TL;DR
CISA added four vulnerabilities to its Known Exploited Vulnerabilities Catalog on August 18, 2026. Each entry rests on evidence of active exploitation. The flaws hit Microsoft, Broadcom, and Apple products. Federal agencies must patch by August 21, 2026.
- Product: Microsoft Windows 10 Version 1607, Microsoft SharePoint Enterprise Server 2016 +2
- Vulnerabilities: 4 flaws (CVE-2026-33824, CVE-2026-55040, CVE-2026-59310, CVE-2026-65400)
- Highest severity: 9.8 (Critical · CVSSv3)
- Worst impact: Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution
- Status: 4 exploited; patches available
- Action: Update to 10.0.14393.9060, 10.0.17763.8644, 10.0.19044.7184, 10.0.19045.7184 (+16) now
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-33824 | 9.8 | CWE-415 | 10.0.14393.9060, 10.0.17763.8644, 10.0.19044.7184 (+8) | Exploited |
| CVE-2026-59310 | 9.8 | CWE-22 | 9.1.0.0300, 9.0.2.0100, 8.0 U3k | Exploited |
| CVE-2026-65400 | 9.8 | CWE-287 | 14.8.9, 15.7.9, 26.6.1 | Exploited |
| CVE-2026-55040 | 9.1 | CWE-1390 | 16.0.5561.1001, 16.0.10417.20175, 16.0.19725.20434 | Exploited |
Why it matters
The CISA KEV Catalog lists flaws that attackers already abuse. All four new entries score 9.1 or higher. They affect widely deployed enterprise systems. As a result, the blast radius is large.
Three carry a critical 9.8 rating. These cover Windows IKE, VMware vCenter, and macOS. The fourth, a SharePoint flaw, scores 9.1.
How the attacks work
The mechanisms differ by product. CVE-2026-33824 abuses a double free in the Windows IKE service to run code over a network. CVE-2026-59310 exploits a path traversal bug in the vCenter Syslog server. CVE-2026-65400 lets a network attacker reach macOS Screen Sharing without valid credentials.
The SharePoint bug, CVE-2026-55040, chains four weak checks to forge a valid token. Rapid7 published a full analysis and a public proof-of-concept. Independent researchers also reported PoC use against honeypots soon after disclosure.
Affected versions
The flaws span Windows, on-premises SharePoint, VMware vCenter, and macOS. Apple fixed the macOS issue in Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1.
Patch and mitigation steps
Apply each vendor’s update right away. FCEB agencies face a August 21, 2026 deadline, per the CISA KEV Catalog alert. Private organizations should treat these as urgent too. Prioritize the internet-facing systems first.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.