Vulnerabilities · 40 days ago
CISA’s KEV Update Spans Four Live Exploits CISA added four flaws in Microsoft Windows IKE Service Extension, Microsoft SharePoint, Broadcom VMware vCenter, and Apple macOS Screen Sharing to its Known Exploited Vulnerabilities catalog on Tuesday, confirming they are being used in the wild. The move puts federal civilian agencies on a two-day remediation clock, with the same exploitation window open to private operators running the same systems.
The four bugs are being abused in different ways: SharePoint is being hit after proof-of-concept code surfaced, vCenter has been used to drop reverse-SSH tooling and, in some cases, a backdoor, macOS Screen Sharing has been used to gain root and install a Monero miner, and the Windows IKE issue has been seen in attacks by a Chinese-speaking threat actor. In plain terms, these are not just patched CVEs; they are live entry points with different outcomes, from commodity mining to persistent access.
For defenders, the key shift is that exploitation is no longer centered on one VMware path. If identity, collaboration, virtualization, or endpoint-sharing services sit on your network edge, the exposure can now arrive through several management planes at once, and the end state may be persistence rather than a one-time break-in.
NVD KEV
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. EPSS 2% (75th percentile).
CISA federal remediation date Aug 21
NVD KEV
Known exploited · CISA KEV
CVSS 9.1 CRITICAL: weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over… Microsoft patch: 5002891.
Patch available KB5002891 Download →
CISA federal remediation date Aug 21
NVD KEV
Known exploited · CISA KEV
CVSS 7.1 HIGH: an authentication issue was addressed with improved state management.
CISA federal remediation date Aug 21
NVD KEV
Known exploited · CISA KEV
CISA federal remediation date Aug 21
Timeline Sources 8 sources covering this story
Cisco PSIRT Aug 19
Cisco Security Advisory: Cisco RoomOS Stack Overflow Vulnerability
A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker with physical access to the USB port on an affected device to execute arbitrary code with root privileges.
The Hacker News Aug 19
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
CISA adds four critical flaws to KEV after active exploitation, with FCEB agencies ordered to patch by August 21, 2026
SecurityWeek Aug 19
CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities
The flaws can be exploited for remote code execution, authentication bypass, and device takeover.
The Hacker News Aug 17
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
A weekly look at exploited flaws, exposed systems, supply-chain attacks, browser abuse, malware campaigns, and the security risks that mattered most.
Help Net Security Aug 17
Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer - Help Net Security
Hackers are exploiting a patched macOS Screen Sharing bug to gain root access and install Monero cryptominers.
SecurityWeek Aug 17
Recent macOS Screen Sharing Vulnerability Exploited in Attacks
Threat actors gained root access to the vulnerable systems and deployed a Monero miner.
The Hacker News Aug 17
Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
A suspected China-nexus actor exploits CVE-2026-59310, compromising an estimated 361 IPs in 47 countries and gaining root execution on vCenter.
The Hacker News Aug 15
Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner
Apple's CVE-2026-65400 Screen Sharing flaw is under active exploitation on internet-exposed Macs to install a Monero miner.
Ars Technica Security Aug 14
Vulnerability giving attackers full control of Macs is under active exploitation
Screen-sharing bug lets remote hackers log in without a password.
BleepingComputer Aug 14
Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
The Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged.
Dark Reading Aug 13
Global Threat Campaign Hits Critical VMware vCenter Flaw
Exploitation against CVE-2026–59310 began earlier this month, and patching the vulnerability may not be enough to fully mitigate the threat.
