Skip to main content
Emerging Threats

CISA Warns of Active Exploitation of Critical Flaws in macOS, SharePoint, vCenter, and Microsoft IKE

Empty server room with rows of equipment racks and computer servers under fluorescent lighting.

361 unique victim IP addresses across 47 countries have been tied to active exploitation of four critical vulnerabilities recently added to CISA’s Known Exploited Vulnerabilities catalog.

What CISA added to the KEV and why it matters

On Tuesday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added four critical flaws to its Known Exploited Vulnerabilities (KEV) catalog, noting each is being exploited in the wild. The entries named in the bulletin are:

  • CVE-2026-65400 (CVSS score: 9.8) — an improper authentication vulnerability impacting Apple macOS that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
  • CVE-2026-55040 (CVSS score: 9.1) — a weak authentication vulnerability impacting Microsoft SharePoint that could allow an unauthorized attacker to bypass a security feature over a network.
  • CVE-2026-59310 (CVSS score: 9.8) — a path traversal vulnerability in Broadcom VMware vCenter that could allow a threat actor with network access to vCenter to execute arbitrary code.
  • CVE-2026-33824 (CVSS score: 9.8) — a double free vulnerability in Microsoft Internet Key Exchange (IKE) Service Extensions that could allow an unauthorized attacker to execute code over a network.

The advisory notes vendors have released patches for the flaws, but that publicly reported exploitation has continued despite those fixes.

Observed exploitation: malware, PoC-driven attacks, backdoors and ransomware

Public reporting ties each vulnerability to active, distinct abuse patterns. The Apple macOS vulnerability has been abused to deliver a Monero cryptocurrency miner. The Microsoft SharePoint flaw has been leveraged by unknown actors after the release of proof-of-concept (PoC) code. Activity exploiting Broadcom VMware vCenter is assessed to have been used by a suspected China‑nexus advanced persistent threat (APT) actor to deploy a backdoor and reverse_ssh binaries, giving the adversary persistent access to compromised instances; in at least one instance that campaign resulted in deployment of a Babuk‑derived ransomware.

Separately, Palo Alto Networks Unit 42 reported that CVE-2026-33824 has been observed in use by a different Chinese‑speaking threat actor. That actor is described as having simultaneously launched an AI‑enabled autonomous hacking campaign using DeepSeek while also conducting manual operations leveraging known vulnerabilities, including Microsoft Internet Key Exchange.

Geography and scale: where infections clustered

Across the tracked activity, 361 unique victim IP addresses in 47 countries were compromised. The largest concentrations of infected systems were in Germany (55), the U.S. (41), Turkey (38), Iran (26), and France (25). The use of backdoors, reverse_ssh tools and at least one Babuk‑derived ransomware deployment indicates both follow‑on access and destructive or monetizing outcomes in multiple cases.

What this means for FCEB agencies, technologists, and adversaries

  • Federal Civilian Executive Branch (FCEB) agencies — The bulletin gives FCEB agencies a firm operational deadline: they have until August 21, 2026, to update vulnerable systems to the latest version and to adhere to BOD 26‑04 patching guidelines for optimal protection. The presence of active exploitation across multiple, highly critical CVEs underpins the directive’s urgency.
  • Technologists and enterprise security teams — The record shows a mix of opportunistic and targeted activity: PoC release has enabled SharePoint exploitation, commodity payloads (a Monero miner) have been delivered via macOS, and more sophisticated operators have used vCenter compromises for persistent access and ransomware delivery. Teams are therefore facing simultaneous risks of mass abuse and targeted intrusion, all tied to publicly identified CVEs that vendors say are already patched.
  • Adversaries and APT operators — Public reporting links at least two distinct clusters of activity: a suspected China‑nexus APT using vCenter compromises to establish persistence and deploy ransomware, and a Chinese‑speaking threat actor combining an AI‑enabled DeepSeek autonomous campaign with manual exploitation of vulnerabilities including Microsoft IKE. Those patterns illustrate both automated and hands‑on‑keyboard approaches in parallel.

Immediate operational implications and the short list of next steps

The facts in the advisory are straightforward: four high‑severity flaws were added to CISA’s KEV because they are actively exploited; vendors have issued patches; and exploitation has already produced miners, backdoors, persistent remote access tooling, and at least one ransomware case. For defenders, the immediate priorities implied by those facts are timely patching, validation of endpoint and network detection for the specific behaviors described (Screen Sharing misuse, SharePoint bypass attempts, vCenter path traversal, IKE Service Extensions exploitation), and investigation of existing instances for indicators of backdoor, reverse_ssh binaries, or Babuk‑derived ransom notes.

For policymakers and operational owners inside the FCEB, the August 21, 2026 deadline to comply with BOD 26‑04 is the concrete next milestone named in the bulletin.

The record the agencies and private reporting paint is clear and narrow: publicly known, high‑severity flaws were exploited in multiple contexts, and the window to remediate those flaws is short. Whether defenders can close that window before new PoCs, autonomous campaigns or follow‑on ransomware operations expand the tally of compromised systems is the immediate question the facts leave on the table.

Original story