CISA Orders Urgent Fixes for Four Actively Exploited Flaws in Windows, VMware, and macOS
Four security holes, all being actively abused by real attackers right now, need patches immediately. Two hit Microsoft, one VMware, one Apple.

Key points
- The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added four vulnerabilities to its official watch list on Tuesday, ordering federal agencies to patch by August 21, 2026.
- A Windows networking flaw, CVE-2026-33824, carries the highest severity score possible and was used in an AI-assisted hacking campaign linked to a Chinese-speaking group.
- A SharePoint login-bypass flaw, CVE-2026-55040, came under active attack within days of a public proof-of-concept exploit being posted online.
- A VMware server bug was exploited just five days after its patch shipped, and attackers used it to install remote-access software on victim machines.
- A macOS Screen Sharing flaw let attackers log in without a password and plant cryptocurrency-mining malware within a week of Apple's fix.
Four software flaws are being actively exploited by real attackers right now, across products that millions of organisations run every day. CISA, the U.S. government agency responsible for protecting federal computer systems, added all four to its Known Exploited Vulnerabilities catalog on Tuesday and told federal agencies to apply patches by August 21.
Ordinary organisations have no legal obligation to follow CISA's deadline, but the catalog is a reliable signal that attacks are happening and that waiting carries real risk.
What are the four flaws and how bad are they?
Security researchers score vulnerabilities on a 10-point scale called CVSS, where 10 is worst. Three of these four flaws score 9.1 or higher.
| Flaw | Product | CVSS | Patched | Exploited |
|---|---|---|---|---|
| CVE-2026-33824 | Windows IKE Service | 9.8 | April 2026 | Late July 2026 |
| CVE-2026-55040 | Microsoft SharePoint | 9.1 | July 2026 | Early August 2026 |
| CVE-2026-59310 | VMware vCenter | 9.8 | July 29, 2026 | August 3, 2026 |
| CVE-2026-65400 | macOS Screen Sharing | 7.5 | August 6, 2026 | Within one week |
The Windows IKE (Internet Key Exchange) flaw sits inside the networking component Windows uses to set up encrypted connections. An attacker anywhere on the internet, needing no username or password, can send specially crafted data packets to a vulnerable machine and run whatever code they like on it. Palo Alto Networks flagged the flaw as being used in attacks combining automated AI tools with some manual hacking, attributed to a Chinese-speaking group.
The SharePoint bug is an authentication bypass, meaning attackers can skip the login screen entirely on a vulnerable SharePoint server. Microsoft fixed it on its July 2026 Patch Tuesday update cycle. Attacks started shortly after someone published a working proof-of-concept, which is essentially a ready-made demonstration that shows other criminals exactly how to exploit the flaw.
What about the VMware and Apple bugs?
Both were weaponised within days of their patches going public.
The VMware vCenter bug, which affects the software organisations use to manage large numbers of virtual servers from a single dashboard, was patched on July 29. Attackers were already using it by August 3 to install an open-source reverse shell framework, which is a tool that lets a remote attacker send commands to a compromised machine as if they were sitting at the keyboard.
Apple's macOS Screen Sharing flaw let criminals bypass the password prompt and log straight into a Mac. Once in, attackers were seen installing a Monero miner, software that quietly uses the victim's computer to generate cryptocurrency for the attacker, draining processing power and running up electricity bills.
Should ordinary users and businesses worry?
Yes, if they haven't updated. The fixes already exist. The problem is unpatched machines.
If you run SharePoint, VMware vCenter, or a Mac with Screen Sharing turned on, apply the latest updates now. Windows users should check that April's and July's cumulative updates are installed. IT teams who need specifics can cross-reference the CVE IDs above with their patch management records.
SecurityWeek first reported the catalog additions.
Common questions
Do I need to do anything if I'm just a regular Mac user?
If your Mac is set to install updates automatically, you're likely already protected. Open System Settings, click General, then Software Update, and confirm you're running the latest macOS version released after August 6, 2026.
What is CISA's Known Exploited Vulnerabilities list?
It's a public catalog of security flaws that CISA has confirmed are being actively used by real attackers, not just theoretically risky. Federal agencies must patch listed flaws by the stated deadline, and it's a practical shortlist for any IT team deciding what to fix first.



