PT-2026-78474 · Undefined · Undefined

CVE-2026-65401

·

Published

2026-08-19

·

Updated

2026-08-19

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Four critical CVEs were added to CISA’s KEV catalog today, confirming active exploitation across macOS, SharePoint, vCenter, and Windows IKE. These are not theoretical—expect scanning and payload delivery within hours if not already underway.
Technical Breakdown: - CVE-2026-65400 (CVSS 9.8): Improper authentication in Apple macOS. Allows remote code execution without authentication. No user interaction required. Affects all currently supported macOS versions prior to the latest patch. - CVE-2026-65401 (CVSS 8.8): Remote code execution in Microsoft SharePoint. Requires authenticated user with Site Owner permissions. Likely chained with credential theft or session hijacking. - CVE-2026-65402 (CVSS 9.8): Heap-based buffer overflow in VMware vCenter Server. Unauthenticated remote code execution over the network. vCenter is a crown jewel—this is a critical lateral movement vector. - CVE-2026-65403 (CVSS 8.1): Remote code execution in Microsoft Windows IKE (Internet Key Exchange) extension. Affects Windows Server and Windows 10/11 with IKE enabled. Exploitable via specially crafted VPN packets.
IOCs: None publicly available at this time. CISA has not released proof-of-concept or observed indicators. Do not fabricate detection rules based on speculation.
Defense: - Patch immediately. Prioritize vCenter and macOS if exposed to the internet. - For SharePoint: audit Site Owner accounts and enforce MFA. - For IKE: disable the IKE service on endpoints where VPN is not required, or restrict inbound UDP ports 500/4500 to trusted sources only. - Monitor for unexpected authentication events, especially against vCenter and SharePoint.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-65401

Affected Products

Undefined