CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities Catalog, all of which are actively being exploited. The vulnerabilities affect Microsoft, Broadcom, and Apple products, with a critical severity rating of 9.8 for three of them, including the Windows IKE Service Extensions. Agencies are required to patch these issues by August 21, 2026. The vulnerabilities include:
1. **CVE-2026-33824** - Double free in Windows IKE service (CVSS 9.8)
2. **CVE-2026-59310** - Path traversal in VMware vCenter (CVSS 9.8)
3. **CVE-2026-65040** - Weak authentication in Microsoft SharePoint (CVSS 9.1)
4. **CVE-2026-65400** - Improper authentication in macOS (CVSS 9.8).
Organizations are urged to apply relevant patches immediately to mitigate risks.