CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog this week, giving federal agencies until August 21 to patch flaws in Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and a Microsoft Internet Key Exchange (IKE) service extension. Two of the four, the macOS and IKE flaws, are new to the catalog.
What happened
The macOS flaw, CVE-2026-65400, is an improper authentication vulnerability in Screen Sharing that lets a network attacker connect without valid credentials; CISA’s catalog entry says it has been exploited to deliver cryptocurrency miners. The Microsoft flaw, CVE-2026-33824, is a double-free vulnerability in IKE Service Extensions that enables remote code execution over the network. Open-source reporting around the catalog update has linked exploitation to Chinese-speaking actors running AI-enabled, largely autonomous hacking campaigns, though CISA’s own catalog entry does not name an attributed actor.
Why it matters
Both flaws are network-reachable and require no authentication, the profile CISA prioritizes for the short remediation window it set here. macOS’s Screen Sharing service and Windows’ IKE stack are both commonly exposed on managed fleets specifically because they are meant to be reachable, which is what makes an authentication bypass or memory-corruption bug in either one immediately actionable for an opportunistic attacker scanning for exposed hosts rather than targeting a specific organization.
The original insight
Grouping two unrelated platform vendors’ flaws into a single KEV update, on the same day as SharePoint and vCenter entries CyberTech has already covered and reported on separately, is a reminder that KEV additions cluster around whatever attackers are actively working that week rather than around any single vendor’s patch cycle. Security teams that patch by vendor advisory rather than by watching the KEV feed directly are structurally always a step behind on cross-platform weeks like this one.