VORANT. Threat Intelligence Sign in Get the full feed

CISA Adds Four Exploited Vulnerabilities to KEV

severe vulnerability government-nationaltechnology

CISA added four actively exploited vulnerabilities affecting Microsoft IKE, SharePoint, VMware vCenter, and macOS to its Known Exploited Vulnerabilities catalog.

CISA has expanded its Known Exploited Vulnerabilities (KEV) Catalog with four new entries, each confirmed to be under active exploitation in the wild. The affected products span Microsoft's Internet Key Exchange (IKE) Service Extensions (a double-free vulnerability), Microsoft SharePoint (weak authentication), Broadcom VMware vCenter (path traversal), and Apple macOS (improper authentication). These products are widely deployed across enterprise and federal environments, making them attractive targets for opportunistic and targeted attackers alike.

Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch agencies are required to remediate these vulnerabilities on a prioritized, risk-based schedule, particularly those enabling full asset compromise on internet-facing systems. The directive also mandates that agencies verify whether systems were compromised prior to patching. While the mandate applies only to federal agencies, CISA recommends all organizations using the affected Microsoft, VMware, and Apple products apply patches and review for indicators of prior compromise given confirmed in-the-wild exploitation.

No specific threat actors, malware families, or IOCs were disclosed in this advisory; it serves as a notification of catalog updates rather than an in-depth technical report. Organizations running SharePoint, vCenter, IKE-based VPN services, or macOS should treat these as high-priority patches given active exploitation status.

Mentioned in this report

Vulnerabilities CVE-2026-33824KEVCVE-2026-55040KEVCVE-2026-59310KEVCVE-2026-65400KEV

Source reporting: https://www.cisa.gov/news-events/alerts/2026/08/18/cisa-adds-four-known-exploited-vulnerabilities-catalog

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free