaining CVE-2026-55040 into an unauthenticated takeover using an AI agent. It carries a CVSS score of 9.1 and hits three server editions still common across government and enterprise.

Who has to patch, and by when?

US federal civilian agencies are on the clock under Binding Operational Directive 26-04, CISA's rule that forces government bodies to fix KEV-listed flaws on publicly exposed assets that grant total control post-exploitation. BOD 26-04 also requires agencies to check whether attackers got in before the patch was applied, meaning log review and threat hunting, not just running Windows Update and calling it done. We've covered BOD 26-04 seven times since tracking it from 10 June.

The directive only binds federal agencies, but CISA's asking every private organisation to treat the KEV list the same way. If a bug's on the KEV list, the exploit isn't theoretical anymore.

Should ordinary people worry?

Not directly, but SharePoint stores corporate documents and vCenter runs the servers behind hospitals and government portals. When these get compromised, data leaks and services go down. Watch for unusual account activity, use multi-factor authentication where it's offered, and treat any unsolicited password-reset email in the coming weeks with suspicion.

For IT teams, the failure mode is familiar. Public-facing SharePoint and vCenter instances that nobody remembered to inventory. The post-mortem will say, again, that the patch was available but the asset wasn't on anyone's list. Pull your KEV list into your ticketing system, tag anything internet-facing, and treat these four as this week's problem.

© 2026 Threat Vectr