CyberSecurity SEE

Critical macOS, SharePoint, vCenter, and Microsoft IKE Vulnerabilities Under Active Exploitation

Critical macOS, SharePoint, vCenter, and Microsoft IKE Vulnerabilities Under Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently taken significant steps to enhance digital safety by adding four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. Announced on a Tuesday, these vulnerabilities are reportedly being actively exploited in various cyber operations, highlighting the urgent need for organizations to address them.

The vulnerabilities added to the KEV catalog include:

  1. CVE-2026-65400: Scoring a CVSS (Common Vulnerability Scoring System) rating of 9.8, this flaw involves improper authentication affecting Apple’s macOS. It poses a serious risk as an attacker on the same network can potentially authenticate to the Screen Sharing service without needing valid credentials.

  2. CVE-2026-55040: With a CVSS score of 9.1, this vulnerability impacts Microsoft SharePoint. It allows unauthorized attackers to bypass significant security features over a network, which could lead to extensive data exposure or system manipulation.

  3. CVE-2026-59310: This vulnerability, also rated at 9.8, relates to a path traversal issue within Broadcom’s VMware vCenter. A threat actor with network access could exploit this to execute arbitrary code, compromising system integrity.

  4. CVE-2026-33824: Another critical flaw, also receiving a CVSS score of 9.8, exists within Microsoft Internet Key Exchange (IKE) Service Extensions. This double free vulnerability can enable unauthorized attackers to execute code over a network, presenting a substantial risk to data security.

While these vulnerabilities have been subsequently patched by their respective vendors, reports indicate they have been actively exploited prior to remediation. The urgency arises from the fact that these vulnerabilities are not merely theoretical but have been used in real-world attacks.

In particular, the flaw within Apple’s macOS has been noted for its exploitation to deliver a Monero cryptocurrency miner, indicating a trend where attackers seek not just unauthorized access, but also ways to profit from compromised systems. Similarly, the vulnerabilities affecting Microsoft SharePoint have been exploited by unknown actors, especially following the release of proof-of-concept (PoC) code, which often emboldens hackers to exploit such flaws.

Interestingly, the vulnerability concerning VMware vCenter has been tied to a suspected advanced persistent threat (APT) actor, believed to have links to China. This actor has reportedly deployed a sophisticated backdoor alongside reverse SSH binaries, ensuring persistent access to compromised instances. In some scenarios, this campaign has resulted in the deployment of Babuk-derived ransomware, demonstrating the severe consequences that arise from such vulnerabilities.

In total, the exploitation of these vulnerabilities has compromised 361 unique victim IP addresses across 47 nations, with a notable concentration of incidents in Germany, the United States, Turkey, Iran, and France. This geographic spread emphasizes the global nature of cyber threats and the broad array of targets that can be affected.

Furthermore, CVE-2026-33824 has also aroused attention due to its exploitation by another Chinese-speaking threat actor. Reports suggest this actor has simultaneously conducted an AI-enabled autonomous hacking campaign utilizing DeepSeek while also engaging in manual operations through known vulnerabilities, including the Microsoft Internet Key Exchange flaw.

In light of these vulnerabilities, CISA has issued a directive requiring Federal Civilian Executive Branch (FCEB) agencies to update vulnerable systems to the latest versions and follow the BOD 26-04 patching guidelines by August 21, 2026. This directive aims to bolster cybersecurity measures within federal agencies and reduce the likelihood of future exploitations.

Overall, the significance of this announcement cannot be overstated. The vulnerabilities highlighted by CISA are not just technical issues; they represent a broader challenge in the digital landscape—one that requires immediate and coordinated responses from both the public and private sectors. As cyber threats grow in sophistication, organizations must remain vigilant and proactive to safeguard their systems against potential exploits.

Source link

Exit mobile version