According to the latest update, cISA has added the vulnerabilities to its catalog of Known Exploited Vulnerabilities (KEV). Microsoft Windows and SharePoint, VMware vCenter, and Apple macOS are affected. The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about four security vulnerabilities that are being exploited by attackers in the wild.

The report highlights that the agency points out that such vulnerabilities are among the most commonly used attack vectors and pose a significant risk. Inclusion in the KEV catalog sends an important signal: CISA doesn’t simply list every known vulnerability out there, but only those for which there is concrete evidence of active exploitation by attackers.

According to the latest update, organizations and system administrators should also check whether affected systems are accessible via the internet and whether there are any indications that an attack has already taken place on vulnerable devices. For home users, this means that if a security patch is available for their device, it should be installed as soon as possible.

The report highlights that it’s caused by a “double-free” error, where a memory block can be freed multiple times under certain conditions. The first vulnerability is designated CVE-2026-33824 and affects the Internet Key Exchange (IKE) service extensions in Windows.

Industry observers note that an unauthenticated attacker can exploit it over the network and thereby execute their own code on an affected system. The vulnerability is classified as critical, with a CVSS score of 9.8 out of 10.

According to the latest update, its inclusion in the CISA KEV catalog now indicates that this risk is no longer merely theoretical—anyone who hasn’t yet installed the April Windows updates should do so ASAP. It affects various versions of Windows 10, Windows 11, and Windows Server. Microsoft already patched this vulnerability with its April security patch.

As part of the ongoing story, microsoft has rated the vulnerability as critical, with a CVSS score of 9.1. Microsoft SharePoint’s vulnerability CVE-2026-55040 allows unauthenticated attackers to bypass a security capability over the network.

Industry observers note that fixed builds are already available for the respective versions. Affected systems include SharePoint Enterprise Server 2016, SharePoint Server 2019, and the Subscription Edition.

Industry observers note that administrators should therefore not only address this specific vulnerability but also ensure, as a general rule, that their SharePoint installations are always up-to-date with the most recent patches. SharePoint has been the target of attacks on several occasions this year.

As part of the ongoing story, this puts additional pressure on admins of unpatched systems. According to available reports, a publicly accessible exploit for CVE-2026-55040 was already available before it was included in the CISA catalog.

According to the latest update, an attacker with network access to vCenter can exploit the vulnerability to access files outside intended directories and subsequently execute arbitrary code. VMware vCenter’s vulnerability CVE-2026-59310 lies within the syslog server and enables a path traversal attack.

In a fresh development, certain versions of VMware vCenter, VMware Cloud Foundation, and vSphere Foundation are affected. For vCenter, different patched versions apply depending on the major version. This vulnerability is classified as critical with a CVSS score of 9.8.

According to the latest update, attackers are said to have attempted to establish a persistent presence within affected VMware environments, and there have also been reports of ransomware attacks in isolated cases. Security experts have known about CVE-2026-59310 since the end of July, and reports of active attacks emerged as early as the beginning of August.

In a fresh development, a compromised vCenter server can have far-reaching consequences for the systems connected to it. This vulnerability is especially relevant for organizations because vCenter plays a central role in the management of virtualized IT environments.

In a fresh development, cVE-2026-65400 is found in macOS’s screen sharing capability. Under certain conditions, an attacker on the network can bypass authentication and log in to Screen Sharing without valid credentials. Apple has resolved the issue with improved status management. The fourth major vulnerability affects Apple systems.

Industry observers note that the original CVSS score was 7.1. Following reports of active exploitation, the vulnerability is now rated as significantly more critical in some databases. Apple patched the vulnerability on August 6th with macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9.

In a fresh development, according to reports, the vulnerability has been exploited to install malware on compromised Macs for mining the cryptocurrency Monero. This vulnerability is especially relevant for Macs where Screen Sharing is enabled and accessible from the network.

The report highlights that the key factor in each case is whether the affected capability or programs is in use and whether the system has already been revised. Although these four vulnerabilities primarily affect enterprise and server environments, CVE-2026-65400 is also relevant to ordinary Mac users.

In a fresh development, if a system has already been compromised, the attacker may have gained permanent access before the patch was installed. Note that when it comes to vulnerabilities included in CISA’s KEV catalog, simply installing a security patch is not always sufficient.

Industry observers note that it does mean, however, that the vulnerabilities in question are being actively exploited and should no longer be regarded as purely theoretical security risks. Also, inclusion in the KEV catalog doesn’t mean that every Windows PC, Mac, or server is automatically at risk.

In a fresh development, this article originally appeared on our sister publication PC-WELT and was translated and localized from German.

According to the latest update, egal, ob Smartphones, Gadgets oder die neuesten Trends aus der Welt von Apple und Android – sie ist in beiden Welten zu Hause. Neben Technik widmet sie sich gerne Lifestyle-Themen, kulinarischen Entdeckungen sowie Filmen und Serien. Mit ihrer Begeisterung für moderne Technologien liefert sie gerne praxisnahe Tipps und spannende Einblicke, die den Alltag bereichern. Viviane Osswald ist freie Redakteurin und Tech-Enthusiastin mit einer besonderen Leidenschaft für Mobile-Tech.