CISA Adds macOS, Microsoft, and VMware Flaws to Known Exploited Catalog
The agency flagged four vulnerabilities under active attack, triggering mandatory remediation for federal agencies.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on August 18, 2026. The agency took action after evidence emerged that threat actors are actively exploiting these flaws to compromise enterprise and government systems.
The affected software spans several major platforms, including Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft's Internet Key Exchange (IKE) service. Among the most severe is CVE-2026-65400, an authentication vulnerability in macOS Screen Sharing that allows unauthorized network attackers to gain access to a system. Additionally, CISA flagged CVE-2026-33824, a double-free vulnerability in Microsoft IKE Service Extensions that can be leveraged for remote code execution (RCE).
The Role of the KEV Catalog
The KEV catalog serves as the authoritative list of vulnerabilities that CISA has verified are being used by threat actors. For Federal Civilian Executive Branch (FCEB) agencies, the inclusion of a flaw in this catalog is not merely a warning; it triggers mandatory remediation timelines under Binding Operational Directive (BOD) 26-04. This directive ensures that critical gaps are closed quickly to prevent widespread exploitation across the federal government's digital infrastructure.
Industry Implications
These vulnerabilities are particularly dangerous because they target internet-facing services. Software like vCenter, SharePoint, and IKE often sit at the perimeter of a network, making them primary targets for attackers seeking initial access. By exploiting authentication bypasses or RCE vectors, attackers can establish a foothold and potentially move laterally through a network to achieve full system compromise.
The diversity of the affected software—ranging from desktop operating systems to virtualization and collaboration tools—indicates a broad attack surface. This variety suggests that attackers are targeting multiple entry points simultaneously, requiring immediate attention from IT administrators across all sectors to prevent a breach.
Next Steps for Organizations
CISA has urged all organizations to prioritize the patching of these specific flaws to mitigate the risk of breach. While the agency has confirmed the active exploitation of these four vulnerabilities, security teams should continue to monitor for further updates as more details on the specific attack chains emerge. Organizations are encouraged to audit their internet-exposed assets, particularly those running macOS Screen Sharing and Microsoft IKE, to ensure they are updated to the latest secure versions.