CISA orders patching of four actively exploited bugs

CISA told federal agencies to patch four actively exploited Microsoft, VMware and Apple vulnerabilities by Aug. 21 under binding directive BOD 26-04 and added them to its KEV catalog.

The Cybersecurity and Infrastructure Security Agency told federal agencies to immediately patch four vulnerabilities in Microsoft, VMware and Apple products that are being actively exploited and set an Aug. 21 remediation deadline under binding operational directive BOD 26-04. CISA added the four defects to its Known Exploited Vulnerabilities (KEV) catalog and reported confirmed in-the-wild use.

Two of the tracked defects affect Microsoft. CVE-2026-33824 is a double-free bug in the Windows Internet Key Exchange (IKE) Service Extension with a CVSS score of 9.8 that can allow remote, unauthenticated attackers to run arbitrary code via specially crafted packets; Microsoft issued a fix in April. CVE-2026-55040 is a SharePoint authentication bypass rated 9.1 and was patched on July’s Patch Tuesday. CISA added both flaws to the KEV list after receiving reports of active exploitation.

The agency’s notice also covers a VMware vCenter vulnerability, CVE-2026-59310, with a 9.8 CVSS score that VMware patched on July 29. Security observations indicate attackers began exploiting that bug on Aug. 3 to execute code and drop an open-source SSH reverse shell framework.

Apple patched a macOS Screen Sharing authentication bypass tracked as CVE-2026-65400 on Aug. 6. The flaw carries a 7.5 CVSS score. In-the-wild abuse was detected within a week of the patch; attackers used the flaw to gain root access and install a Monero cryptocurrency miner on affected devices.

Security vendors reported exploit activity across several of the flaws. At the end of July, one vendor flagged a Chinese-speaking threat actor running an AI-enabled autonomous hacking campaign with manual follow-up to exploit the Windows IKE Extension defect. The SharePoint weakness saw increased targeting after a proof-of-concept exploit was published in early August.

CISA directed federal civilian agencies to apply vendor updates and any available mitigations by Aug. 21 in accordance with BOD 26-04, which requires timely remediation for vulnerabilities listed in the KEV catalog. Vendors have released patches for all four issues. Organizations are advised to install updates, apply workarounds where provided, and monitor systems for indicators of compromise.

Articles by this author