
Four vulnerabilities now confirmed exploited — patch SharePoint and vCenter first
On 18 August 2026 CISA added four CVEs to its Known Exploited Vulnerabilities catalog: Microsoft IKE (CVE-2026-33824), SharePoint weak authentication (CVE-2026-55040), VMware vCenter path traversal (CVE-2026-59310), and Apple macOS improper authentication (CVE-2026-65400). Internet-facing SharePoint and vCenter are the highest-consequence pair for most organisations. Hunt for compromise before you patch, then close the exposure window the same week.


