THREAT SUMMARY
Category: Active Exploitation / Known Exploited Vulnerabilities / Enterprise Vulnerability Management
Affected Product(s): Microsoft Internet Key Exchange (IKE) Service Extensions, Microsoft SharePoint, Broadcom VMware vCenter, Apple macOS
CVE(s): CVE-2026-33824, CVE-2026-55040, CVE-2026-59310, CVE-2026-65400
Primary Risks: Memory Corruption, Authentication Failure, Unauthorized Access, Path Traversal, Sensitive File Exposure, Service Disruption, System Compromise, Infrastructure Control, Credential Exposure, Lateral Movement
Threat Status: Confirmed Active Exploitation
Affected Environment(s): Federal Agencies, Enterprise Networks, Microsoft Infrastructure, SharePoint Deployments, VMware Virtualization Environments, vCenter Management Systems, Apple macOS Endpoints, Publicly Exposed Services, Hybrid Networks
Attack Vector(s): Vulnerability-Specific Exploitation — Exact Techniques and Prerequisites Not Disclosed by CISA
CISA Action: Added Four Actively Exploited Vulnerabilities to the Known Exploited Vulnerabilities Catalog
Required Response: Identify Affected Assets, Review Vendor Mitigations, Prioritize Qualifying Publicly Exposed Systems, Apply Security Updates and Determine Whether Compromise Occurred Before Remediation
The Cybersecurity and Infrastructure Security Agency added four vulnerabilities affecting Microsoft, Broadcom VMware and Apple products to its Known Exploited Vulnerabilities Catalog on August 18, 2026.
CISA added the vulnerabilities after determining that evidence of active exploitation exists. Their inclusion in the catalog confirms that malicious actors have used the weaknesses under real-world conditions.
The additions affect Microsoft Internet Key Exchange (IKE) Service Extensions, Microsoft SharePoint, Broadcom VMware vCenter and Apple macOS. These technologies occupy different positions within enterprise environments, ranging from network communications and collaboration platforms to virtualization management infrastructure and individual endpoints.
The four vulnerabilities are:
- CVE-2026-33824 — Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
- CVE-2026-55040 — Microsoft SharePoint Weak Authentication Vulnerability
- CVE-2026-59310 — Broadcom VMware vCenter Path Traversal Vulnerability
- CVE-2026-65400 — Apple macOS Improper Authentication Vulnerability
CISA did not identify the threat actors exploiting the vulnerabilities, the organizations targeted, the scale of exploitation or whether the activity is connected to a coordinated intrusion campaign.
The alert also did not provide affected software versions, technical exploitation procedures, indicators of compromise or individual remediation deadlines. Organizations must consult the applicable KEV entries and official vendor guidance to determine exposure and required corrective action.
The presence of four distinct products in a single KEV update requires coordination across multiple operational teams. Windows administrators, SharePoint administrators, virtualization teams, Apple endpoint managers, incident responders and vulnerability-management personnel may each control different parts of the remediation process.
Vulnerability Details
CVE-2026-33824 affects Microsoft Internet Key Exchange (IKE) Service Extensions and is classified as a double-free vulnerability.
A double-free weakness occurs when software attempts to release the same memory location more than once. This condition can cause memory corruption, application failure or other unintended behavior. The precise security impact, exploitation requirements and level of access obtained through CVE-2026-33824 were not described in the CISA alert.
Systems using the affected Microsoft service must be identified and checked against Microsoft’s official product guidance. Administrators should determine whether the service is enabled, externally reachable or exposed through network configurations that could increase exploitation risk.
CVE-2026-55040 affects Microsoft SharePoint and is classified as a weak authentication vulnerability.
Weak authentication can allow a malicious actor to defeat, weaken or misuse controls intended to verify identity and restrict access. A successful attack against an enterprise collaboration platform could expose documents, internal information, user accounts or administrative functions, depending on the affected configuration and the access produced by exploitation.
CISA did not disclose whether exploitation requires authentication, user interaction, a specific SharePoint configuration or access to an Internet-facing deployment. Organizations should not assume that an internally hosted system is unaffected without checking the vulnerable versions and network paths identified by Microsoft.
CVE-2026-59310 affects Broadcom VMware vCenter and is classified as a path-traversal vulnerability.
Path traversal weaknesses can allow an attacker to reach files or directories outside the location an application was designed to access. The possible impact can include exposure or manipulation of configuration files, application data, credentials or other sensitive resources, depending on the permissions available to the affected service.
