CISA Flags Four Critical Flaws Under Active Attack — Patch Now
The US Cybersecurity and Infrastructure Security Agency (CISA) has added four critical security flaws to its Known Exploited Vulnerabilities catalog, confirming that attackers are actively exploiting them right now. Among them is a severe authentication weakness in Apple macOS (CVSS score 9.8), meaning it's about as serious as vulnerabilities get.
The affected products—macOS, Microsoft SharePoint, VMware vCenter, and Microsoft's IKE networking protocol—are widely used across businesses of all sizes, including many Australian SMBs that rely on Microsoft 365, SharePoint document sharing, or virtualised server environments. When CISA adds a vulnerability to its KEV catalog, it's a strong signal that real-world attacks are already happening, not just a theoretical risk.
While the technical details of each flaw vary, the common thread is urgency: these aren't vulnerabilities businesses can afford to leave unpatched while they wait for a convenient time. Attackers actively scan the internet for organisations running outdated versions of these products, and small businesses without dedicated IT security staff are often the easiest targets.