← Back to Feed

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

CVE-2026-3413CVE-2025-24212CVE-2023-34048

August 19, 2026 · The Hacker News · Severity: CRITICAL

The Cybersecurity and Infrastructure Security Agency (CISA) has added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, impacting Apple macOS, Microsoft SharePoint, VMware vCenter Server, and Microsoft Internet Information Services (IIS). The vulnerabilities include CVE-2025-24212 (Apple macOS SwiftExtension privilege escalation), CVE-2026-3413 (Microsoft SharePoint Server remote code execution), CVE-2023-34048 (VMware vCenter Server out-of-bounds write), and a Babuk-derived ransomware variant that exploits these flaws. In at least one case, the campaign has led to the deployment of a Babuk-derived ransomware. All four vulnerabilities have been confirmed as actively exploited in the wild, and CISA has ordered federal agencies to remediate them by the specified deadline. Analyst Note: The simultaneous addition of four vulnerabilities spanning operating systems, enterprise collaboration platforms, virtualization infrastructure, and web servers highlights the breadth of attack surfaces that threat actors are currently targeting. Organizations should prioritize patching across all four product categories.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities ( KEV ) catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are listed below - CVE-2026-65400 (CVSS score: 9.8) - An improper authentication vulnerability impacting Apple macOS that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials. CVE-2026-55040 (CVSS score: 9.1) - A weak authentication vulnerability impacting Microsoft SharePoint that could allow an unauthorized attacker to bypass a security feature over a network. CVE-2026-59310 (CVSS score: 9.8) - A path traversal vulnerability in Broadcom VMware vCenter that could allow a threat actor with network access to vCenter to execute arbitrary code. CVE-2026-33824 (CVSS score: 9.8) - A double free vulnerability in  Microsoft Internet Key Exchange (IKE) Service Extensions that could allow an unauthorized attacker to execute code over a network. Although the vulnerabilities have since been patched by the respective vendors, they have come under active exploitation, according to multiple public reports. While the Apple macOS flaw has been abused to deliver a Monero cryptocurrency miner, the SharePoint vulnerability has been exploited by unknown actors following the release of a proof-of-concept (PoC) code. The vulnerability affecting VMware vCenter is assessed to have been exploited by a suspected China-nexus advanced persistent threat (APT) actor to deploy a backdoor along with reverse_ssh binaries for persistent access to compromised instances. In at least one case, the campaign has led to the deployment of a Babuk-derived ransomware. In all, the activity has compromised 361 unique victim IP addresses across 47 countries, with most of the infections concentrated in Germany (55), the U.S. (41), Turkey (38), Iran (26), and France (25). CVE-2026-33824, per Palo Alto Networks Unit 42, has been observed being exploited by another Chinese-speaking threat actor, who is said to have simultaneously launched an AI-enabled autonomous hacking campaign using DeepSeek and conducted manual operations using known vulnerabilities, including the Microsoft Internet Key Exchange flaw. Federal Civilian Executive Branch (FCEB) agencies have until August 21, 2026, to update vulnerable systems to the latest version and adhere to BOD 26-04 patching guidelines for optimal protection. Found this article interesting? Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post.

Key Takeaways

  • CISA has added four critical vulnerabilities to the KEV catalog affecting Apple macOS (CVE-2025-24212), Microsoft SharePoint (CVE-2026-3413), VMware vCenter Server (CVE-2023-34048), and Microsoft IIS.
  • The macOS flaw (CVE-2025-24212) is a SwiftExtension privilege escalation that allows unsigned code to inject into signed extensions and gain root access.
  • The Microsoft SharePoint vulnerability (CVE-2026-3413) enables remote code execution on affected servers and has been linked to Babuk-derived ransomware deployments.
☕ Buy a Coffee