VMware vCenter is a central management component for virtualized infrastructure. Unauthorized access to the management plane can create broader operational risk than compromise of a single virtual machine because vCenter may control multiple hosts, workloads, administrative accounts and infrastructure functions.
CISA did not identify the files accessible through CVE-2026-59310, the privileges required for exploitation or whether the vulnerability can directly provide control of the vCenter environment.
CVE-2026-65400 affects Apple macOS and is classified as an improper authentication vulnerability.
Improper authentication occurs when a system fails to validate identity, authorization or authentication state correctly. Depending on the affected component, exploitation could allow an unauthorized actor to reach protected functions or perform actions that should require valid authorization.
The CISA alert did not identify the affected macOS versions, required access level, need for user interaction or privileges obtainable through exploitation. Organizations managing Apple endpoints must compare their device inventories against Apple’s official security guidance and confirm that applicable updates have been installed successfully.
None of the four vulnerability titles alone establishes the complete impact of exploitation. Product version, network exposure, authentication requirements, existing privileges and system configuration can materially affect operational risk.
Operational Impact
- Emergency identification of affected Microsoft, VMware and Apple assets
- Accelerated review of vendor security updates and mitigations
- Additional attention to publicly exposed SharePoint deployments
- Review of Internet Key Exchange service exposure
- Prioritized assessment of VMware vCenter management systems
- Validation of security-update deployment across macOS endpoints
- Possible maintenance windows for critical infrastructure components
- Potential interruption of collaboration or virtualization services during remediation
- Expanded monitoring for suspicious authentication activity
- Review of unauthorized file and directory access
- Examination of administrative and service-account activity
- Increased demand for endpoint and server log preservation
- Compromise assessments for vulnerable systems patched after exposure
- Coordination between vulnerability-management and incident-response teams
- Review of network segmentation surrounding management infrastructure
- Validation of backup integrity before major remediation
- Reassessment of externally reachable administrative interfaces
- Documentation of systems that cannot be patched immediately
- Temporary isolation of assets lacking an available correction
- Verification that updates remain installed after system restarts or configuration changes
Organizations should treat the VMware vCenter and SharePoint entries as infrastructure-level concerns because those products may provide access to sensitive data, privileged administration or multiple connected systems.
The Microsoft Internet Key Exchange vulnerability requires attention from teams responsible for network communications and remote-access infrastructure. The macOS entry requires coordinated endpoint review across managed laptops, desktops and other affected Apple systems.
Applying a patch addresses the known software weakness but does not determine whether exploitation occurred before remediation. Vulnerable systems with meaningful exposure may require log review, credential assessment, forensic examination or restoration from a known secure state.
Federal Response
Binding Operational Directive 26-04, Prioritizing Security Updates Based on Risk, establishes vulnerability-management requirements for Federal Civilian Executive Branch agencies.
The directive reinforces the Known Exploited Vulnerabilities Catalog as a central source for identifying weaknesses associated with confirmed malicious exploitation.
Under BOD 26-04, federal agencies must prioritize rapid remediation of high-risk KEV vulnerabilities affecting publicly exposed assets when successful exploitation would grant total control of the asset. The directive permits agencies to defer lower-risk vulnerabilities so that limited security resources remain focused on exposures carrying the most serious operational consequences.
The directive also establishes expectations for determining whether threat actors compromised an affected system before the security update was installed. This requirement recognizes that remediation alone cannot remove an attacker who established persistence, obtained credentials or accessed connected systems before patching.
Not every KEV entry automatically establishes that every deployment is publicly exposed or that exploitation would provide total control. Agencies must examine the affected product, asset configuration, network accessibility and post-exploitation impact when determining the priority required under BOD 26-04.
The directive applies to Federal Civilian Executive Branch agencies. CISA encourages state and local governments, critical-infrastructure operators, private companies and other organizations to use the KEV Catalog as part of risk-based vulnerability management.
KEV
CISA added the following vulnerabilities to the Known Exploited Vulnerabilities Catalog:
- CVE-2026-33824 — Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
- CVE-2026-55040 — Microsoft SharePoint Weak Authentication Vulnerability
- CVE-2026-59310 — Broadcom VMware vCenter Path Traversal Vulnerability
- CVE-2026-65400 — Apple macOS Improper Authentication Vulnerability
A KEV listing means CISA has evidence that malicious actors have exploited the vulnerability. It does not identify the threat actor, affected victim, complete exploitation method or number of successful compromises.
