That April Windows update you skipped? Hackers are exploiting it now
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about four security vulnerabilities that are being exploited by attackers in the wild. CISA has added the vulnerabilities to its catalog of Known Exploited Vulnerabilities (KEV). Microsoft Windows and SharePoint, VMware vCenter, and Apple macOS are affected.
Inclusion in the KEV catalog sends an important signal: CISA doesn’t simply list every known vulnerability out there, but only those for which there is concrete evidence of active exploitation by attackers. The agency points out that such vulnerabilities are among the most commonly used attack vectors and pose a significant risk.
For home users, this means that if a security update is available for their device, it should be installed as soon as possible. Organizations and system administrators should also check whether affected systems are accessible via the internet and whether there are any indications that an attack has already taken place on vulnerable devices.
Microsoft IKE: Critical vulnerability enables code execution
The first vulnerability is designated CVE-2026-33824 and affects the Internet Key Exchange (IKE) service extensions in Windows. It’s caused by a “double-free” error, where a memory block can be freed multiple times under certain conditions.
The vulnerability is classified as critical, with a CVSS score of 9.8 out of 10. An unauthenticated attacker can exploit it over the network and thereby execute their own code on an affected system.
Microsoft already patched this vulnerability with its April security update. Its inclusion in the CISA KEV catalog now indicates that this risk is no longer merely theoretical—anyone who hasn’t yet installed the April Windows updates should do so ASAP. It affects various versions of Windows 10, Windows 11, and Windows Server.
Microsoft SharePoint: Attackers can bypass security feature
Microsoft SharePoint’s vulnerability CVE-2026-55040 allows unauthenticated attackers to bypass a security feature over the network. Microsoft has rated the vulnerability as critical, with a CVSS score of 9.1.
Affected systems include SharePoint Enterprise Server 2016, SharePoint Server 2019, and the Subscription Edition. Fixed builds are already available for the respective versions.
SharePoint has been the target of attacks on several occasions this year. Administrators should therefore not only address this specific vulnerability but also ensure, as a general rule, that their SharePoint installations are always up-to-date with the latest patches.
According to available reports, a publicly accessible exploit for CVE-2026-55040 was already available before it was included in the CISA catalog. This puts additional pressure on admins of unpatched systems.
VMware vCenter: Path traversal vulnerability being exploited
VMware vCenter’s vulnerability CVE-2026-59310 lies within the syslog server and enables a path traversal attack. An attacker with network access to vCenter can exploit the vulnerability to access files outside intended directories and subsequently execute arbitrary code.
This vulnerability is classified as critical with a CVSS score of 9.8. Certain versions of VMware vCenter, VMware Cloud Foundation, and vSphere Foundation are affected. For vCenter, different patched versions apply depending on the major version.
Security experts have known about CVE-2026-59310 since the end of July, and reports of active attacks emerged as early as the beginning of August. Attackers are said to have attempted to establish a persistent presence within affected VMware environments, and there have also been reports of ransomware attacks in isolated cases.
This vulnerability is especially relevant for organizations because vCenter plays a central role in the management of virtualized IT environments. A compromised vCenter server can have far-reaching consequences for the systems connected to it.
Apple macOS: Screen sharing can be used without a password
The fourth major vulnerability affects Apple systems. CVE-2026-65400 is found in macOS’s screen sharing feature. Under certain conditions, an attacker on the network can bypass authentication and log in to Screen Sharing without valid credentials. Apple has resolved the issue with improved status management.
Apple patched the vulnerability on August 6th with macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9. The original CVSS score was 7.1. Following reports of active exploitation, the vulnerability is now rated as significantly more critical in some databases.
This vulnerability is especially relevant for Macs where Screen Sharing is enabled and accessible from the network. According to reports, the vulnerability has been exploited to install malware on compromised Macs for mining the cryptocurrency Monero.
What does CISA’s warning mean for you?
Although these four vulnerabilities primarily affect enterprise and server environments, CVE-2026-65400 is also relevant to ordinary Mac users. The key factor in each case is whether the affected feature or software is in use and whether the system has already been updated.
You should therefore:
- Update Windows and Windows Server to the latest version.
- Check SharePoint installations and bring them up to their latest available security updates.
- Update VMware vCenter systems to their latest versions.
- Update Macs to at least macOS Sonoma 14.8.9, Sequoia 15.7.9, or Tahoe 26.6.1.
- For affected systems, also check for any suspicious login attempts, unknown users, unusual processes, or other signs of compromise.
Note that when it comes to vulnerabilities included in CISA’s KEV catalog, simply installing a security patch is not always sufficient. If a system has already been compromised, the attacker may have gained permanent access before the update was installed.
Also, inclusion in the KEV catalog doesn’t mean that every Windows PC, Mac, or server is automatically at risk. It does mean, however, that the vulnerabilities in question are being actively exploited and should no longer be regarded as purely theoretical security risks.