The U.S. Cybersecurity and Infrastructure Security Agency has confirmed active exploitation of four critical security vulnerabilities affecting widely deployed enterprise systems, adding them to its Known Exploited Vulnerabilities catalog on Tuesday. The additions signal immediate risk to organizations using Apple macOS, Microsoft SharePoint, and VMware vCenter Server platforms.
The most severe flaw is CVE-2026-65400, an improper authentication vulnerability in Apple macOS with a CVSS score of 9.8 out of 10. This weakness could allow attackers to bypass authentication mechanisms and gain unauthorized access to affected systems. The vulnerability joins three other actively exploited flaws targeting Microsoft SharePoint and VMware vCenter Server, though specific CVE identifiers and technical details for these additional vulnerabilities were not provided in the initial disclosure.
Improper authentication vulnerabilities like CVE-2026-65400 represent a critical security risk because they undermine the fundamental access control mechanisms protecting systems and data. Attackers exploiting such flaws can potentially gain administrative privileges without valid credentials, enabling them to execute arbitrary code, access sensitive information, or establish persistent access to compromised networks. The 9.8 CVSS score reflects the severity and ease of exploitation.
Inclusion in CISA's KEV catalog indicates threat actors are already using these vulnerabilities in real-world attacks, elevating the urgency for remediation. Organizations running affected Apple, Microsoft, and VMware products face immediate risk of compromise. The active exploitation status suggests attackers have developed reliable exploit techniques and may be conducting widespread scanning or targeted campaigns against vulnerable systems.
Federal agencies operating under Binding Operational Directive 22-01 must remediate these vulnerabilities according to CISA-specified deadlines. Private sector organizations should treat KEV catalog additions as high-priority security incidents requiring immediate attention. Security teams should identify affected systems through asset inventory, apply available patches or vendor-recommended mitigations, and monitor for indicators of compromise that may signal successful exploitation attempts.
Source: https://thehackernews.com/2026/08/critical-macos-sharepoint-vcenter-and.html


