CISA Adds Four Known Exploited Vulnerabilities to Catalog

Executive Summary

CISA has added four CVEs—CVE‑2026‑33824 (Microsoft IKE double free), CVE‑2026‑55040 (Microsoft SharePoint weak auth), CVE‑2026‑59310 (Broadcom VMware vCenter path traversal), and CVE‑2026‑65400 (Apple macOS improper auth)—to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The update reinforces BOD 26‑04, which mandates federal agencies prioritize rapid remediation of high‑risk KEV CVEs on publicly exposed assets, and encourages all organizations to adopt risk‑based vulnerability management.


Intelligence Metadata - Source Publisher: CISA Cyber Advisories - Published Date: 2026-08-18T12:00:00+00:00 - Category: cves

"We should all be thankful for those people who rekindle the inner spirit."

— Albert Schweitzer
Source: CISA Cyber Advisories