Four critical flaws in macOS, SharePoint, vCenter, and Microsoft IKE are being actively exploited right now — including one tied to a China-nexus APT deploying ransomware. Here's what's happening and what to fix first.

Every so often, a patch advisory drops that's worth reading in full rather than skimming past. This week is one of those weeks.

On August 18, 2026, CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog — the list reserved specifically for flaws confirmed to be under active attack, not just theoretically dangerous. Federal civilian agencies have until August 21, 2026 to patch. That's a three-day window. And while the deadline is technically only binding for U.S. federal agencies, the attackers behind these campaigns are not waiting to see who's in scope. If you're running any of these systems, the clock is already running for you too.

Here's what's actually going on, and why this batch is more serious than the usual weekly patch roundup.

The Four Vulnerabilities, Plainly Explained

1. Apple macOS Screen Sharing (CVE-2026-65400, CVSS 9.8) An improper authentication flaw that lets an attacker on the same network connect to Screen Sharing without valid credentials. In the wild, it's already being used to quietly drop a Monero cryptocurrency miner onto compromised Macs — a relatively "quiet" payload, which often means it's been running longer than anyone's noticed.

2. Microsoft SharePoint (CVE-2026-55040, CVSS 9.1) A weak authentication issue that lets an attacker bypass a SharePoint security control over the network. Once proof-of-concept code went public, exploitation followed almost immediately — a pattern that's become depressingly predictable in enterprise collaboration platforms.

3. Broadcom VMware vCenter (CVE-2026-59310, CVSS 9.8) This is the one that should worry infrastructure teams most. A path traversal bug lets an attacker with network access to vCenter execute arbitrary code. It's assessed to have been exploited by a suspected China-nexus APT group, who deployed a backdoor alongside reverse_ssh binaries for persistent access — and in at least one confirmed case, followed up with Babuk-derived ransomware. vCenter sits at the center of most enterprise virtualization environments, so a compromise here isn't just one server; it's potentially your whole VM fleet.

4. Microsoft Internet Key Exchange (IKE) Service Extensions (CVE-2026-33824, CVSS 9.8) A double-free vulnerability allowing unauthorized remote code execution. According to Palo Alto Networks' Unit 42, this one has a particularly modern twist: a Chinese-speaking threat actor was observed running an AI-enabled autonomous hacking campaign using DeepSeek in parallel with manual exploitation of known vulnerabilities, including this IKE flaw. AI-assisted, semi-autonomous exploitation chains are quickly becoming a normal part of the threat landscape, not a future risk.

The Scale Is Already Real, Not Hypothetical

This isn't a "patch before something bad happens" advisory — the bad thing has already happened, repeatedly. Across these four flaws, security researchers have tracked 361 unique victim IP addresses across 47 countries, with the heaviest concentrations in Germany (55), the United States (41), Turkey (38), Iran (26), and France (25).

That spread tells you this isn't a narrow, targeted campaign against one industry or region. It's opportunistic, automated scanning-and-exploitation at scale — the kind that finds you because you're exposed, not because you were specifically chosen.

Why This Batch Feels Different

A few things stand out when you look at these four together:

  • They span very different layers of the stack — endpoint (macOS), collaboration software (SharePoint), virtualization infrastructure (vCenter), and network protocol services (IKE). There's no single "patch this one system" fix. It requires coordinated action across IT, infrastructure, and endpoint teams simultaneously.
  • Nation-state and ransomware activity have converged. The same vCenter flaw that gave a suspected China-nexus actor a foothold also led to ransomware deployment. Espionage-motivated actors and financially motivated ones are increasingly using the same access for different goals — sometimes on the same target.
  • AI is now part of the exploitation toolkit. The IKE campaign's use of autonomous, AI-driven attack techniques alongside manual methods is a preview of what vulnerability management is going to look like going forward: faster reconnaissance, faster chaining, less time between disclosure and exploitation.

What to Actually Do About It

If you're responsible for patching, prioritization matters more than trying to fix everything overnight:

  1. Patch vCenter first if you run it. The combination of remote code execution, confirmed APT activity, and ransomware follow-through makes this the highest-consequence flaw of the four.
  2. Check macOS Screen Sharing exposure, especially on any Macs reachable from untrusted network segments, even internal ones.
  3. Review SharePoint authentication configurations, not just patch status — weak authentication bypasses often point to broader configuration drift worth auditing.
  4. Don't treat the IKE flaw as "just a network issue." With AI-assisted exploitation in play, the time between a public PoC and active abuse is shrinking fast.

If your team is stretched thin trying to figure out which of these actually apply to your environment — and how exposed you really are — that's exactly the gap a proper VAPT (Vulnerability Assessment and Penetration Testing) engagement or a configuration review is built to close. Instead of reacting to each new KEV entry one at a time, it maps out where you're actually exposed across endpoints, collaboration tools, and infrastructure before attackers find it for you. CyberCube works with organizations on exactly this kind of prioritized, real-world exposure testing — the difference between patching reactively and knowing where you stand.

The Bigger Pattern Worth Remembering

CISA's KEV catalog exists precisely because "critical" and "actively exploited" are two different risk levels, and this week's additions sit firmly in the second, more urgent category. A CVSS score tells you how bad a flaw could be. A KEV listing tells you it already is.

With AI-assisted attackers, converging nation-state and ransomware activity, and exploitation spanning endpoint to infrastructure, the takeaway isn't "patch these four things." It's that patch management needs to be continuous, prioritized by real-world exploitation data, and treated as a security program — not an occasional fire drill.

Three days isn't a long runway. If any of these four systems are in your environment, now's the time to check.