CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog, raising the total from 1666 to 1670 entries and flagging active exploitation affecting Microsoft Internet Key Exchange (IKE) Service Extensions, Microsoft SharePoint, Broadcom VMware vCenter, and Apple macOS Screen Sharing. The newly listed issues are CVE-2026-33824, CVE-2026-55040, CVE-2026-59310, and CVE-2026-65400, covering weaknesses that can enable remote code execution, path traversal, weak authentication, or improper authentication.
Under BOD 22-01, CISA directed U.S. federal agencies to remediate all four flaws by 2026-08-21 and urged other organizations to review exposure and apply available fixes. Reporting on the update said the SharePoint issue is tied to a JWT forgery attack chain, while the macOS Screen Sharing flaw was confirmed as actively exploited by the Dutch National Cyber Security Centre; Apple has already released patches, and CISA's KEV data indicates ransomware use is currently unknown for all four CVEs.

See which actors are running it and whether you're in range.
10 events from the most recent confirmed update back to the earliest known activity.
CISA updated its Known Exploited Vulnerabilities catalog from version 2026.08.17 to 2026.08.18, increasing the total from 1666 to 1670 entries by adding CVE-2026-33824, CVE-2026-59310, CVE-2026-55040, and CVE-2026-65400.
CISA added CVE-2025-62593, a code-injection vulnerability affecting the Ray distributed computing framework, to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The flaw can be exploited via DNS rebinding and browser-based interaction against vulnerable Ray interfaces.
The Dutch National Cyber Security Centre confirmed active exploitation of CVE-2026-65400, an improper authentication flaw affecting macOS Screen Sharing.
VMware published security advisory VMSA-2026-0006 covering multiple vulnerabilities affecting products including ESX, vCenter, Workstation, Fusion, Cloud Foundation, Telco Cloud Infrastructure, Telco Cloud Platform, and vSphere Foundation. The advisory provided patched versions for CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, and CVE-2026-41709.
Palo Alto Networks reported at the end of July 2026 that CVE-2026-33824 had been exploited by a Chinese-speaking threat actor. The activity was described as part of an AI-enabled autonomous hacking campaign that also involved manual exploitation.
A CVE record was published for CVE-2026-33824, a double free vulnerability affecting Microsoft Internet Key Exchange (IKE) Service Extensions that could enable remote code execution.
CYFIRMA reported that a campaign named “流血你” (“bleed you”) was launched to exploit CVE-2022-34721, a critical remote code execution flaw in Windows Internet Key Exchange Protocol Extensions. The report said the activity targeted more than 1,000 vulnerable systems and attributed it with moderate confidence to Mandarin-speaking threat actors, with possible ties to Russian cybercriminals including FIN7.
Public reporting said the macOS Screen Sharing flaw CVE-2026-65400 has been abused to deliver a Monero cryptocurrency miner. The vulnerability allows a network attacker to authenticate to Screen Sharing without valid credentials.
Apple released fixes for CVE-2026-65400 in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9, improving authentication state handling to prevent network attackers from authenticating without valid credentials.
CISA warned that attackers are actively exploiting CVE-2026-33824, a critical remote code execution flaw in Windows Internet Key Exchange Service Extensions (MS-IKEE). The agency urged defenders to prioritize patching and noted mitigations such as blocking or restricting inbound UDP traffic on ports 500 and 4500.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
14 references tracked. Mallory keeps watching after this page renders.
cirt.gy
Open sourcethecyberthrone.in
Open sourcesocradar.io
Open sourcecert.ug
Open sourcecve.org
Open sourcecyfirma.com
Open sourcefirst.org
Open sourcegov.br
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.