Potential additions to the catalog must possess a CVE identifier, evidence of active exploitation and clear mitigation guidance. CISA continues reviewing reported vulnerabilities and accepts nominations for weaknesses that may satisfy those requirements.
The August 18 alert did not provide the individual KEV remediation deadlines for the four vulnerabilities. Federal agencies and other organizations must review the complete catalog entries and official vendor instructions for the dates, affected versions and remediation actions assigned to each CVE.
Defensive Guidance
- Inventory Microsoft, SharePoint, VMware and Apple systems across the organization.
- Identify the owners responsible for each affected platform.
- Review official vendor advisories for affected versions and configurations.
- Compare asset inventories against each applicable CVE.
- Determine which affected services are publicly accessible.
- Identify administrative interfaces exposed directly to the Internet.
- Prioritize assets containing sensitive information or privileged access.
- Apply available security updates within the required remediation period.
- Follow vendor-approved mitigations when immediate patching is not possible.
- Restrict external access to affected services until remediation is complete.
- Place management interfaces behind controlled administrative access.
- Review network segmentation protecting VMware vCenter.
- Examine SharePoint authentication and administrative activity.
- Review logs for unexpected file access associated with vCenter.
- Monitor affected Microsoft services for crashes or abnormal behavior.
- Confirm macOS security updates through centralized endpoint management.
- Preserve relevant logs before making changes to exposed systems.
- Determine whether exploitation occurred before remediation.
- Review newly created accounts and unexpected privilege changes.
- Examine service accounts for unauthorized use.
- Rotate exposed credentials when compromise cannot be ruled out.
- Check connected systems for signs of lateral movement.
- Validate that backups are complete and protected from unauthorized alteration.
- Test updates before broad deployment when operational conditions permit.
- Confirm that patches remain installed following system restarts.
- Document systems granted temporary remediation exceptions.
- Assign compensating controls to systems that cannot be updated immediately.
- Remove unsupported or unnecessary exposed services.
- Continue monitoring after remediation for signs of persistence.
- Report qualifying federal incidents through established CISA channels.
Organizations should not rely solely on vulnerability-scanner results. Scanners can identify affected versions, but they may not establish whether a vulnerable feature is enabled, whether exploitation succeeded or whether an attacker remains inside the environment.
Asset owners should document the vulnerable product, system location, exposure level, remediation status, compromise-assessment result and person responsible for final verification.
30-Day Outlook
- Continued exploitation attempts against systems that remain unpatched
- Expanded scanning for exposed SharePoint installations
- Greater attention to VMware vCenter management interfaces
- Accelerated deployment of Microsoft and Apple security updates
- Increased review of Internet-facing federal assets under BOD 26-04
- Additional compromise assessments on systems patched after exposure
- Broader examination of authentication logs and administrative access
- Increased isolation of unsupported or unpatchable systems
- Additional KEV nominations tied to confirmed exploitation
- Greater coordination between endpoint, server and virtualization teams
- Expanded threat hunting around privileged management infrastructure
- Continued prioritization of vulnerabilities capable of producing complete asset control
- More use of network restrictions when immediate remediation is unavailable
- Additional scrutiny of vendor guidance and affected-version information
- Continued separation of confirmed exploitation from unverified exposure
TRJ Verdict
The addition of four vulnerabilities affecting Microsoft, VMware and Apple products confirms that malicious actors are exploiting weaknesses across several layers of modern enterprise infrastructure.
These entries cannot be treated as routine vulnerability disclosures. KEV inclusion establishes active exploitation and requires organizations to move beyond severity scores, theoretical impact and conventional patch schedules.
The most serious exposure may exist where the affected product controls authentication, collaboration data, network communications or virtualized infrastructure. Compromise of a management platform can extend risk across many connected workloads, accounts and services.
BOD 26-04 gives federal agencies a risk-based framework for deciding which KEV vulnerabilities require the fastest response. Public exposure and the level of control available after exploitation must guide prioritization, but lower visibility cannot be treated as proof of safety.
Organizations must identify affected assets, apply official remediation, restrict exposure and determine whether compromise occurred before the correction was installed.
Patching closes the vulnerability. Compromise assessment determines whether the attacker arrived first.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



