Independent perspective. Actionable security.Know what matters · Reduce exposure

Vulnerability Assurance / Intelligence

Active Exploitation of Microsoft, VMware, and Apple Vulnerabilities

Source context: this article examines information published by the source on August 18, 2026. This site’s publication date is shown separately. Check the latest vendor guidance before acting.

What the vulnerability is

On August 18, 2026, CISA added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. The affected flaws are:

  • CVE-2026-33824: A double free vulnerability in Microsoft Internet Key Exchange (IKE) Service Extensions.
  • CVE-2026-55040: A weak authentication vulnerability in Microsoft SharePoint.
  • CVE-2026-59310: A path traversal vulnerability in Broadcom VMware vCenter.
  • CVE-2026-65400: An improper authentication vulnerability in Apple macOS.

Exposure and applicability

These vulnerabilities affect organizations utilizing the specific versions of Microsoft, Broadcom VMware, and Apple software listed above. The risk is particularly acute for assets that are publicly exposed. According to Binding Operational Directive (BOD) 26-04, certain vulnerabilities in this catalog may grant total control of an asset post-exploitation, making them high-priority targets for remediation.

Remediation priorities

Our analysis suggests a risk-based prioritization strategy based on the KEV status and asset exposure:

  1. Publicly Exposed Assets: Immediate priority should be given to patching or mitigating these four CVEs on any internet-facing systems, as these represent the most likely entry paths for attackers.
  2. Compromise Assessment: Before applying patches, defenders should check for indicators of compromise. This is critical because a patch prevents future exploitation but does not remove an attacker who has already gained access.
  3. Internal Asset Inventory: Organizations should cross-reference their asset inventory against these CVEs to identify internal systems that may be vulnerable, even if they are not currently public-facing.

How to validate remediation

To ensure exposure is reduced, vulnerability management teams should move beyond simple version checks:

  • Configuration Verification: Confirm that the specific security updates addressing these CVEs are active and that no configuration regressions have occurred during the update process.
  • Exposure Testing: For the path traversal (VMware) and authentication flaws (SharePoint, macOS), verify through authorized testing that the specific vulnerable paths or authentication bypasses are no longer accessible.
  • Post-Patch Audit: Validate that the remediation was applied across all instances of the affected software, not just a subset of servers.

Limits and open questions

Applying a patch does not guarantee that a system was not compromised prior to the update. There remains residual risk if an attacker established persistence before the vulnerability was remediated. Additionally, while CISA provides the KEV list for prioritization, the specific technical requirements for each fix depend on the vendor’s guidance for the respective software versions.

Source and editorial note

CISA Adds Four Known Exploited Vulnerabilities to Catalog · Source date: August 18, 2026 · Retrieved August 31, 2026.

Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.

Request a Vulnerability Assessment

Turn security intelligence into action.

Discuss your exposure, priorities, and the evidence needed to validate the outcome.

Request a security assessment ↗

Turn security intelligence into action.

Understand exposure, prioritize the response, and define evidence for the outcome.

Request a Security Assessment