What happened
The Cybersecurity and Infrastructure Security Agency added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on August 18, 2026, all confirmed under active exploitation. Three of the four carry a CVSS score of 9.8, the second-highest severity rating available.
The additions span four different vendors: Microsoft Windows, Microsoft SharePoint, Broadcom's VMware vCenter, and Apple macOS. Under Binding Operational Directive 26-04, CISA's current risk-based patching directive that replaced BOD 22-01 in June 2026, Federal Civilian Executive Branch agencies have until August 21 to remediate or disconnect affected systems.
The four vulnerabilities
CVE-2026-33824 is a double-free vulnerability in the Windows Internet Key Exchange (IKE) Service Extensions, rated CVSS 9.8. It lets an unauthenticated attacker execute code remotely by sending crafted packets to UDP ports 500 or 4500 on unpatched Windows 10, Windows 11 and Windows Server systems. Microsoft shipped a fix in its April 2026 Patch Tuesday release, according to Windows IKE analysis from SOCRadar, but CISA's KEV addition confirms attackers are now exploiting systems that were never patched.
CVE-2026-55040 is a weak authentication flaw in on-premises Microsoft SharePoint, rated CVSS 9.1. An unauthenticated attacker can forge JSON Web Tokens to bypass login and reach administrative functions and collaboration sites. The flaw affects SharePoint Server Subscription Edition, SharePoint Server 2019 and SharePoint Enterprise Server 2016; SharePoint Online is not affected. Microsoft patched the on-premises flaw in July 2026. Rapid7 published a technical breakdown on August 11, and exploitation against unpatched servers followed within hours, per Rapid7's own writeup.
CVE-2026-59310 is a path traversal vulnerability in the Syslog service of VMware vCenter Server, rated CVSS 9.8. It allows an attacker with network access to the service to execute commands as root without authenticating. Broadcom disclosed the flaw on July 29, 2026. Security firm QUIRSO mapped 361 affected IP addresses across 47 countries as of its scan, concentrated in technology, research, education and telecommunications environments, with Germany, the United States and Turkey showing the highest counts, according to reporting corroborated by Dark Reading and BleepingComputer. The fix ships in vCenter 9.1.0.0300, 9.0.2.0100, 8.0 U3k or 8.0 U2f and later.
CVE-2026-65400 is an improper authentication flaw in the macOS Screen Sharing daemon, initially scored CVSS 7.1 when Apple patched it on August 6 in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9. CISA rescored it to 9.8 on August 14 after reports of active exploitation, then added it to KEV on August 18. The Netherlands' NCSC-NL reported attackers reaching the service over TCP port 5900 exposed to the internet, authenticating without valid credentials, and installing Monero cryptocurrency miners, according to Tanium's advisory summary.
Who is affected
Federal civilian agencies are the parties formally bound by the August 21 deadline under BOD 26-04. In practice, exposure is broader. Any organization running on-premises SharePoint Server, internet-facing VMware vCenter, Windows systems with IKEv2/IPsec exposed to untrusted networks, or Mac systems with Screen Sharing reachable from the internet should treat these as immediate patching priorities regardless of sector.
CISA's advisory does not name or characterize the actors behind the exploitation, and this brief makes no attempt to fill that gap. The NCSC-NL report on the macOS flaw describes the observed payload, cryptocurrency mining malware, without attributing the campaign to a specific group.
What to do now
Organizations should check exposure against all four CVEs: confirm patch status on Windows systems handling IKE/IPsec traffic, verify on-premises SharePoint is running a patched build or restrict internet exposure, update vCenter to the fixed builds listed above, and confirm Mac endpoints with Screen Sharing enabled are on the patched OS versions. For internet-facing vCenter and macOS Screen Sharing instances in particular, restricting network exposure is a faster mitigation than waiting on a patch cycle.
CISA's KEV catalog entry for each CVE includes the required action and due date and is the authoritative reference for federal remediation obligations. Organizations outside the federal government are not bound by the directive but face the same exploitation activity.
Sources
- CISA, "CISA Adds Four Known Exploited Vulnerabilities to Catalog" (Aug 18, 2026) - https://www.cisa.gov/news-events/alerts/2026/08/18/cisa-adds-four-known-exploited-vulnerabilities-catalog
- The Hacker News, coverage of macOS/SharePoint/vCenter flaws - https://thehackernews.com/2026/08/critical-macos-sharepoint-vcenter-and.html
- Rapid7, "CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (Fixed)" - https://www.rapid7.com/blog/post/ve-cve-2026-55040-microsoft-sharepoint-jwt-token-authentication-bypass-fixed/
- SOCRadar, "Windows IKE CVE-2026-33824 CISA KEV" - https://socradar.io/blog/windows-ike-cve-2026-33824-cisa-kev/
- BleepingComputer, "Critical VMware vCenter RCE flaw exploited for reverse SSH access" - https://www.bleepingcomputer.com/news/security/critical-vmware-vcenter-rce-flaw-exploited-for-reverse-ssh-access/
- Dark Reading, "Global Threat Campaign: Critical VMware vCenter Flaw" - https://www.darkreading.com/vulnerabilities-threats/global-threat-campaign-critical-vmware-vcenter-flaw
- Tanium, "Guardian: Critical macOS Screen Sharing Authentication Bypass CVE-2026-65400" - https://www.tanium.com/blog/guardian-critical-macos-screen-sharing-authentication-bypass-cve-2026-65400
- CISA, "BOD 26-04: Prioritizing Security Updates Based on Risk" - https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
