CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities
CISA urges immediate patching of four exploited vulnerabilities in Microsoft, VMware, and Apple products.
Summary
CISA has issued an urgent call to patch four critical vulnerabilities affecting Microsoft, VMware, and Apple products, which are already being exploited in the wild. These flaws enable remote code execution, authentication bypass, and device takeover, with nation-state actors reportedly involved in exploiting some of them to deploy malware and conduct autonomous hacking campaigns.
Full text
The US Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday called for the immediate patching of four vulnerabilities in Microsoft, VMware, and Apple products that have been exploited in the wild. CISA’s fresh warning refers to two Microsoft flaws, namely CVE-2026-33824 (CVSS score of 9.8), a double free issue in the Windows Internet Key Exchange (IKE) Service Extension, and CVE-2026-55040 (CVSS score of 9.1), a weak authentication flaw in SharePoint. Patched in April, the Windows IKE Extension defect allows remote, unauthenticated attackers to execute arbitrary code via specially crafted packets. At the end of July, Palo Alto Networks flagged the weakness as being exploited by a Chinese-speaking threat actor in an AI-enabled autonomous hacking campaign that also involved manual exploitation. Threat actors started targeting the SharePoint vulnerability, an authentication bypass fixed on Microsoft’s July 2026 Patch Tuesday, earlier this month, after a proof-of-concept (PoC) exploit was published. On Tuesday, CISA added both security defects to its Known Exploited Vulnerabilities (KEV) catalog, along with a recent VMware vCenter bug tracked as CVE-2026-59310 (CVSS score of 9.8), and a macOS Screen Sharing flaw tracked as CVE-2026-65400 (CVSS score of 7.5).Advertisement. Scroll to continue reading. The VMware weakness was patched on July 29, and threat actors started exploiting it for code execution on August 3 to drop an open source SSH reverse shell framework. Apple patched the macOS Screen Sharing issue on August 6, warning that it could allow attackers to bypass authentication and log into vulnerable devices without valid credentials. In-the-wild exploitation was observed less than a week later. Threat actors were seen abusing it to gain root access and deploy a Monero miner. CISA urges federal agencies to patch all four security defects by August 21, in line with BOD 26-04 recommendations. Related: Oracle’s August 2026 Update Includes 943 Security Patches Related: Chrome, Firefox Updates Patch Dozens of Vulnerabilities Related: AI-Driven Vulnerability Surge Breaks the Traditional Patching Model Related: 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Xpander Raises $7.5 Million for AI Management and Governance300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin FlawHeights Finance Data Breach Impacts at Least 1.2 Million IndividualsGitLab Patches Critical Code Injection VulnerabilityDozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates680,000 Impacted by French Tax Authority Data Breach40,000 Impacted by SafePal Data BreachRecent macOS Screen Sharing Vulnerability Exploited in Attacks Latest News US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of ThemCl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign943 Patches Rolled Out With Oracle’s August 2026 Security UpdateChrome, Firefox Updates Patch Dozens of VulnerabilitiesCareCloud Data Breach Impact Grows to 3.7 Million IndividualsWebinar Today: Rethinking Cyber Defense for AI-Speed AttacksCISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOWAI-Driven Vulnerability Surge Breaks the Traditional Patching Model Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveDali Rajic is joining OpenAI as Chief Revenue Officer.Erika Dean has been appointed Chief Information Security Officer at Tricentis.C1 has named Jeff St. Clair Chief Revenue Officer.More People On The MoveExpert Insights The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- cve — CVE-2026-33824
- cve — CVE-2026-55040
- cve — CVE-2026-59310
- cve — CVE-2026-65400