HomeSecurityCISA: Immediately fix 4 critical vulnerabilities Microsoft, VMware, Apple

CISA: Immediately fix 4 critical vulnerabilities Microsoft, VMware, Apple

The Cybersecurity and Infrastructure Security Agency ( CISA ) has issued an urgent warning, urging organizations and federal agencies to immediately patch four critical vulnerabilities being exploited by cybercriminals. The vulnerabilities affect products from Microsoft , VMware , and Apple , and have already been used by malicious actors to attack corporate infrastructure worldwide. CISA added all four to the Known Exploited Vulnerabilities (KEV) list, setting a deadline of August 21, 2026 , for patching .

CISA warns of critical vulnerabilities in Microsoft, VMware, Apple, KEV

This move is part of a broader wave of additions to the KEV list in August 2026, with a focus on vulnerabilities affecting critical enterprise infrastructure. CISA ’s KEV list now has 1,662 vulnerabilities in total, with Microsoft and Apple leading the way in terms of the number of vulnerabilities reported. The continued growth of the list reflects the acceleration of cyberattacks and the increasingly shorter time lag between the publication of a vulnerability and its active exploitation by threat actors.

According to SecurityWeek , CISA 's warning comes at a time when cyberattacks on corporate systems, collaboration platforms, and operating systems are accelerating dramatically. The speed with which attackers have exploited these vulnerabilities — in some cases within days of patches being released — shows that delaying system updates is now a luxury no organization can afford.

See also: CVE-2026-59310: Chinese hackers exploit VMware vCenter vulnerability

CISA KEV: The four vulnerabilities that require immediate action

The first vulnerability, CVE-2026-33824 with a CVSS score of 9.8, concerns a critical double-free error in the Windows Internet Key Exchange (IKE) Service Extension. The flaw could allow remote, unauthenticated attackers to execute arbitrary code via specially crafted network packets. Microsoft released a fix in April, but Palo Alto Networks discovered an active exploit in late July by a Chinese threat actor running an automated hacking campaign using artificial intelligence, combined with manual exploitation. Double-free errors are particularly dangerous because they can lead to memory corruption and, under the right circumstances, to complete remote code execution.

The second Microsoft, CVE-2026-55040 with a CVSS score of 9.1, concerns a weak authentication mechanism in SharePoint. The vulnerability was fixed in the Patch Tuesday July 2026, but its exploitation began shortly after the publication of a proof-of-concept (PoC) exploit. SharePoint has long been a target for attacks due to its widespread use in corporate environments; bypassing authentication can give attackers access to confidential documents, user accounts, and administrative functions, opening the way for lateral movement within the corporate network.

The third vulnerability, CVE-2026-59310 with a CVSS score of 9.8, concerns a critical path traversal in Broadcom VMware vCenter. Broadcom released a fix on July 29, but by August 3, attackers had already begun exploiting it for code execution by installing an open source SSH reverse shell framework. vCenter is a particularly attractive target because its compromise provides administrative control over entire virtual infrastructures, allowing for credential theft, lateral movement, and bulk access to virtual machines.

The fourth vulnerability, CVE-2026-65400 with a CVSS score of 7.5 , concerns an authentication flaw in Apple ’s macOS Screen Sharing feature . Apple released a patch on August 6 , warning that the vulnerability allows attackers to bypass authentication and log in to vulnerable devices without valid credentials. Active exploitation was observed less than a week later, with malicious actors gaining root access and installing a Monero miner on victims. The Dutch National Cybersecurity Center (NCSC) confirmed the active exploitation immediately after the patch was released, highlighting the extremely short time it now takes to exploit a vulnerability.

See also: Microsoft Patch Tuesday August 2026: 421 CVEs and active zero-day in Windows

CISA: Immediately fix 4 critical vulnerabilities Microsoft, VMware, Apple

The pattern observed in all four cases is alarming: attackers are closely monitoring patch announcements and PoC exploit publications and moving with extraordinary speed to exploit them before organizations have time to update their systems. This phenomenon, known as patch gap exploitation , is one of the main reasons why CISA imposes strict deadlines through Binding Operational Directive (BOD) 26-04 . This directive obliges federal agencies to patch KEV vulnerabilities within specific deadlines, while also providing a priority guide for the private sector.

Practical recommendations for immediate protection

CISA and cybersecurity experts recommend a series of immediate actions to address the four vulnerabilities. The priority is to immediately apply the available patches for CVE-2026-33824 , CVE-2026-55040 , CVE-2026-59310 , and CVE-2026-65400 , with a particular focus on systems exposed to the Internet. SharePoint and VMware vCenter systems , which are accessible from the Internet, should be treated as urgent points of exposure and verified to be fully updated.

In addition, it is recommended to restrict network access to macOS Screen Sharing and any remote management services to trusted management networks only. Security teams should also look for signs of exploitation, including unusual authentication events, suspicious administrator logins, and unexpected changes to virtualization or SharePoint configurations. In cases where immediate patching is not feasible, the use of compensating controls, network segmentation , or temporary disabling of affected services should be evaluated.

See also: CISA: VMware vCenter vulnerability in KEV Catalog

Microsoft Patch Tuesday August 2026 updates rollout

Overall, CISA’s warning is a reminder that vulnerability management can no longer be done on a lax schedule. In a world where attackers exploit new vulnerabilities within hours or days of their publication, organizations that lack automated notification processes and clear prioritization policies are at serious risk. CISA’s KEV list is the most reliable prioritization tool for any organization — private or public — that wants to focus its resources on the most dangerous and actively exploited threats.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS