CISA Adds Four Vulnerabilities to the KEV Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, this week, based on evidence of active exploitation (Even though vendors have released patches already).

  • CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

  • CVE-2026-55040 Microsoft SharePoint Weak Authentication Vulnerability

  • CVE-2026-59310 Broadcom VMware vCenter Path Traversal Vulnerability  

  • CVE-2026-65400 Apple macOS Improper Authentication Vulnerability

More information can be found here: https://www.cisa.gov/news-events/alerts/2026/08/18/cisa-adds-four-known-exploited-vulnerabilities-catalog

#cisa #vulnerabilities #kev #patchmananagement #danweis #boardroomcyber #hackproofyourself

Previous
Previous

Microsoft Email Threat Landscape Report Q2, 2026

Next
Next

Terabytes of credentials leaked in massive supply-chain attack