Published on August 19, 2026
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
Severity
Critical
Detail
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four critical vulnerabilities affecting Apple macOS, Microsoft SharePoint, VMware vCenter, and Microsoft IKE Service Extensions to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation.
The vulnerabilities are tracked as CVE-2026-65400, CVE-2026-55040, CVE-2026-59310, and CVE-2026-33824, with CVSS scores ranging from 9.1 to 9.8. Successful exploitation could allow attackers to bypass authentication, execute arbitrary code, gain persistent access, deploy malware, and potentially compromise affected environments.
CVE-2026-65400 affects Apple macOS and is an improper authentication vulnerability in the Screen Sharing service. An attacker on the network can potentially authenticate without valid credentials. The vulnerability has been exploited to deploy a Monero cryptocurrency miner on compromised systems.
CVE-2026-55040 affects Microsoft SharePoint and allows an unauthorized attacker to bypass a security feature over the network. The vulnerability has been actively exploited following the public availability of proof-of-concept code.
CVE-2026-59310 affects VMware vCenter and is a path traversal vulnerability that can allow attackers with network access to execute arbitrary code. Exploitation has been associated with the deployment of backdoors, reverse SSH tools, and ransomware.
CVE-2026-33824 affects Microsoft IKE Service Extensions and is a double-free vulnerability that can allow an unauthorized attacker to execute arbitrary code over the network. Security researchers have observed exploitation of the vulnerability by threat actors targeting vulnerable systems.
The exploitation of these vulnerabilities has reportedly affected 361 unique victim IP addresses across 47 countries, highlighting the active and widespread nature of the attacks.
| CVE ID | Summary | CVSS Score |
| CVE-2026-65400 | Improper authentication vulnerability in Apple macOS Screen Sharing that can allow network-based attackers to authenticate without valid credentials. | 9.8 (Critical) |
| CVE-2026-55040 | Authentication-related vulnerability in Microsoft SharePoint that can allow unauthorized attackers to bypass a security feature over the network. | 9.8 (Critical) |
| CVE-2026-59310 | Path traversal vulnerability in VMware vCenter that can allow attackers with network access to execute arbitrary code. | 9.1 (Critical) |
| CVE-2026-33824 | Double-free vulnerability in Microsoft IKE Service Extensions that can allow unauthorized attackers to execute arbitrary code over the network. | 9.1 (Critical) |
Affected Products
The vulnerabilities affect the following products:
- Apple macOS versions affected by CVE-2026-65400.
- Microsoft SharePoint versions affected by CVE-2026-55040.
- VMware vCenter versions affected by CVE-2026-59310.
- Microsoft IKE Service Extensions versions affected by CVE-2026-33824.
Recommendation
Organizations should implement the following measures to reduce the risk of exploitation:
- Apply the latest security updates for Apple macOS, Microsoft SharePoint, VMware vCenter, and Microsoft IKE Service Extensions.
- Prioritize internet-facing and network-accessible systems for immediate remediation.
- Restrict access to Screen Sharing, SharePoint, vCenter, and IKE services to trusted networks where possible.
- Monitor affected systems for suspicious authentication attempts, unexpected remote access, reverse SSH connections, and unusual processes.
- Investigate affected systems for indicators of cryptocurrency mining, backdoors, and ransomware activity.
- Prioritize these vulnerabilities for remediation due to their inclusion in CISA’s Known Exploited Vulnerabilities catalog.
Source
https://thehackernews.com/2026/08/critical-macos-sharepoint-vcenter-and.html