Infosecurity Magazine Aug 13
vCenter Flaw Exploited Just Five Days After Disclosure
Attackers exploited a critical-severity vCenter flaw five days after Broadcom disclosed it
Entities CVE-2026-33824 CVE-2026-55040 CVE-2026-59310 CVE-2026-65400 Vendor digest: Microsoft
Vendor digest: Cisco
Vendor digest: VMware
Part of the PlainSec briefing for 2026-08-18
Editions Related stories
Vulnerabilities · 40 days ago
CISA’s KEV Update Spans Four Live Exploits CISA added four flaws in Microsoft Windows IKE Service Extension, Microsoft SharePoint, Broadcom VMware vCenter, and Apple macOS Screen Sharing to its Known Exploited Vulnerabilities catalog on Tuesday, confirming they are being used in the wild. The move puts federal civilian agencies on a two-day remediation clock, with the same exploitation window open to private operators running the same systems.
The four bugs are being abused in different ways: SharePoint is being hit after proof-of-concept code surfaced, vCenter has been used to drop reverse-SSH tooling and, in some cases, a backdoor, macOS Screen Sharing has been used to gain root and install a Monero miner, and the Windows IKE issue has been seen in attacks by a Chinese-speaking threat actor. In plain terms, these are not just patched CVEs; they are live entry points with different outcomes, from commodity mining to persistent access.
For defenders, the key shift is that exploitation is no longer centered on one VMware path. If identity, collaboration, virtualization, or endpoint-sharing services sit on your network edge, the exposure can now arrive through several management planes at once, and the end state may be persistence rather than a one-time break-in.
NVD KEV
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. EPSS 2% (75th percentile).
CISA federal remediation date Aug 21
NVD KEV
Known exploited · CISA KEV
CVSS 9.1 CRITICAL: weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over… Microsoft patch: 5002891.
Patch available KB5002891 Download →
CISA federal remediation date Aug 21
NVD KEV
Known exploited · CISA KEV
CVSS 7.1 HIGH: an authentication issue was addressed with improved state management.
CISA federal remediation date Aug 21
NVD KEV
Known exploited · CISA KEV
CISA federal remediation date Aug 21
Timeline Sources 8 sources covering this story
Cisco PSIRT Aug 19
Cisco Security Advisory: Cisco RoomOS Stack Overflow Vulnerability
A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker with physical access to the USB port on an affected device to execute arbitrary code with root privileges.
The Hacker News Aug 19
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
CISA adds four critical flaws to KEV after active exploitation, with FCEB agencies ordered to patch by August 21, 2026
SecurityWeek Aug 19
CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities
The flaws can be exploited for remote code execution, authentication bypass, and device takeover.
The Hacker News Aug 17
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
A weekly look at exploited flaws, exposed systems, supply-chain attacks, browser abuse, malware campaigns, and the security risks that mattered most.
Help Net Security Aug 17
Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer - Help Net Security
Hackers are exploiting a patched macOS Screen Sharing bug to gain root access and install Monero cryptominers.
SecurityWeek Aug 17
Recent macOS Screen Sharing Vulnerability Exploited in Attacks
Threat actors gained root access to the vulnerable systems and deployed a Monero miner.
The Hacker News Aug 17
Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
A suspected China-nexus actor exploits CVE-2026-59310, compromising an estimated 361 IPs in 47 countries and gaining root execution on vCenter.
The Hacker News Aug 15
Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner
Apple's CVE-2026-65400 Screen Sharing flaw is under active exploitation on internet-exposed Macs to install a Monero miner.
Ars Technica Security Aug 14
Vulnerability giving attackers full control of Macs is under active exploitation
Screen-sharing bug lets remote hackers log in without a password.
BleepingComputer Aug 14
Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
The Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged.
Dark Reading Aug 13
Global Threat Campaign Hits Critical VMware vCenter Flaw
Exploitation against CVE-2026–59310 began earlier this month, and patching the vulnerability may not be enough to fully mitigate the threat.
Infosecurity Magazine Aug 13
vCenter Flaw Exploited Just Five Days After Disclosure
Attackers exploited a critical-severity vCenter flaw five days after Broadcom disclosed it
Entities CVE-2026-33824 CVE-2026-55040 CVE-2026-59310 CVE-2026-65400 Vendor digest: Microsoft
Vendor digest: Cisco
Vendor digest: VMware
Part of the PlainSec briefing for 2026-08-18
Editions Related stories