Summary
- CISA has added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild.
- The affected platforms span Apple macOS, Microsoft SharePoint, VMware vCenter, and Microsoft IKE — a broad cross-section of enterprise infrastructure.
- The macOS vulnerability carries a CVSS score of 9.8 and involves improper authentication, representing a severe risk to Apple-dependent environments.
- Federal agencies are subject to mandatory remediation timelines under CISA’s KEV directive; private sector organisations should treat these with equivalent urgency.
- No corroborating sources were available at time of publication; organisations should monitor vendor advisories for additional technical detail.
Four Platforms, Four Active Threats
The U.S. Cybersecurity and Infrastructure Security Agency confirmed on Tuesday that four critical vulnerabilities are being actively exploited, adding each to its Known Exploited Vulnerabilities catalog. The affected products — Apple macOS, Microsoft SharePoint, VMware vCenter, and the Microsoft Internet Key Exchange protocol implementation — collectively represent infrastructure components found in the overwhelming majority of enterprise environments. That breadth is significant: the likelihood that any given organisation is exposed to at least one of these flaws is high.
The macOS Flaw Is the Most Severe
The vulnerability tracked as CVE-2026-65400 carries a CVSS score of 9.8, placing it at the upper end of the critical range. It involves improper authentication in Apple macOS, meaning an attacker could potentially bypass access controls without valid credentials. The source material does not specify the precise attack vector, whether exploitation requires local access or can be achieved remotely, or what versions of macOS are confirmed as affected. Organisations running macOS endpoints or macOS-based infrastructure should consult Apple’s security advisories directly for scope and patch availability.
SharePoint, vCenter, and IKE Round Out the Catalog Additions
The three remaining vulnerabilities affect Microsoft SharePoint, VMware vCenter, and Microsoft’s IKE implementation. SharePoint vulnerabilities have historically been attractive targets given its prevalence as a collaboration and intranet platform in large organisations. VMware vCenter sits at the heart of many virtualisation environments, and a compromise there can provide an attacker with broad lateral movement opportunities across a data centre. The Microsoft IKE flaw is particularly relevant to organisations relying on IPsec-based VPN infrastructure, where exploitation could undermine encrypted tunnels or authentication mechanisms. The source material does not provide CVSS scores or specific CVE identifiers for these three beyond naming them as critical. Further technical detail was not available at the time of writing.
What KEV Inclusion Means in Practice
CISA’s KEV catalog is more than an advisory list. Under Binding Operational Directive 22-01, U.S. federal civilian agencies are legally required to remediate KEV entries within defined timeframes, typically two weeks for most additions. For private sector and non-U.S. organisations, the KEV carries no mandatory force, but its operational intelligence value is considerable. Inclusion requires CISA to have confirmed evidence of active exploitation — not just proof-of-concept code or theoretical exposure. When a vulnerability makes this list, it means adversaries have already operationalised it.
Caution on the Source Material
It is worth noting that the CVE identifier cited for the macOS vulnerability — CVE-2026-65400 — contains a future year in its identifier, which is unusual. This may reflect a typographical error in the source material. No corroborating sources were available to verify the exact CVE numbers for all four vulnerabilities. CISOs should cross-reference CISA’s official KEV catalog directly at cisa.gov to confirm the precise identifiers and associated remediation guidance before prioritising patch cycles.
Why it matters
For a CISO, four simultaneous KEV additions spanning macOS, SharePoint, vCenter, and VPN infrastructure is a material risk event. These are not obscure niche products — they are foundational components in most enterprise environments. Active exploitation confirmed by CISA means patch prioritisation should be immediate rather than queued to the next maintenance window. Organisations that have not yet adopted a KEV-informed vulnerability prioritisation process should treat this as a prompt to do so. The spread across endpoint, collaboration, virtualisation, and network security layers also suggests that a single patching team or platform owner cannot address this alone; cross-functional coordination is required.
What to do now
- Consult CISA’s official KEV catalog at cisa.gov to confirm the exact CVE identifiers and mandated remediation dates for all four vulnerabilities.
- Identify all instances of affected products — Apple macOS, Microsoft SharePoint, VMware vCenter, and Microsoft IKE — within your environment.
- Review vendor security advisories from Apple, Microsoft, and VMware for available patches and any workarounds where patches are not yet deployable.
- Escalate patching of these four vulnerabilities outside normal patch cycle cadence given confirmed active exploitation.
- Coordinate remediation across endpoint, infrastructure, collaboration, and network security teams given the breadth of affected platforms.
