The US cybersecurity agency CISA has added four critical vulnerabilities to its catalog of actively exploited flaws. They affect macOS, Microsoft SharePoint, VMware vCenter and the Windows IKE service – all are already under attack. The patches should be applied urgently.
The four flaws at a glance
- macOS Screen Sharing (CVE-2026-65400, CVSS 9.8): attackers on the network authenticate without valid credentials – used to deliver Monero crypto miners.
- Microsoft SharePoint (CVE-2026-55040, CVSS 9.1): a security-feature bypass; exploited after a proof-of-concept was published.
- VMware vCenter (CVE-2026-59310, CVSS 9.8): a path-traversal flaw enables code execution. A suspected China-nexus group deployed backdoors – 361 victim IPs across 47 countries, followed by Babuk-derived ransomware.
- Windows IKE service (CVE-2026-33824, CVSS 9.8): a double-free flaw allows code execution over the network; exploited by Chinese-speaking threat actors.
What to do now
CISA gave US federal agencies until 21 August to update their systems. All other operators too – from enterprises to homelabs – should apply the available security updates without delay.
Sources: The Hacker News, CISA.



















