Vulnerabilità · 40 giorni fa
Quattro CVE in KEV, l’esposizione si allarga su più piattaforme CISA ha aggiunto quattro CVE al catalogo KEV e ha confermato sfruttamento attivo su Microsoft Windows IKE Service Extension, Microsoft SharePoint, Broadcom VMware vCenter e Apple macOS Screen Sharing. Per le agenzie civili federali si è aperta una finestra di rimedio di due giorni, ma il segnale va oltre il perimetro pubblico: il problema non è più un singolo prodotto, è una fase di attacco che si è allargata su più superfici di gestione.
I casi mostrano esiti diversi, non solo accesso iniziale. Su macOS gli attaccanti hanno usato la falla per distribuire un Monero miner; su SharePoint il PoC pubblicato ha accelerato l’abuso di autenticazione; su vCenter il codice remoto è servito a lasciare backdoor e reverse_ssh per persistenza; su IKE è stato osservato sfruttamento contro il servizio di rete. In pratica, una patch chiude il bug, ma non basta a descrivere ciò che è già stato fatto con quella finestra di accesso.
Per chi gestisce accesso remoto, collaboration, virtualizzazione o condivisione dell’endpoint, la lezione è che la pubblicazione di un exploit può tradursi quasi subito in sfruttamento reale sul piano di management esposto. Qui il punto non è una sola CVE critica: è la combinazione di monetizzazione rapida e accesso persistente su piattaforme diverse, con un raggio d’azione che supera il singolo vendor.
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 9.8 CRITICAL: double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. EPSS 2% (75º percentile).
Data di correzione federale CISA 21 ago
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 9.1 CRITICAL: weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over… Patch Microsoft: 5002891.
Patch disponibile KB5002891 Scarica →
Data di correzione federale CISA 21 ago
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 7.1 HIGH: an authentication issue was addressed with improved state management.
Data di correzione federale CISA 21 ago
NVD KEV
Sfruttamento noto · CISA KEV
Data di correzione federale CISA 21 ago
Cronologia Fonti 8 fonti che coprono questa storia
Cisco PSIRT 19 ago
Cisco Security Advisory: Cisco RoomOS Stack Overflow Vulnerability
A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker with physical access to the USB port on an affected device to execute arbitrary code with root privileges.
The Hacker News 19 ago
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
CISA adds four critical flaws to KEV after active exploitation, with FCEB agencies ordered to patch by August 21, 2026
SecurityWeek 19 ago
CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities
The flaws can be exploited for remote code execution, authentication bypass, and device takeover.
The Hacker News 17 ago
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
A weekly look at exploited flaws, exposed systems, supply-chain attacks, browser abuse, malware campaigns, and the security risks that mattered most.
Help Net Security 17 ago
Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer - Help Net Security
Hackers are exploiting a patched macOS Screen Sharing bug to gain root access and install Monero cryptominers.
SecurityWeek 17 ago
Recent macOS Screen Sharing Vulnerability Exploited in Attacks
Threat actors gained root access to the vulnerable systems and deployed a Monero miner.
The Hacker News 17 ago
Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
A suspected China-nexus actor exploits CVE-2026-59310, compromising an estimated 361 IPs in 47 countries and gaining root execution on vCenter.
The Hacker News 15 ago
Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner
Apple's CVE-2026-65400 Screen Sharing flaw is under active exploitation on internet-exposed Macs to install a Monero miner.
Ars Technica Security 14 ago
Vulnerability giving attackers full control of Macs is under active exploitation
Screen-sharing bug lets remote hackers log in without a password.
BleepingComputer 14 ago
Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
The Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged.
Dark Reading 13 ago
Global Threat Campaign Hits Critical VMware vCenter Flaw
Exploitation against CVE-2026–59310 began earlier this month, and patching the vulnerability may not be enough to fully mitigate the threat.
