HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws (CVE‑2026‑65400) Under Active Exploitation

CISA added four high‑severity vulnerabilities—including a macOS authentication bypass (CVSS 9.8)—to its KEV catalog, confirming they are being weaponized today. For SOC 2‑compliant firms, this underscores the need for real‑time vulnerability management and auditable remediation evidence.

LiveThreat™ Intelligence · 📅 August 19, 2026· 📰 thehackernews.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
5 recommended
📰
Source
thehackernews.com

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws (CVE‑2026‑65400) Under Active Exploitation

What It Is — CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming they are being weaponized in the wild. The most severe, CVE‑2026‑65400, is an improper‑authentication flaw in Apple macOS with a CVSS 9.8 score; similar high‑severity bugs affect Microsoft SharePoint, VMware vCenter, and Microsoft IKE.

Exploitability — All four are confirmed “actively exploited” by threat actors; public proof‑of‑concepts and ransomware‑as‑a‑service kits have been observed leveraging the macOS bug to gain system‑level access.

Affected Products

  • Apple macOS (CVE‑2026‑65400)
  • Microsoft SharePoint Server (specific CVE not disclosed in the article)
  • VMware vCenter Server (specific CVE not disclosed)
  • Microsoft IKE (IPsec) implementation (specific CVE not disclosed)

Why It Matters for Compliance & Audit Readiness

  • Control CC6.1 – Vulnerability Management: SOC 2 requires documented processes for identifying, assessing, and remediating critical flaws. Active exploitation forces organizations to prove they can respond within the control’s defined timeframes.
  • Continuous Evidence: Real‑time patch‑status feeds and remediation tickets become audit evidence that the organization is not merely “paper‑compliant” but actually mitigating known threats.
  • Enterprise Buyer Expectation: Prospects now demand proof (e.g., a Trust Center view) that vendors have patched KEV‑listed flaws before signing contracts.

Recommended Actions

  • Asset Discovery – Run an inventory sweep to locate any macOS, SharePoint, vCenter, or IKE endpoints in scope.
  • Prioritized Patch Deployment – Apply vendor‑released patches or mitigations immediately; document dates, versions, and responsible owners.
  • Control Mapping – Align each remediation step to SOC 2 CC6.1 and capture screenshots or ticket logs as continuous compliance evidence.
  • Monitor for Indicators of Compromise – Deploy endpoint detection rules that flag exploitation patterns associated with these CVEs.
  • Update Incident‑Response Playbooks – Incorporate the new CVEs into your “exploit‑in‑the‑wild” response flow.

Source: The Hacker News – Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

📰 Original Source
https://thehackernews.com/2026/08/critical-macos-sharepoint-vcenter-and.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →