CISA's list that day
18 August 2026
On CISA added 4 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Internet Key Exchange (IKE) Service Extensions, Microsoft SharePoint, Broadcom VMware vCenter and 1 other product. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2026-55040Weak Authentication | Microsoft SharePoint | Patch nowForensic triage required by CISA | 0.70 | ||
| CVE-2026-59310Path Traversal | Broadcom VMware vCenter | Patch nowForensic triage required by CISA; ransomware use, listed within a year | 0.03 | ||
| CVE-2026-65400Improper Authentication | Apple macOS | Patch nowForensic triage required by CISA | 0.02 | ||
| CVE-2026-33824Double Free | Microsoft Internet Key Exchange (IKE) Service Extensions | Patch soon | 0.02 |