Infosecurity Magazine 13 ago
vCenter Flaw Exploited Just Five Days After Disclosure
Attackers exploited a critical-severity vCenter flaw five days after Broadcom disclosed it
Entità CVE-2026-33824 CVE-2026-55040 CVE-2026-59310 CVE-2026-65400 Riepilogo fornitore: Microsoft
Riepilogo fornitore: Cisco
Riepilogo fornitore: VMware
Part of the PlainSec briefing for 2026-08-18
Editions Storie correlate
Vulnerabilità · 40 giorni fa
Quattro CVE in KEV, l’esposizione si allarga su più piattaforme CISA ha aggiunto quattro CVE al catalogo KEV e ha confermato sfruttamento attivo su Microsoft Windows IKE Service Extension, Microsoft SharePoint, Broadcom VMware vCenter e Apple macOS Screen Sharing. Per le agenzie civili federali si è aperta una finestra di rimedio di due giorni, ma il segnale va oltre il perimetro pubblico: il problema non è più un singolo prodotto, è una fase di attacco che si è allargata su più superfici di gestione.
I casi mostrano esiti diversi, non solo accesso iniziale. Su macOS gli attaccanti hanno usato la falla per distribuire un Monero miner; su SharePoint il PoC pubblicato ha accelerato l’abuso di autenticazione; su vCenter il codice remoto è servito a lasciare backdoor e reverse_ssh per persistenza; su IKE è stato osservato sfruttamento contro il servizio di rete. In pratica, una patch chiude il bug, ma non basta a descrivere ciò che è già stato fatto con quella finestra di accesso.
Per chi gestisce accesso remoto, collaboration, virtualizzazione o condivisione dell’endpoint, la lezione è che la pubblicazione di un exploit può tradursi quasi subito in sfruttamento reale sul piano di management esposto. Qui il punto non è una sola CVE critica: è la combinazione di monetizzazione rapida e accesso persistente su piattaforme diverse, con un raggio d’azione che supera il singolo vendor.
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 9.8 CRITICAL: double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. EPSS 2% (75º percentile).
Data di correzione federale CISA 21 ago
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 9.1 CRITICAL: weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over… Patch Microsoft: 5002891.
Patch disponibile KB5002891 Scarica →
Data di correzione federale CISA 21 ago
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 7.1 HIGH: an authentication issue was addressed with improved state management.
Data di correzione federale CISA 21 ago
NVD KEV
Sfruttamento noto · CISA KEV
Data di correzione federale CISA 21 ago
Cronologia Fonti 8 fonti che coprono questa storia
Cisco PSIRT 19 ago
Cisco Security Advisory: Cisco RoomOS Stack Overflow Vulnerability
A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker with physical access to the USB port on an affected device to execute arbitrary code with root privileges.
The Hacker News 19 ago
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
CISA adds four critical flaws to KEV after active exploitation, with FCEB agencies ordered to patch by August 21, 2026
SecurityWeek 19 ago
CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities
The flaws can be exploited for remote code execution, authentication bypass, and device takeover.
The Hacker News 17 ago
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
A weekly look at exploited flaws, exposed systems, supply-chain attacks, browser abuse, malware campaigns, and the security risks that mattered most.
Help Net Security 17 ago
Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer - Help Net Security
Hackers are exploiting a patched macOS Screen Sharing bug to gain root access and install Monero cryptominers.
SecurityWeek 17 ago
Recent macOS Screen Sharing Vulnerability Exploited in Attacks
Threat actors gained root access to the vulnerable systems and deployed a Monero miner.
The Hacker News 17 ago
Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
A suspected China-nexus actor exploits CVE-2026-59310, compromising an estimated 361 IPs in 47 countries and gaining root execution on vCenter.
The Hacker News 15 ago
Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner
Apple's CVE-2026-65400 Screen Sharing flaw is under active exploitation on internet-exposed Macs to install a Monero miner.
Ars Technica Security 14 ago
Vulnerability giving attackers full control of Macs is under active exploitation
Screen-sharing bug lets remote hackers log in without a password.
BleepingComputer 14 ago
Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
The Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged.
Dark Reading 13 ago
Global Threat Campaign Hits Critical VMware vCenter Flaw
Exploitation against CVE-2026–59310 began earlier this month, and patching the vulnerability may not be enough to fully mitigate the threat.
Infosecurity Magazine 13 ago
vCenter Flaw Exploited Just Five Days After Disclosure
Attackers exploited a critical-severity vCenter flaw five days after Broadcom disclosed it
Entità CVE-2026-33824 CVE-2026-55040 CVE-2026-59310 CVE-2026-65400 Riepilogo fornitore: Microsoft
Riepilogo fornitore: Cisco
Riepilogo fornitore: VMware
Part of the PlainSec briefing for 2026-08-18
Editions Storie correlate