HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Advisory

CISA Adds Four Actively Exploited Vulnerabilities (CVE-2026-33824, CVE-2026-55040, CVE-2026-59310, CVE-2026-65400) to KEV Catalog

CISA has placed four high‑risk CVEs—Microsoft IKE, SharePoint, Broadcom VMware vCenter, and Apple macOS—into its Known Exploited Vulnerabilities catalog, signaling active exploitation. Organizations should treat these as top‑priority remediation items to satisfy SOC 2 vulnerability‑management requirements and maintain a defensible audit trail.

LiveThreat™ Intelligence · 📅 August 19, 2026· 📰 cisa.gov
🟠
Severity
High
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
cisa.gov

Four Actively Exploited Vulnerabilities Added to CISA KEV Catalog (CVE‑2026‑33824, CVE‑2026‑55040, CVE‑2026‑59310, CVE‑2026‑65400)

What It Is – The Cybersecurity & Infrastructure Security Agency (CISA) announced that four CVEs—Microsoft IKE double‑free, Microsoft SharePoint weak authentication, Broadcom VMware vCenter path traversal, and Apple macOS improper authentication—have been confirmed as actively exploited and are now listed in the Known Exploited Vulnerabilities (KEV) Catalog.

Exploitability – All four have publicly documented exploitation activity; CISA’s inclusion criteria require evidence of real‑world attacks. No public proof‑of‑concept is needed beyond the observed activity.

Affected Products – Microsoft Windows IKE service, Microsoft SharePoint Server, Broadcom VMware vCenter, Apple macOS (all current supported releases).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 CC6.1 (Vulnerability Management) requires documented, risk‑based remediation of known, exploitable flaws; the KEV list gives a defensible, regulator‑aligned priority set.
  • Continuous control monitoring can capture patch‑status evidence for each KEV item, providing audit‑ready proof that high‑risk vulnerabilities are being addressed promptly.
  • Enterprise buyers increasingly demand evidence that vendors follow a formal, risk‑based patch cadence—using the KEV catalog as a benchmark satisfies that expectation.

Recommended Actions

  • Map each KEV entry to your internal vulnerability‑management controls (e.g., SOC 2 CC6.1, ISO 27001 A.12.6).
  • Deploy automated scanning to detect the four CVEs on all public‑facing assets and capture remediation timestamps as audit evidence.
  • Prioritize patching or mitigations within the timelines defined by CISA’s Binding Operational Directive 26‑04.
  • Document verification that the systems were not compromised before patching, per BOD 26‑04 guidance.

Source: CISA Advisory – Four Known Exploited Vulnerabilities Added to KEV Catalog (2026‑08‑18)

📰 Original Source
https://www.cisa.gov/news-events/alerts/2026/08/18/cisa-adds-four-known-exploited-vulnerabilities-catalog

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →