Mastodon Mastodon Mastodon Mastodon

Critical macOS, vCenter, SharePoint and IKE Bugs Added to CISA KEV

Photo of author

CyberSecureFox Editorial Team

Published:

On August 18, 2026, CISA added four critical vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog, confirming that they are being actively exploited. The issues affect Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft Internet Key Exchange (IKE) Service Extensions — products widely used across enterprise and government infrastructures. All four vulnerabilities are rated critical, and patches have already been released by the vendors. U.S. federal civilian agencies are required to remediate the vulnerabilities by August 21, 2026 in accordance with directive BOD 26-04.

Technical details of the vulnerabilities

Each of the four vulnerabilities represents a distinct attack vector, but they all share one key property: the potential for remote network exploitation without prior authentication, or with authentication bypass.

  • CVE-2026-65400 (Apple macOS) is an improper authentication vulnerability in the Screen Sharing mechanism. It allows a network-based attacker to authenticate without valid credentials. This provides direct access to the desktop of the target system, making the vulnerability particularly dangerous for organizations that use the screen sharing feature in macOS.
  • CVE-2026-55040 (Microsoft SharePoint) is a weak authentication vulnerability that allows an unauthorized attacker to bypass the security mechanism over the network. Given SharePoint’s role as a corporate document repository and collaboration platform, compromise can lead to leakage of sensitive data.
  • CVE-2026-59310 (Broadcom VMware vCenter) is a path traversal vulnerability that allows an attacker with network access to vCenter to execute arbitrary code. vCenter is the central management component of virtualized infrastructure, and its compromise can potentially provide control over all managed virtual machines.
  • CVE-2026-33824 (Microsoft IKE Service Extensions) is a double free vulnerability that allows an unauthorized attacker to execute code over the network. IKE is used to establish IPsec VPN connections, which makes this vulnerability critical for perimeter security.

All four vulnerabilities have reportedly been fixed by the respective vendors; however, their inclusion in the KEV catalog confirms that unpatched systems continue to be targeted in attacks.

Threat context and observed campaigns

Available information indicates that each vulnerability is being exploited as part of different campaigns with varying objectives.

The vulnerability in Microsoft SharePoint (CVE-2026-55040) reportedly began to be exploited by unknown attackers after proof-of-concept (PoC) code was published. This is a typical scenario in which the appearance of a public exploit sharply lowers the barrier to entry for attackers.

The most extensive campaign appears to be associated with VMware vCenter (CVE-2026-59310). According to sources, a China-linked advanced persistent threat (APT) group is believed to have used this vulnerability to deploy backdoors and reverse_ssh tools, enabling persistent access to compromised systems. In some cases, the attack reportedly culminated in the deployment of ransomware based on Babuk code. Available data indicates that the campaign affected 361 unique victim IP addresses in 47 countries, with the highest concentrations in Germany (55), the United States (41), Turkey (38), Iran (26), and France (25). It should be noted that attribution to specific groups and the details of the campaign are not confirmed by primary sources in the available data set and should be interpreted with caution.

The vulnerability in Microsoft IKE (CVE-2026-33824) is reportedly being exploited by another Chinese-speaking threat actor, according to data attributed to Palo Alto Networks Unit 42. However, the specific Unit 42 report was not made available for independent verification.

Impact assessment

Taken together, these four vulnerabilities pose a threat to a wide range of organizations. The affected products cover key components of corporate infrastructure:

  • Virtualization (VMware vCenter) — compromise at the hypervisor layer can lead to cascading compromise of all virtual machines in the environment;
  • Collaboration and document management (SharePoint) — risk of corporate data leakage and use of the platform as a foothold for lateral movement;
  • Workstations (macOS) — direct access to the screen without authentication allows interception of user data and actions;
  • Network perimeter (IKE) — a vulnerability in a VPN component puts secure communication channels at risk.

Of particular concern is the combination of vCenter exploitation with ransomware deployment: compromising the virtualization management center allows entire virtual environments to be encrypted at once, greatly amplifying the damage.

Practical recommendations

  1. Immediately apply patches for all four affected products. All vendors have reportedly released fixes. Priority should go to VMware vCenter and Microsoft IKE due to the potential for remote code execution.
  2. Check for vulnerable versions in your environment. Pay special attention to vCenter systems reachable over the network and SharePoint servers with external access.
  3. Conduct retrospective analysis (threat hunting) for signs of compromise: presence of reverse_ssh utilities, unusual SSH connections originating from vCenter servers, and abnormal authentication processes in macOS Screen Sharing.
  4. Restrict network access to vCenter management interfaces and IKE services if immediate patching is not possible. Use network segmentation and access control lists.
  5. Disable Screen Sharing on macOS systems where this feature is not required for business operations until the update is applied.
  6. Monitor for publication of PoC code for CVE-2026-65400, CVE-2026-59310, and CVE-2026-33824 — the appearance of public exploits will inevitably expand the pool of attackers.

U.S. federal civilian executive branch agencies (FCEB) are required to remediate all four vulnerabilities by August 21, 2026 under directive BOD 26-04. Commercial organizations are advised to follow similar timelines — the three-day window between KEV publication and the deadline reflects the criticality of the situation. Recommended patching priority: CVE-2026-59310 (vCenter, confirmed ransomware campaigns), followed by CVE-2026-33824 (IKE, perimeter vector), CVE-2026-55040 (SharePoint, public PoC available), and CVE-2026-65400 (macOS).


CyberSecureFox Editorial Team

The CyberSecureFox Editorial Team covers cybersecurity news, vulnerabilities, malware campaigns, ransomware activity, AI security, cloud security, and vendor security advisories. Articles are prepared using official advisories, CVE/NVD data, CISA alerts, vendor publications, and public research reports. Content is reviewed before publication and updated when new information becomes available.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.