Critical macOS, SharePoint, vCenter, and Microsoft IKE Vulnerabilities Under Active Exploitation, CISA Warns

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified four critical vulnerabilities that are currently being exploited in the wild. These vulnerabilities have been added to its Known Exploited Vulnerabilities (KEV) catalog, highlighting the urgency for organizations to address them.

Critical macOS, SharePoint, vCenter, and Microsoft IKE Vulnerabilities

The vulnerabilities include:

  • CVE-2026-65400 (CVSS score: 9.8) – An improper authentication vulnerability in Apple macOS that allows attackers to authenticate to Screen Sharing without valid credentials.
  • CVE-2026-55040 (CVSS score: 9.1) – A weak authentication vulnerability in Microsoft SharePoint that enables unauthorized attackers to bypass security features over a network.
  • CVE-2026-59310 (CVSS score: 9.8) – A path traversal vulnerability in Broadcom VMware vCenter that allows threat actors with network access to execute arbitrary code.
  • CVE-2026-33824 (CVSS score: 9.8) – A double free vulnerability in Microsoft Internet Key Exchange (IKE) Service Extensions that could permit unauthorized code execution over a network.

Despite being patched by the respective vendors, these vulnerabilities are under active exploitation. Reports indicate that the Apple macOS flaw has been used to deploy a Monero cryptocurrency miner, while the SharePoint vulnerability has been targeted following the release of proof-of-concept code.

The VMware vCenter vulnerability is believed to have been exploited by a suspected China-nexus advanced persistent threat (APT) actor, leading to the deployment of a backdoor and reverse_ssh binaries for persistent access. This campaign has reportedly resulted in the deployment of Babuk-derived ransomware.

Overall, these activities have compromised 361 unique victim IP addresses across 47 countries, with the highest concentrations of infections in Germany, the U.S., Turkey, Iran, and France. Federal Civilian Executive Branch (FCEB) agencies have until August 21, 2026, to update their systems in accordance with BOD 26-04 patching guidelines for optimal protection.

For further details, refer to the advisory published by The Hacker News.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

FQ-42 Vengeance unmanned fighter aircraft displayed at AFA 2026

The FQ-42 Vengeance unmanned fighter aircraft, developed by General Atomics, was prominently displayed at the Air, Space and Cyber conference on September 14, 2026....

Meta’s AI Assistant Muse Exposed by Zero-Day Vulnerability, Prompting Amazon to Block Access

Meta's new AI assistant, Muse, has come under scrutiny following the discovery of a zero-day vulnerability that allows locally run applications and terminal commands...

EU fines Google €403 million for location data breach, mandates compliance within six months.

DUBLIN: Ireland's Data Protection Commission (DPC), representing the European Union, has imposed a hefty fine of €403 million ($462 million) on Google for violating...