CISA's list that day

18 August 2026

On CISA added 4 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Internet Key Exchange (IKE) Service Extensions, Microsoft SharePoint, Broadcom VMware vCenter and 1 other product. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2026-55040Weak AuthenticationMicrosoft SharePointPatch nowForensic triage required by CISA0.70
CVE-2026-59310Path TraversalBroadcom VMware vCenterPatch nowForensic triage required by CISA; ransomware use, listed within a year0.03
CVE-2026-65400Improper AuthenticationApple macOSPatch nowForensic triage required by CISA0.02
CVE-2026-33824Double FreeMicrosoft Internet Key Exchange (IKE) Service ExtensionsPatch soon0.02