Vulnerabilities & Exploits

CISA’s KEV Update Spans Four Live Exploits

CISA added four flaws in Microsoft Windows IKE Service Extension, Microsoft SharePoint, Broadcom VMware vCenter, and Apple macOS Screen Sharing to its Known Exploited Vulnerabilities catalog on Tuesday, confirming they are being used in the wild. The move puts federal civilian agencies on a two-day remediation clock, with the same exploitation window open to private operators running the same systems.

The four bugs are being abused in different ways: SharePoint is being hit after proof-of-concept code surfaced, vCenter has been used to drop reverse-SSH tooling and, in some cases, a backdoor, macOS Screen Sharing has been used to gain root and install a Monero miner, and the Windows IKE issue has been seen in attacks by a Chinese-speaking threat actor. In plain terms, these are not just patched CVEs; they are live entry points with different outcomes, from commodity mining to persistent access.

For defenders, the key shift is that exploitation is no longer centered on one VMware path. If identity, collaboration, virtualization, or endpoint-sharing services sit on your network edge, the exposure can now arrive through several management planes at once, and the end state may be persistence rather than a one-time break-in.

8 sources · Aug 19

CVE-2026-33824

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. EPSS 2% (75th percentile).

CISA federal remediation date Aug 21

CVE-2026-55040

NVD KEV

Known exploited · CISA KEV

CVSS 9.1 CRITICAL: weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over… Microsoft patch: 5002891.

Patch available KB5002891 Download →

CISA federal remediation date Aug 21

CVE-2026-65400

NVD KEV

Known exploited · CISA KEV

CVSS 7.1 HIGH: an authentication issue was addressed with improved state management.

CISA federal remediation date Aug 21

CVE-2026-59310

NVD KEV

Known exploited · CISA KEV

CISA federal remediation date Aug 21

Timeline

Sources

Vendor digest: Microsoft

Vendor digest: Cisco

Vendor digest: VMware

Part of the PlainSec briefing for 2026-08-13

Every edition of this story: CISA’s KEV Update Spans Four Live Exploits

More from today