The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four actively exploited vulnerabilities in Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft Internet Key Exchange (IKE) Service Extensions to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of in-the-wild attacks and setting an accelerated remediation deadline for federal agencies[2][3][7][10].
The newly listed flaws are tracked as CVE-2026-65400 in Apple macOS, a critical improper authentication bug that allows an attacker on the local network to authenticate to Screen Sharing without valid credentials and has been abused to deploy a Monero cryptocurrency miner[1][3]; CVE-2026-55040, a weak authentication vulnerability in Microsoft SharePoint that enables an unauthorized attacker to bypass security features over the network[2][3]; CVE-2026-59310, a path traversal flaw in Broadcom VMware vCenter that lets an attacker with network access execute arbitrary code on the vCenter host[2][3][7]; and CVE-2026-33824, a double free vulnerability in Windows Internet Key Exchange (IKE) Service Extensions that can be exploited for remote code execution on systems with IKE enabled[2][3][7].
All four bugs carry high to critical severity scores, with CVE-2026-33824, CVE-2026-59310, and the macOS Screen Sharing issue CVE-2026-65400 rated with a CVSS score of 9.8 and the SharePoint authentication flaw CVE-2026-55040 assessed at 9.1, underscoring the ease of exploitation and potential for full system compromise[1][2][7]. Security researchers report that the macOS vulnerability has already been leveraged to drop a Monero miner on targeted hosts, while exploitation of the SharePoint flaw has been observed following the publication of public proof-of-concept code by unknown threat actors[1][5].
CISA’s decision to add these vulnerabilities to the KEV catalog means there is reliable evidence that they are being used by adversaries in real-world operations, a list that frequently overlaps with techniques leveraged in ransomware and espionage intrusions[2][6][10]. For Windows environments, the IKE double free bug is particularly dangerous because it can be triggered remotely and may provide a foothold on internet-facing systems, though hardening guidance notes that blocking UDP ports 500 and 4500 at network boundaries can significantly reduce exposure from external attackers[2][3].
Organizations running on-premises Microsoft SharePoint, macOS endpoints with Screen Sharing enabled, or Broadcom VMware vCenter instances accessible over the network face heightened risk, as successful exploitation of any of these flaws can enable attackers to bypass authentication, execute arbitrary code, steal data, or pivot deeper into the environment[2][3][11]. CISA stresses that exploitation of SharePoint and vCenter vulnerabilities often serves as an entry point for follow-on activities such as credential theft, lateral movement, and the deployment of web shells or malware on critical servers[2][11].
Under CISA’s binding operational guidance, U.S. federal civilian agencies are required to prioritize remediation of KEV-listed vulnerabilities and must apply vendor updates or mitigations for these four CVEs within a short, fixed window—reported as three days for this set of flaws—using the KEV catalog as a de facto patching roadmap[7][10]. Enterprises outside the federal space are urged to follow the same playbook: identify all systems running vulnerable macOS builds, on-premises SharePoint, VMware vCenter, or Windows IKE services; apply the latest security updates and hardening measures; restrict exposure of administrative and VPN services to the internet; and review logs for suspicious Screen Sharing access, anomalous IKE service crashes, or unusual activity on SharePoint and vCenter that could indicate successful exploitation[1][2][3][11].
References
- Critical macOS, SharePoint, vCenter, and Microsoft IKE …
- U.S. CISA adds Apple macOS, Microsoft SharePoint …
- CISA known exploited vulnerabilities – Security Briefs
- Microsoft Internet Key Exchange (IKE) Service (CVE-2026 …
- Known Exploited Vulnerabilities Catalog
- CVE-2026-59310 – Overview, Insights & Trends – cvemon
- CSV版のダウンロード
- CISA Urges SharePoint Hardening After New Exploitations
