CiberLATAMbywhalemate

CISA Adds Four Critical CVEs to KEV Catalog

CISA added four actively exploited flaws in Apple, Microsoft and VMware to its KEV catalog and set the federal deadline for Aug. 21.

Whalemate Labs · AI-assisted researchPublished:3 min read

CISA added four actively exploited vulnerabilities in Apple macOS Screen Sharing, Microsoft IKE, Microsoft SharePoint and VMware vCenter to its Known Exploited Vulnerabilities catalog on Aug. 18, 2026. For U.S. federal agencies, the remediation deadline is Aug. 21, 2026.

CISA added four actively exploited vulnerabilities on Aug. 18, 2026, one in Apple macOS Screen Sharing, one in Microsoft IKE, one in Microsoft SharePoint and one in VMware vCenter, to its Known Exploited Vulnerabilities catalog. The agency set Aug. 21, 2026 as the remediation deadline for U.S. federal entities in cases covered by that directive.

What vulnerabilities were added to the KEV?

CISA added CVE-2026-65400, CVE-2026-33824, CVE-2026-55040 and CVE-2026-59310, all reported as actively exploited. Based on the technical coverage compiled around them, the list includes an authentication bypass in macOS Screen Sharing, a double free flaw in Microsoft Internet Key Exchange Service Extensions, a vulnerability in Microsoft SharePoint and a critical path traversal issue in Broadcom VMware vCenter Syslog Server.

In the case of CVE-2026-33824, Ciberplaneta reported that it is a critical double free vulnerability that allows remote code execution without prior authentication. Penligent also described it as a pre-authentication remote code execution flaw in Windows IKE Extensions and confirmed that CISA added it to the KEV on Aug. 18, 2026 as an actively exploited vulnerability.

For CVE-2026-59310, f4n6 said it is a critical path traversal vulnerability with a CVSS score of 9.8 in Broadcom VMware vCenter Syslog Server. SecurityWeek added that CISA placed that flaw, along with the Microsoft and Apple issues, in the KEV catalog and urged immediate patching.

What is known about the Apple case?

CVE-2026-65400 was treated as a critical authentication bypass flaw in macOS Screen Sharing, with a CVSS score of 9.8 and active exploitation, and CISA added it to the KEV on Aug. 18, 2026. Tanium also noted that the CVSS score was reassessed to 9.8 on Aug. 14 and that the federal remediation deadline was set for Aug. 21.

The Canadian Centre for Cyber Security advisory specified the patching scope for macOS Tahoe 26.x before 26.6.1, macOS Sequoia 15.x before 15.7.9 and macOS Sonoma 14.x before 14.8.9. That same Canadian alert confirmed that CISA added CVE-2026-65400 to its KEV database.

What did regional agencies say?

Brazil's Institutional Security Office, through CTIR.GOV, issued alert 68/2026 about a vulnerability in Microsoft Internet Key Exchange Service Extensions. In that notice, the agency reminded readers that inclusion in the KEV catalog is based on reliable evidence of active exploitation and on the availability of fixes from the vendor.

That regional warning is a useful operational reference for teams in Latin America that manage environments with Microsoft, Apple or VMware. The technical material cited by CISA and specialized media places all four flaws in widely used products and prioritizes patching.

Sources

View all