THE US Cybersecurity and Infrastructure Security Agency (CISA) has urged immediate action to patch four critical vulnerabilities in Microsoft, VMware, and Apple products that are currently being exploited.
Notable vulnerabilities include: 1) CVE-2026-33824, a critical flaw in Microsoft's Windows IKE Service Extension with a CVSS score of 9.8, allowing remote code execution; 2) CVE-2026-55040, a weak authentication issue in SharePoint (CVSS 9.1); 3) VMware's CVE-2026-59310 (CVSS 9.8), exploited to drop an SSH reverse shell; and 4) Apple’s CVE-2026-65400 (CVSS 7.5), allowing attackers to bypass authentication on macOS. CISA advises all federal agencies to implement these patches by August 21.