Ethical Hacking News
Four critical vulnerabilities, including those in Apple macOS, Microsoft SharePoint, VMware vCenter, and Microsoft IKE, have been identified as being under active exploitation, highlighting the need for organizations to prioritize patching and updating their systems to prevent exploitation of these vulnerabilities.
Four critical vulnerabilities in Apple macOS, Microsoft SharePoint, VMware vCenter, and Microsoft IKE are under active exploitation. CVE-2026-65400 allows attackers to authenticate to Screen Sharing without valid credentials, while CVE-2026-55040 enables unauthorized bypass of a security feature. CVE-2026-59310 allows threat actors with network access to execute arbitrary code in VMware vCenter, and CVE-2026-33824 is a double-free vulnerability in Microsoft IKE Service Extensions. The vulnerabilities have been actively exploited by threat actors in at least 47 countries, with the most affected countries including Germany, the U.S., Turkey, Iran, and France. A suspected China-nexus APT actor has been observed exploiting CVE-2026-33824, highlighting the growing threat of nation-state actors and their sophisticated hacking techniques. Federal agencies have until August 21, 2026, to update vulnerable systems and prioritize patching and updating to prevent exploitation.
Critical Vulnerabilities Under Active Exploitation: A Global Threat Landscape
The cybersecurity landscape has become increasingly complex, with new vulnerabilities and threats emerging at an alarming rate. The latest batch of known exploited vulnerabilities (KEV) cataloged by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) highlights the gravity of the situation. Four critical vulnerabilities, including those in Apple macOS, Microsoft SharePoint, VMware vCenter, and Microsoft IKE, have been identified as being under active exploitation.
The first vulnerability, CVE-2026-65400, impacts Apple macOS and allows an attacker on the network to authenticate to Screen Sharing without valid credentials. This vulnerability has been abused to deliver a Monero cryptocurrency miner, further exacerbating the threat. The CVE-2026-55040 vulnerability in Microsoft SharePoint enables an unauthorized attacker to bypass a security feature over a network, while CVE-2026-59310 in Broadcom VMware vCenter allows a threat actor with network access to vCenter to execute arbitrary code. The fourth vulnerability, CVE-2026-33824, is a double-free vulnerability in Microsoft Internet Key Exchange (IKE) Service Extensions, which could allow an unauthorized attacker to execute code over a network.
The vulnerabilities have been actively exploited by various threat actors, including those from China, in at least 47 countries. The most affected countries include Germany, the U.S., Turkey, Iran, and France. The compromised IP addresses belong to 361 unique victims, with the majority of infections concentrated in these five countries. The campaign has also led to the deployment of a Babuk-derived ransomware in at least one case.
The suspected China-nexus advanced persistent threat (APT) actor has been observed exploiting CVE-2026-33824, a Chinese-speaking threat actor who has also been observed launching an AI-enabled autonomous hacking campaign using DeepSeek. This highlights the growing threat of nation-state actors and their sophisticated hacking techniques.
Federal Civilian Executive Branch (FCEB) agencies have until August 21, 2026, to update vulnerable systems to the latest version and adhere to BOD 26-04 patching guidelines for optimal protection. It is essential for organizations to prioritize patching and updating their systems to prevent exploitation of these critical vulnerabilities.
The recent addition of these vulnerabilities to the KEV catalog serves as a reminder of the ongoing threat landscape. As threat actors continue to evolve and improve their tactics, it is crucial for organizations to stay vigilant and proactive in their cybersecurity measures.
Related Information:
https://www.ethicalhackingnews.com/articles/Critical-Vulnerabilities-Under-Active-Exploitation-A-Global-Threat-Landscape-ehn.shtml
https://thehackernews.com/2026/08/critical-macos-sharepoint-vcenter-and.html
https://nvd.nist.gov/vuln/detail/CVE-2026-65400
https://www.cvedetails.com/cve/CVE-2026-65400/
https://nvd.nist.gov/vuln/detail/CVE-2026-55040
https://www.cvedetails.com/cve/CVE-2026-55040/
https://nvd.nist.gov/vuln/detail/CVE-2026-59310
https://www.cvedetails.com/cve/CVE-2026-59310/
https://nvd.nist.gov/vuln/detail/CVE-2026-33824
https://www.cvedetails.com/cve/CVE-2026-33824/
Published: Wed Aug 19 06:52:59 2026 by llama3.2 3B Q4_K_M