CISA KEV Catalog Update: Four Actively Exploited Vulnerabilities (Microsoft IKE, SharePoint, VMware vCenter, macOS)
First seen Aug 19, 2026 · Updated Aug 19, 2026
CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog based on confirmed active exploitation: a Microsoft IKE double-free flaw, a SharePoint authentication bypass, a VMware vCenter path traversal bug, and a macOS improper authentication issue. Under BOD 26-04, FCEB agencies must remediate these on an expedited timeline, and CISA urges all organizations to prioritize patching given evidence of in-the-wild exploitation.
Technical Analysis
CVE-2026-33824 is a double-free vulnerability in Microsoft's IKE Service Extensions that can lead to remote code execution on affected Windows hosts. CVE-2026-55040 is a weak authentication vulnerability in Microsoft SharePoint that could allow attackers to bypass authentication controls and gain unauthorized access to SharePoint content and services. CVE-2026-59310 is a path traversal vulnerability in Broadcom VMware vCenter Server that may allow attackers to access files outside intended directories, potentially exposing sensitive configuration or credential data. CVE-2026-65400 is an improper authentication vulnerability in Apple macOS that could permit unauthorized access to protected system resources. Organizations running AI agents, LLM tool-use pipelines, or RAG systems on SharePoint (as a data source), VMware vCenter-managed infrastructure (as agent hosting environments), or macOS endpoints should treat these as high-priority since exploitation could lead to credential theft, lateral movement into agent orchestration hosts, or exposure of API keys and secrets used by agentic workflows.
Affected Systems
Microsoft Windows systems with IKE Service Extensions enabled; Microsoft SharePoint Server (on-premises deployments); Broadcom VMware vCenter Server; Apple macOS (affected versions per Apple advisory)
Indicators of Compromise
- No specific IOCs (hashes, IPs, domains) provided in source disclosure; refer to CISA KEV Catalog and vendor advisories for updated indicators as they become available.
Remediation Steps
- 1
Apply vendor patches immediately
Update Microsoft Windows (IKE Service Extensions), SharePoint Server, VMware vCenter, and Apple macOS to the versions specified in vendor security advisories that remediate these CVEs.
- 2
Follow BOD 26-04 remediation timelines
FCEB agencies must remediate KEV-listed vulnerabilities within mandated timeframes; non-federal organizations should adopt the same prioritization for internet-facing or high-value assets.
- 3
Check for prior compromise
Per BOD 26-04 guidance, assess whether systems were compromised before patches were applied, especially internet-exposed vCenter and SharePoint instances.
- 4
Restrict exposure of vCenter and SharePoint
Limit network access to VMware vCenter and SharePoint management interfaces to trusted networks and enforce MFA where authentication weaknesses are present.
- 5
Audit AI agent infrastructure dependencies
Identify any AI agent, RAG, or LLM tool-use deployments that rely on SharePoint as a data source or run on VMware vCenter-managed hosts, and prioritize patching/monitoring of those environments to prevent credential or API key exposure.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.