CyberSafe Threat Research · Operator brief · 18 August 2026

CISA KEV: four vulnerabilities confirmed exploited

Source: CISA alert, 18 August 2026. CyberSafe does not add CVEs. We rank them for operators without a full-time SOC.

  1. CVE-2026-55040 — Microsoft SharePoint weak authentication. Internet-facing SharePoint first. Hunt for compromise, then patch, then verify.
  2. CVE-2026-59310 — Broadcom VMware vCenter path traversal. Take vCenter off the open internet. MFA on jump paths. Hunt, then patch.
  3. CVE-2026-33824 — Microsoft IKE Service Extensions double free (RCE class). Treat VPN/IKE appliances as untrusted until closed.
  4. CVE-2026-65400 — Apple macOS improper authentication. Fleet-patch Mac endpoints; lower blast radius than the three above for most orgs.

Federal BOD 26-04 windows are short. Non-federal teams should still treat internet-facing SharePoint and vCenter as this week’s work. Compensating isolation is allowed. Silence is not.

CS-ADV-0001 · Windhoek · https://www.cisa.gov/news-events/alerts/2026/08/18/cisa-adds-four-known-exploited-vulnerabilities-catalog