CISA Adds Four Actively Exploited Vulnerabilities to KEV Catalog
CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog to include four new flaws found in Microsoft, VMware, and Apple products that are currently being targeted by attackers.

English Brief
CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog to include four new flaws found in Microsoft, VMware, and Apple products that are currently being targeted by attackers.
الموجز العربي
وكالة الأمن السيبراني الأمريكية تضيف أربع ثغرات مُستغلة إلى قائمة التهديدات المؤكدة
قامت وكالة الأمن السيبراني الأمريكية (CISA) بتحديث قائمتها للثغرات الأمنية المعروفة والمُستغلة (KEV) لتشمل أربع ثغرات جديدة في منتجات مايكروسوفت وVMware وأبل، والتي يتم استغلالها حالياً من قبل المهاجمين.
- 1Identify affected systems using vulnerability scanner. # 2. Consult vendor security portals for patches corresponding to CVE-2026-33824, CVE-2026-55040, CVE-2026-59310, and CVE-2026-65400. # 3. Apply updates to Microsoft SharePoint, IKE service, VMware vCenter, and macOS. # 4. Audit system logs for unauthorized authentication attempts or path traversal patterns.
English Advisory
// Intelligence Summary
CISA has expanded its Known Exploited Vulnerabilities (KEV) Catalog to include four vulnerabilities observed in active exploitation campaigns. These CVEs affect critical infrastructure software, including Microsoft SharePoint, Microsoft IKE service, VMware vCenter, and macOS.
التقرير العربي
// ملخص استخباراتي
قامت وكالة الأمن السيبراني (CISA) بتوسيع قائمة الثغرات الأمنية المعروفة والمستغلة (KEV) لتشمل أربع ثغرات أمنية تم رصدها في حملات استغلال نشطة. تؤثر هذه الثغرات على برمجيات البنية التحتية الحيوية، بما في ذلك Microsoft SharePoint، وخدمة IKE من مايكروسوفت، وVMware vCenter، ونظام macOS.
// Technical Context
- CVE-2026-33824: Double-free vulnerability in Microsoft IKE Service Extensions.
- CVE-2026-55040: Weak authentication vulnerability in Microsoft SharePoint.
- CVE-2026-59310: Path traversal vulnerability in Broadcom VMware vCenter.
- CVE-2026-65400: Improper authentication vulnerability in Apple macOS.
// السياق الفني
- CVE-2026-33824: ثغرة تحرير مزدوج (Double-free) في ملحقات خدمة IKE من مايكروسوفت.
- CVE-2026-55040: ثغرة مصادقة ضعيفة في Microsoft SharePoint.
- CVE-2026-59310: ثغرة اجتياز مسار (Path Traversal) في Broadcom VMware vCenter.
- CVE-2026-65400: ثغرة مصادقة غير سليمة في نظام Apple macOS.
// Exposure Notes
Organizations utilizing these specific software versions are at elevated risk of compromise. The identified vulnerabilities span network services, application platforms, and endpoint operating systems, necessitating an enterprise-wide review of patch management status.
// ملاحظات التعرض
تواجه المؤسسات التي تستخدم هذه الإصدارات من البرمجيات خطراً متزايداً للاختراق. تغطي الثغرات المحددة خدمات الشبكة، ومنصات التطبيقات، وأنظمة تشغيل النقاط الطرفية، مما يستدعي مراجعة شاملة لحالة إدارة التحديثات على مستوى المؤسسة.
// Defensive Priority
Per CISA’s Binding Operational Directive (BOD) 26-04, organizations should prioritize the immediate application of security updates for these vulnerabilities. Conduct thorough forensic log analysis to determine if these systems were targeted prior to patching.
// أولوية الدفاع
وفقاً للتوجيه التشغيلي الإلزامي (BOD 26-04) الصادر عن CISA، يجب على المؤسسات إعطاء الأولوية للتطبيق الفوري لتحديثات الأمان الخاصة بهذه الثغرات. يجب إجراء تحليل جنائي دقيق للسجلات (Logs) لتحديد ما إذا كانت هذه الأنظمة قد تعرضت لهجمات قبل تطبيق التحديثات.
Mitigation Checklist
- 1Identify affected systems using vulnerability scanner. # 2. Consult vendor security portals for patches corresponding to CVE-2026-33824, CVE-2026-55040, CVE-2026-59310, and CVE-2026-65400. # 3. Apply updates to Microsoft SharePoint, IKE service, VMware vCenter, and macOS. # 4. Audit system logs for unauthorized authentication attempts or path traversal patterns.
قائمة إجراءات التخفيف
- 1تحديد الأنظمة المتأثرة باستخدام ماسح الثغرات. # 2. مراجعة بوابات أمان الموردين للحصول على التحديثات الخاصة بـ CVE-2026-33824, CVE-2026-55040, CVE-2026-59310, و CVE-2026-65400. # 3. تطبيق التحديثات على Microsoft SharePoint وخدمة IKE وVMware vCenter وmacOS. # 4. فحص سجلات النظام بحثاً عن محاولات مصادقة غير مصرح بها أو أنماط اجتياز مسار.
- Source: CISA Alerts
# 1. Identify affected systems using vulnerability scanner. # 2. Consult vendor security portals for patches corresponding to CVE-2026-33824, CVE-2026-55040, CVE-2026-59310, and CVE-2026-65400. # 3. Apply updates to Microsoft SharePoint, IKE service, VMware vCenter, and macOS. # 4. Audit system logs for unauthorized authentication attempts or path traversal patterns.