CISA Flags Four Actively Exploited Bugs in Microsoft, VMware and Apple Products
The US Cybersecurity and Infrastructure Security Agency (CISA) has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming they are being actively used in attacks. The affected products include Microsoft's Internet Key Exchange (IKE) Service, Microsoft SharePoint, Broadcom VMware vCenter, and Apple macOS.
Each vulnerability allows attackers different ways to compromise systems, from bypassing authentication to manipulating file paths, and all are considered serious because they are already being exploited in the wild rather than just theoretical risks. While the KEV Catalog primarily drives patching requirements for US federal agencies, it is widely used by security teams worldwide as a reliable signal of which vulnerabilities deserve immediate attention.
For Australian small businesses, this listing is a useful early warning. If your organisation uses Microsoft SharePoint, VMware vCenter, or Apple devices, checking for and applying available security updates should be a priority, as delays increase the window of opportunity for attackers.