CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities

Cybersecurity Agency Sounds Alarm on Exploited Vulnerities in Microsoft, VMware, and Apple Products

A stark warning has been issued by the US Cybersecurity and Infrastructure Security Agency (CISA) regarding four critical vulnerabilities that have been exploited in the wild. The agency is urging all affected organizations to patch these weaknesses as quickly as possible, emphasizing the importance of doing so before they can be leveraged by malicious actors.

At the heart of this warning are two high-severity flaws in Microsoft products: CVE-2026-33824 and CVE-2026-55040. The former is a double free issue in the Windows Internet Key Exchange (IKE) Service Extension, which allows remote attackers to execute arbitrary code via specially crafted packets. This vulnerability has been known since April but was recently exploited by a Chinese-speaking threat actor in an AI-enabled hacking campaign. The latter is a weak authentication flaw in SharePoint that was patched on Microsoft’s July 2026 Patch Tuesday.

In addition to these two Microsoft flaws, CISA has also added two other vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-59310 in VMware vCenter and CVE-2026-65400 in macOS Screen Sharing. The former was patched on July 29 but saw in-the-wild exploitation just a week later, while the latter was patched by Apple on August 6 after being exploited to gain root access and deploy a Monero miner.

The CISA warning specifically targets federal agencies, which are urged to patch all four vulnerabilities by August 21. This is in line with BOD 26-04 recommendations, which emphasize the importance of prioritizing timely patching to prevent exploitation by malicious actors.

This warning serves as a stark reminder of the ongoing threat posed by exploited vulnerabilities. As we’ve seen, even patched flaws can still be leveraged by determined attackers, highlighting the need for organizations to stay vigilant and prioritize regular security updates.

In light of this warning, it’s essential that all affected organizations take immediate action to patch these vulnerabilities and prevent potential exploitation. This includes not only applying the latest security patches but also reviewing existing systems and networks for signs of compromise. By taking proactive steps to address these weaknesses, organizations can significantly reduce their exposure to cyber threats and ensure the ongoing integrity of their systems.

Practically speaking, this means that all organizations relying on Microsoft, VMware, or Apple products should treat these vulnerabilities as a high-priority issue. This includes not only IT teams but also leadership and management, who must work together to allocate necessary resources and prioritize patching efforts. By taking a proactive approach to addressing these vulnerabilities, we can minimize the risk of exploitation and protect against potential cyber threats.


Source: SecurityWeek — 2026-08-19