HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

CISA Flags Critical macOS, SharePoint, VMware vCenter, and Microsoft IKE Flaws as Actively Exploited

CISA added five high‑severity CVEs—covering Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE—to its Known Exploited Vulnerabilities catalog. The flaws enable remote code execution or authentication bypass and are confirmed in the wild. For SOC 2‑ready organizations, the catalog provides a concrete trigger to map, remediate, and evidence control compliance.

LiveThreat™ Intelligence · 📅 August 19, 2026· 📰 securityaffairs.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
securityaffairs.com

Critical Vulnerabilities Added to CISA KEV Catalog: macOS, SharePoint, VMware vCenter, and Microsoft IKE (CVE‑2026‑33824, CVE‑2026‑55040, CVE‑2026‑59310, CVE‑2026‑65400)

What It Is – The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has placed five high‑severity flaws in its Known Exploited Vulnerabilities (KEV) catalog. The CVEs span Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft Internet Key Exchange (IKE) services, each scoring 9.1‑9.8 on the CVSS v3.1 scale.

Exploitability – All five are confirmed as actively exploited in the wild. Public proof‑of‑concept code exists for the SharePoint JWT bypass and the IKE double‑free RCE.

Affected Products – Apple macOS (any version supporting the vulnerable IKE component), Microsoft SharePoint Server Subscription Edition, Broadcom VMware vCenter Server, and Microsoft Windows IKE service extensions.

Why It Matters for Compliance & Audit Readiness

  • Control Mapping – Each flaw maps to SOC 2 CC6.1 (Logical Access) and CC7.1 (System Operations) controls; evidence of remediation must be captured continuously to satisfy auditors.
  • Continuous Monitoring – Real‑time vulnerability feeds (e.g., CISA KEV) become audit‑ready evidence that your organization is actively tracking and mitigating known exploits.
  • Defensible Audit Trail – Documented patch cycles, port‑blocking rules, and privileged‑access reviews demonstrate due diligence when regulators or enterprise customers request SOC 2 proof.

Recommended Actions

  • Prioritize patching the listed CVEs on all affected assets; apply Microsoft’s IKE and SharePoint updates, VMware’s vCenter hotfix, and Apple macOS security updates immediately.
  • Block external UDP 500/4500 where IKE is not required, and enforce strict JWT validation policies on SharePoint.
  • Map each vulnerability to the relevant SOC 2 controls in your compliance platform and capture remediation tickets, patch‑install logs, and firewall rule changes as continuous evidence.
  • Enable automated KEV feed ingestion to trigger alerts and generate audit‑ready reports.

Source: Security Affairs – CISA adds macOS, SharePoint, VMware vCenter, and Microsoft IKE flaws to KEV catalog

📰 Original Source
https://securityaffairs.com/197490/hacking/u-s-cisa-adds-apple-macos-microsoft-sharepoint-broadcom-vmware-vcenter-and-microsoft-ike-flaws-to-its-known-exploited-vulnerabilities-catalog.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →