CISA orders federal agencies to patch four actively exploited flaws within three days
The vulnerabilities affect widely used Windows, VMware vCenter, SharePoint and macOS software; one has been tied to a suspected China-nexus campaign that has compromised hundreds of servers worldwide.

The Cybersecurity and Infrastructure Security Agency added four vulnerabilities to its catalog of flaws known to be under active attack on August 18, ordering federal civilian agencies to patch systems running Microsoft Windows, VMware vCenter, Microsoft SharePoint and Apple macOS within three days. The additions cover software used inside nearly every large enterprise and government network, and each of the four flaws is already being exploited in the wild rather than sitting as a theoretical risk.
Two of the vulnerabilities, tracked as CVE-2026-33824 and CVE-2026-59310, carry the maximum possible severity score of 9.8 out of 10 under the industry's standard rating system. The Windows flaw sits in the operating system's Internet Key Exchange service and can be triggered with a single malicious network packet, requiring no authentication and no action from a user. The vCenter flaw allows an attacker with only network access to the management console, again without valid credentials, to write files outside their intended location and ultimately run arbitrary code on the server. A third flaw, in Microsoft SharePoint, scored 9.1 and lets an attacker forge a valid authentication token by exploiting how the software validates a type of security certificate. The fourth, in the Screen Sharing feature built into every supported version of macOS, lets an attacker on the same network connect to a Mac without a valid username or password at all.
Four flaws, one three-day deadline
Under Binding Operational Directive 22-01, the standing CISA order that governs how federal agencies must respond to entries on the Known Exploited Vulnerabilities catalog, civilian agencies had until August 21 to apply patches or otherwise remediate all four flaws. That compressed timeline reflects how CISA treats catalog additions: unlike routine vulnerability disclosures, an entry on the KEV list is CISA's certification that real attackers, not just security researchers, are already using the flaw to break into systems. All four vulnerabilities had patches available well before their addition to the catalog — Microsoft fixed the Windows and SharePoint flaws in earlier monthly updates, according to Microsoft's own advisory, Broadcom shipped a vCenter fix on July 29, and Apple patched the macOS flaw on August 6 — meaning the August 18 deadline was aimed largely at organizations that had not yet installed updates already sitting on vendor servers.
A backdoor campaign spanning dozens of countries
The vCenter flaw has drawn particular attention from threat researchers because of the scale of the campaign built around it. Broadcom's own advisory is blunt about the risk: the company warned that a malicious actor with network access to vCenter could exploit the directory-traversal weakness to execute arbitrary code, and that no workaround exists short of installing the patched release.
"A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code," Broadcom said in its security advisory, warning that organizations running any affected version had no mitigation available other than the update itself.
Researchers tracking exploitation of the flaw have identified 361 unique compromised vCenter servers spread across 47 countries, with the heaviest concentrations in Germany, the United States, Turkey, Iran and France, according to a separate investigation into the campaign, which attributed the intrusions to a suspected China-nexus advanced persistent threat group operating in a time zone consistent with mainland China. Investigators have observed the attackers deploying reverse SSH tools to maintain persistent, hard-to-detect access to compromised systems, and in at least one documented case the intrusion progressed to the deployment of ransomware built on leaked Babuk source code. Separately, the Windows IKE vulnerability has been linked to a distinct Chinese-speaking threat actor that researchers describe as using AI tools to automate parts of its intrusion process, while the macOS Screen Sharing flaw has mostly been used by financially motivated attackers to install cryptocurrency-mining software on compromised Macs, according to the Dutch National Cyber Security Centre, which confirmed exploitation within roughly a week of Apple's patch shipping.
Who is exposed
The affected products are broadly deployed enough that the practical exposure extends well past federal agencies covered by CISA's binding directive. VMware vCenter is the management layer underneath a large share of corporate virtualization infrastructure worldwide, meaning any organization running an unpatched, internet-reachable vCenter instance is a potential target regardless of its size or sector. Windows systems running the IKE service are used for virtual private networking across both enterprise and government networks, and SharePoint remains one of the most widely deployed document-collaboration platforms inside large companies. CISA's directive is legally binding only on federal civilian executive branch agencies, but the agency and outside researchers alike have urged state governments, critical infrastructure operators and private companies to treat the same deadline as a practical benchmark, given that the underlying flaws are identical regardless of who operates the network.
What happens next
None of the four vulnerabilities is new in the sense of being freshly discovered; all had been patched by their respective vendors weeks before CISA's catalog addition, and the newest development is simply confirmation that attackers have moved from theoretical interest to working exploitation. Coverage from The Hacker News noted that the SharePoint flaw's exploitation accelerated sharply after a public proof-of-concept was released, a pattern security teams have grown accustomed to seeing repeat with nearly every major enterprise software vulnerability once technical details become widely available. SecurityWeek's reporting on the catalog addition emphasized that organizations still running any of the four unpatched products should assume compromise rather than simply applying the patch, particularly for vCenter instances that have been internet-reachable in the weeks since Broadcom's late-July fix. CISA has not indicated whether it expects to add further vulnerabilities tied to the same exploitation campaigns in the coming weeks, though the agency's catalog has grown steadily throughout 2026 as it continues to formalize which flaws it considers to be under confirmed active attack.

Alibaba raises record $10.2 billion in Hong Kong share sale to fund AI buildout
