CISA has added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog, confirming active exploitation of flaws in Apple macOS, Microsoft SharePoint, VMware vCenter, and Microsoft IKE implementations.
CVE-2026-65400 affects Apple macOS with a CVSS score of 9.8. This improper authentication vulnerability allows attackers to bypass security controls and gain unauthorized access to systems. The flaw resides in macOS core authentication mechanisms, making it a direct threat to the installed base of Mac users across enterprise and consumer environments. Apple systems handling sensitive data or running critical services face immediate risk.
The Microsoft SharePoint vulnerability targets one of the world's most widely deployed document and content management platforms. Thousands of organisations rely on SharePoint for collaboration, file sharing, and business processes. Exploitation of this flaw could grant attackers access to confidential documents, intellectual property, and internal communications stored within SharePoint sites. The presence of this vulnerability in CISA's KEV catalog indicates attackers have demonstrated working exploits in production environments.
VMware vCenter remains a high-value target for threat actors. vCenter serves as the control plane for virtualised infrastructure in data centres across financial services, healthcare, government, and technology sectors. A critical flaw in vCenter authentication or access control allows attackers to compromise the hypervisor management layer, potentially leading to deployment of persistent malware across entire virtual machine farms, lateral movement into hosted applications, and exfiltration of sensitive workloads.
The Microsoft IKE (Internet Key Exchange) vulnerability impacts VPN and remote access security. IKE protocols handle encryption key negotiation for IPsec-based virtual private networks. A vulnerability in IKE implementations can compromise the confidentiality and integrity of encrypted tunnels, allowing attackers to intercept, decrypt, or modify traffic flowing through corporate VPN connections.
CISA's addition of these flaws to the KEV catalog carries significant operational weight. The agency maintains this catalog specifically to warn federal agencies and critical infrastructure operators of vulnerabilities with confirmed real-world exploitation. Organisations should treat items on the KEV catalog as immediate priorities for patching.
The timing reflects the escalating sophistication of threat actors leveraging zero-days and newly disclosed vulnerabilities. Security teams that delay patching these four vulnerabilities expose their organisations to direct compromise. In federated networks where macOS endpoints, SharePoint servers, vCenter clusters, and VPN gateways interact, compromise of any single component can cascade into broader intrusions.
Vendors have released patches or mitigations for these flaws. Apple, Microsoft, and VMware have published security advisories with recommended update paths. Organisations should prioritise deploying updates for macOS systems, apply Microsoft patches to on-premises and cloud-based SharePoint deployments, update vCenter instances in virtualisation environments, and patch IKE implementations across VPN concentrators and firewalls.
Patch deployment complexity varies. macOS updates can be staged to non-critical systems first. SharePoint patches may require maintenance windows and testing in non-production environments. vCenter updates may necessitate planned downtime or migration of virtual machines to other cluster members. VPN gateway updates require careful coordination to avoid disrupting remote access for legitimate users.
Threat actors actively exploiting these flaws demonstrate persistent determination to penetrate enterprise networks. Organisations that remain unpatched will face higher breach probability. CISA's KEV notification creates accountability for federal contractors and critical infrastructure operators mandated to implement mitigations.
