CyberSafe Threat Research · Operator brief · 18 August 2026
Source: CISA alert, 18 August 2026. CyberSafe does not add CVEs. We rank them for operators without a full-time SOC.
CVE-2026-55040 — Microsoft SharePoint weak authentication. Internet-facing SharePoint first. Hunt for compromise, then patch, then verify.CVE-2026-59310 — Broadcom VMware vCenter path traversal. Take vCenter off the open internet. MFA on jump paths. Hunt, then patch.CVE-2026-33824 — Microsoft IKE Service Extensions double free (RCE class). Treat VPN/IKE appliances as untrusted until closed.CVE-2026-65400 — Apple macOS improper authentication. Fleet-patch Mac endpoints; lower blast radius than the three above for most orgs.Federal BOD 26-04 windows are short. Non-federal teams should still treat internet-facing SharePoint and vCenter as this week’s work. Compensating isolation is allowed. Silence is not.
CS-ADV-0001 · Windhoek · https://www.cisa.gov/news-events/alerts/2026/08/18/cisa-adds-four-known-exploited-vulnerabilities-catalog