Threat Intelligence

CISA Flags Four Critical Flaws Under Active Attack — Patch Now

The Hacker News · 19 Aug 2026
Key Takeaway If your business uses macOS, SharePoint, or VMware vCenter, check for and apply the latest security updates immediately rather than waiting for your next scheduled maintenance window.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added four critical security flaws to its Known Exploited Vulnerabilities catalog, confirming that attackers are actively exploiting them right now. Among them is a severe authentication weakness in Apple macOS (CVSS score 9.8), meaning it's about as serious as vulnerabilities get.

The affected products—macOS, Microsoft SharePoint, VMware vCenter, and Microsoft's IKE networking protocol—are widely used across businesses of all sizes, including many Australian SMBs that rely on Microsoft 365, SharePoint document sharing, or virtualised server environments. When CISA adds a vulnerability to its KEV catalog, it's a strong signal that real-world attacks are already happening, not just a theoretical risk.

While the technical details of each flaw vary, the common thread is urgency: these aren't vulnerabilities businesses can afford to leave unpatched while they wait for a convenient time. Attackers actively scan the internet for organisations running outdated versions of these products, and small businesses without dedicated IT security staff are often the easiest targets.

vulnerability management patch now macOS security Microsoft SharePoint VMware vCenter

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.