Government Advisory

CISA Flags Four Actively Exploited Bugs in Microsoft, VMware and Apple Products

CISA · 18 Aug 2026
Key Takeaway If your business uses Microsoft, VMware or Apple products, check for and apply the latest security patches immediately, as these flaws are already being exploited by attackers.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming they are being actively used in attacks. The affected products include Microsoft's Internet Key Exchange (IKE) Service, Microsoft SharePoint, Broadcom VMware vCenter, and Apple macOS.

Each vulnerability allows attackers different ways to compromise systems, from bypassing authentication to manipulating file paths, and all are considered serious because they are already being exploited in the wild rather than just theoretical risks. While the KEV Catalog primarily drives patching requirements for US federal agencies, it is widely used by security teams worldwide as a reliable signal of which vulnerabilities deserve immediate attention.

For Australian small businesses, this listing is a useful early warning. If your organisation uses Microsoft SharePoint, VMware vCenter, or Apple devices, checking for and applying available security updates should be a priority, as delays increase the window of opportunity for attackers.

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.