Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
Reported exploitedmacOSSharePointOur summary
CISA has updated its Known Exploited Vulnerabilities catalog to include four high-severity flaws currently being targeted by threat actors. These vulnerabilities affect Apple macOS (CVE-2026-65400), Microsoft SharePoint (CVE-2026-55040), VMware vCenter (CVE-2026-59310), and Microsoft IKE (CVE-2026-33824).
Active attacks range from cryptocurrency mining via the macOS flaw to ransomware deployment through the vCenter path traversal bug, with victims reported across 47 countries. Federal agencies are required to apply the vendor-provided patches by August 21, 2026, to mitigate these risks.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.