Critical macOS, SharePoint, vCenter, and Microsoft IKE Vulnerabilities Under Active Exploitation, CISA Warns

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified four critical vulnerabilities that are currently being exploited in the wild. These vulnerabilities have been added to its Known Exploited Vulnerabilities (KEV) catalog, highlighting the urgency for organizations to address them.

Critical macOS, SharePoint, vCenter, and Microsoft IKE Vulnerabilities

The vulnerabilities include:

  • CVE-2026-65400 (CVSS score: 9.8) – An improper authentication vulnerability in Apple macOS that allows attackers to authenticate to Screen Sharing without valid credentials.
  • CVE-2026-55040 (CVSS score: 9.1) – A weak authentication vulnerability in Microsoft SharePoint that enables unauthorized attackers to bypass security features over a network.
  • CVE-2026-59310 (CVSS score: 9.8) – A path traversal vulnerability in Broadcom VMware vCenter that allows threat actors with network access to execute arbitrary code.
  • CVE-2026-33824 (CVSS score: 9.8) – A double free vulnerability in Microsoft Internet Key Exchange (IKE) Service Extensions that could permit unauthorized code execution over a network.

Despite being patched by the respective vendors, these vulnerabilities are under active exploitation. Reports indicate that the Apple macOS flaw has been used to deploy a Monero cryptocurrency miner, while the SharePoint vulnerability has been targeted following the release of proof-of-concept code.

The VMware vCenter vulnerability is believed to have been exploited by a suspected China-nexus advanced persistent threat (APT) actor, leading to the deployment of a backdoor and reverse_ssh binaries for persistent access. This campaign has reportedly resulted in the deployment of Babuk-derived ransomware.

Overall, these activities have compromised 361 unique victim IP addresses across 47 countries, with the highest concentrations of infections in Germany, the U.S., Turkey, Iran, and France. Federal Civilian Executive Branch (FCEB) agencies have until August 21, 2026, to update their systems in accordance with BOD 26-04 patching guidelines for optimal protection.

For further details, refer to the advisory published by The Hacker News.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

IDScan Confirms Data Breach Exposing 153 Million Driver’s License Scans for Sale on Dark Web

Identity verification firm IDScan has confirmed a data breach that has exposed scans of approximately 153 million driver’s licenses, with the information reportedly available...

NVIDIA and Palantir Collaborate to Enhance Supply Chain Sovereignty with AI Solutions

Palantir Technologies Inc. and NVIDIA have announced a strategic collaboration aimed at enhancing supply chain sovereignty through advanced artificial intelligence (AI) solutions. This partnership...

Microsoft Warns of AI-Enhanced Executive Impersonation and Invoice Fraud Campaigns

In a concerning trend, threat actors are leveraging artificial intelligence (AI) to enhance their tactics in executing executive impersonation and invoice fraud schemes. Recent...

NASA’s SARSAT technology aids in rescue of five fishermen at sea

NASA's Search and Rescue Satellite-Aided Tracking (SARSAT) technology played a crucial role in the rescue of five fishermen off the Gulf Coast of Mississippi...