Hackers exploit critical VMware vCenter and Windows bugs

CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog on August 18, and all four carry critical severity scores. The catalog is not a patch advisory list. CISA adds an entry only when it has evidence that attackers are using the flaw in real intrusions, so the practical message is that every one of these is being exploited right now.

Two of the four have already appeared in our coverage. The other two have not, and one of them sits on the infrastructure that runs entire virtual server estates.

A traversal bug that reaches vCenter

CVE-2026-59310 affects Broadcom's VMware vCenter, the management console administrators use to run fleets of virtual machines. The National Vulnerability Database describes it as a directory traversal vulnerability in the Syslog server, and says an attacker with network access to vCenter may exploit it to execute arbitrary code. NVD scores it 9.8 out of 10.

Broadcom disclosed the flaw at the end of July, and we wrote it up then as one of a set of critical vCenter bugs that could hand over virtual server fleets. What changed on August 18 is that somebody is now using it. A vCenter compromise is rarely the end of an intrusion. It is the point at which an attacker stops needing to move from host to host.

Windows IKE is the quiet one

CVE-2026-33824 is a double free, a memory-handling bug where the same block of memory is released twice, in the Windows IKE extension. That is the component that negotiates keys for IPsec VPN connections. NVD's summary is blunt: it allows an unauthorized attacker to execute code over a network. It also scores 9.8, and it has been public since April 14.

One number set this one apart long before this week. Its EPSS score, the industry's estimate of how likely a flaw is to be exploited in the next 30 days, stands at 0.56. The other three entries in this batch sit between 0.005 and 0.04. The forecast on the IKE bug was loud, and it has now been borne out.

Two we have already reported

CVE-2026-55040 is the SharePoint weak-authentication flaw that lets an unauthorized attacker bypass a security feature over the network, rated 9.1. We covered attacks on it two days ago, and the KEV listing is CISA formalizing what was already visible.

CVE-2026-65400 is the macOS authentication flaw that lets an attacker on the network authenticate to Screen Sharing, rated 9.8. Apple fixed it in macOS Sequoia 15.7.9, Sonoma 14.8.9 and Tahoe 26.6.1. We reported the in-the-wild abuse of it on the same day.

Patch the exposed ones first

For US federal civilian agencies, the listing triggers Binding Operational Directive 26-04, which tells them to prioritize rapid remediation of high-risk KEV entries on publicly exposed assets that would give an attacker total control of the asset, and to defer lower-risk work. The directive also sets an expectation that agencies check whether a system was compromised before the patch was applied. That is the right instinct for anyone reading this, federal or not: on a flaw that has already been exploited, patching closes the door but does not evict whoever came through it.

CISA published the addition in its August 18 alert. The alert names the four CVEs and the exploitation-evidence standard, and says nothing about how the attacks work. The vendor advisories from Microsoft, Broadcom and Apple carry the technical detail and the fixed versions.

Everyone outside the federal government is outside the directive's scope, but nobody is outside the attackers' scope. Internet-facing vCenter and SharePoint deserve attention before the end of the week.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions