CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4698

As cited

Copy frozen at (site build).

vulnerabilities

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

The US Cybersecurity and Infrastructure Security Agency (CISA) added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog on Tuesday, indicating active exploitation in the wild. The flaws affect macOS, SharePoint, vCenter, and Microsoft IKE, with CVE-2026-65400 identified as an improper authentication vulnerability in macOS with a CVSS score of 9.8.

Why it matters: Organizations running affected Apple, Microsoft, and VMware products face immediate risk from attackers actively exploiting these flaws; patching should be prioritized today.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog on August 19, 2026, including CVE-2026-65400, an improper authentication flaw in Apple macOS with a CVSS score of 7.1. All four vulnerabilities are confirmed to be exploited in the wild.

Why it matters: Organizations running macOS, SharePoint, vCenter, and systems using Microsoft IKE must prioritize patching these vulnerabilities immediately, as exploitation is already active.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog on August 19, 2026, including CVE-2026-65400, an improper authentication flaw in Apple macOS with a CVSS score of 7.1. All four vulnerabilities are confirmed to be exploited in the wild.

Why it matters: Organizations running macOS, SharePoint, vCenter, and systems using Microsoft IKE must prioritize patching these vulnerabilities immediately, as exploitation is already active.

VendorsMicrosoftAppleVMware
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary