Four Actively Exploited Vulnerabilities Added to CISA KEV Catalog (CVE‑2026‑33824, CVE‑2026‑55040, CVE‑2026‑59310, CVE‑2026‑65400)
What It Is – The Cybersecurity & Infrastructure Security Agency (CISA) announced that four CVEs—Microsoft IKE double‑free, Microsoft SharePoint weak authentication, Broadcom VMware vCenter path traversal, and Apple macOS improper authentication—have been confirmed as actively exploited and are now listed in the Known Exploited Vulnerabilities (KEV) Catalog.
Exploitability – All four have publicly documented exploitation activity; CISA’s inclusion criteria require evidence of real‑world attacks. No public proof‑of‑concept is needed beyond the observed activity.
Affected Products – Microsoft Windows IKE service, Microsoft SharePoint Server, Broadcom VMware vCenter, Apple macOS (all current supported releases).
Why It Matters for Compliance & Audit Readiness
- SOC 2 CC6.1 (Vulnerability Management) requires documented, risk‑based remediation of known, exploitable flaws; the KEV list gives a defensible, regulator‑aligned priority set.
- Continuous control monitoring can capture patch‑status evidence for each KEV item, providing audit‑ready proof that high‑risk vulnerabilities are being addressed promptly.
- Enterprise buyers increasingly demand evidence that vendors follow a formal, risk‑based patch cadence—using the KEV catalog as a benchmark satisfies that expectation.
Recommended Actions
- Map each KEV entry to your internal vulnerability‑management controls (e.g., SOC 2 CC6.1, ISO 27001 A.12.6).
- Deploy automated scanning to detect the four CVEs on all public‑facing assets and capture remediation timestamps as audit evidence.
- Prioritize patching or mitigations within the timelines defined by CISA’s Binding Operational Directive 26‑04.
- Document verification that the systems were not compromised before patching, per BOD 26‑04 guidance.
Source: CISA Advisory – Four Known Exploited Vulnerabilities Added to KEV Catalog (2026‑08‑18)