CISA gave federal agencies three days to patch four exploited flaws
CISA added four actively exploited CVEs to the KEV catalog on 18 August 2026 with a federal due date of 21 August, a three-day window against the usual three weeks. Microsoft IKE, SharePoint, VMware vCenter and Apple macOS Screen Sharing. All four already have patches.

CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on 18 August 2026, covering Microsoft IKE, Microsoft SharePoint, Broadcom VMware vCenter and Apple macOS.
The federal remediation deadline is 21 August 2026, three days after the catalog entry. Under BOD 22-01, CISA normally sets KEV due dates around three weeks out. Three days is the exception, and it is the single most informative thing in this batch.
| CVE | Product | CISA's title | CVSS | Vendor patch |
|---|---|---|---|---|
| CVE-2026-33824 | Microsoft IKE Service Extensions | Double Free Vulnerability | 9.8 | April 2026 |
| CVE-2026-55040 | Microsoft SharePoint | Weak Authentication Vulnerability | 9.1 | July 2026 Patch Tuesday |
| CVE-2026-59310 | Broadcom VMware vCenter | Path Traversal Vulnerability | 9.8 | 29 July 2026 |
| CVE-2026-65400 | Apple macOS | Improper Authentication Vulnerability | 9.8 (disputed, see below) | 6 August 2026 |
Every one of these already has a patch. Nothing here is a zero-day awaiting a fix. The oldest, the IKE double free, was patched in April 2026, which means the exploited population has had roughly four months to install it and has not.
CVE-2026-33824, Microsoft IKE Service Extensions. A double free that lets a remote, unauthenticated attacker execute arbitrary code via specially crafted packets. Exploitation is attributed to a Chinese-speaking threat actor running an AI-assisted campaign, with Palo Alto Networks describing largely autonomous operation using DeepSeek alongside manual work. The patch shipped in April 2026.
CVE-2026-55040, Microsoft SharePoint. CISA files this as weak authentication. Microsoft's framing is a security-feature bypass over a network by an unauthorized attacker, and the flaw is not remote code execution on its own. Exploitation began after public proof-of-concept code appeared in early August 2026: patch in July, PoC in August, exploitation immediately after.
CVE-2026-59310, Broadcom VMware vCenter. CISA catalogs it as path traversal, which is the mechanism rather than the outcome. An attacker with network access to vCenter can execute arbitrary code. Reporting describes a suspected China-nexus group deploying backdoors, reverse_ssh binaries and Babuk-derived ransomware, with 361 victim IPs across 47 countries. Broadcom patched it on 29 July 2026.
CVE-2026-65400, Apple macOS. Improper authentication in Screen Sharing, letting an attacker on the network authenticate without valid credentials. Observed exploitation has been dropping a Monero cryptocurrency miner. Apple patched it on 6 August 2026.
The macOS entry does not have an agreed severity. The Hacker News puts CVE-2026-65400 at CVSS 9.8. SecurityWeek puts it at 7.5. That is the difference between critical and high, and it changes where the ticket sits in most patching queues. A network authentication bypass scores very differently depending on whether the assessor counts the result as full system compromise or as unauthorized access to a single service. CISA's own catalog entries do not carry CVSS scores, so there is no tiebreaker in the primary source. The exploitation evidence itself is not in dispute.
Federal Civilian Executive Branch agencies are bound by BOD 22-01, which requires them to remediate catalogued vulnerabilities by the due date. For these four, that is 21 August 2026. Everyone else has no legal obligation and the same exposure. CISA's standing position is that private organizations should review the catalog and address these vulnerabilities in their own infrastructure. The KEV catalog is an evidence-of-exploitation list rather than a severity list.
The four already-shipped fixes are the April 2026 Windows updates, the July 2026 SharePoint updates, the 29 July vCenter fix and the 6 August macOS update.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free