Are you sure every computer, server, VPN service, and development tool your business uses is protected today?
It is a reasonable question. You lock the doors to your St. Louis business when you leave, right? You would not knowingly leave a side entrance propped open overnight.
But an unpatched system can create the same kind of opening: sometimes without any warning.
CISA has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. Four were added on August 18, 2026, and one was added on August 17. That means attackers are not merely discussing these flaws or testing them in a lab. CISA has identified evidence that they are being exploited.
And here is the urgent part: four of the five entries have a listed action due date of August 21, 2026. The Ray vulnerability is due August 20.
The five vulnerabilities at a glance
| CVE | Affected product | Primary risk | CISA date added | CISA action due date |
|---|---|---|---|---|
| CVE-2026-65400 | Apple macOS Screen Sharing | Authentication bypass and unauthorized remote access | August 18, 2026 | August 21, 2026 |
| CVE-2026-55040 | Microsoft SharePoint | Weak authentication and security feature bypass | August 18, 2026 | August 21, 2026 |
| CVE-2026-59310 | Broadcom VMware vCenter | Path traversal leading to arbitrary code execution | August 18, 2026 | August 21, 2026 |
| CVE-2026-33824 | Microsoft IKE Service Extensions | Double-free vulnerability enabling remote code execution | August 18, 2026 | August 21, 2026 |
| CVE-2025-62593 | Ray Project Ray | Browser-assisted code injection and remote code execution | August 17, 2026 | August 20, 2026 |
What BOD 26-04 means for your business
CISA’s Binding Operational Directive 26-04 establishes risk-based deadlines for federal civilian agencies. The most serious KEV situations: particularly internet-exposed systems that can be exploited automatically for total control: can carry a three-day remediation window.
Most other KEV situations fall into longer risk-based timelines, such as 14 or 60 days.
Your small business may not be directly subject to the federal directive. Still, these deadlines are useful warning signals. If CISA gives a vulnerability three days, you should not treat it like an ordinary software update scheduled for next month.
Think of it as a flashing warning light.
1. Apple macOS Screen Sharing : CVE-2026-65400
This vulnerability involves improper authentication in macOS Screen Sharing. In plain English, an attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
That could give an unauthorized person remote access to a Mac’s screen and active session. From there, the attacker may be able to view sensitive information, interact with applications, or use the system as a stepping stone into your business network.
What you should do
- Update every supported Mac to the latest security release offered by Apple.
- Prioritize Macs with Screen Sharing enabled.
- Disable Screen Sharing where it is not required.
- Restrict Screen Sharing to trusted users and controlled networks.
- Review recent remote-access activity for unfamiliar connections.
- If a Mac was exposed or suspicious activity is found, isolate it before investigating.
Apple’s security guidance is available through its macOS security updates, Apple security advisories, and related product notices.

2. Microsoft SharePoint weak authentication : CVE-2026-55040
CVE-2026-55040 affects Microsoft SharePoint and allows an unauthorized attacker to bypass a security feature over the network.
Security researchers have described the issue as a weakness in SharePoint’s token-based authentication process. A forged authentication token may be accepted as legitimate, potentially allowing an attacker to impersonate a SharePoint user or administrator.
Here’s the problem: SharePoint can contain contracts, customer records, financial documents, employee information, and internal procedures. If an attacker can impersonate a privileged account, the risk is much larger than a single stolen file.
What you should do
- Determine whether you use on-premises SharePoint Server, Microsoft 365 SharePoint Online, or both.
- Apply Microsoft’s security updates to affected on-premises SharePoint deployments immediately.
- Verify the resulting SharePoint build numbers instead of assuming the update succeeded.
- Limit direct internet exposure to SharePoint servers.
- Review authentication logs for unusual service-to-service activity.
- Investigate unexpected file access, account changes, or administrator actions.
- Rotate credentials, tokens, and certificates if compromise is suspected.
Follow Microsoft’s CVE-2026-55040 security guidance. Do not assume that a cloud-hosted service and an on-premises server have identical remediation requirements.
3. VMware vCenter path traversal : CVE-2026-59310
A path traversal flaw is like giving someone a building directory and allowing them to walk through doors that should be off-limits. In this case, an attacker with network access to VMware vCenter may be able to use crafted paths to reach files outside the intended directory.
CISA says the flaw could allow arbitrary code execution.
And here’s where it gets scary: vCenter is a management point for virtual machines and other infrastructure. A compromise may affect far more than the vCenter appliance itself.
What you should do
- Identify every VMware vCenter Server, Cloud Foundation, and related deployment.
- Apply the latest Broadcom security updates for your product branch.
- Keep vCenter management interfaces off the public internet.
- Restrict access to trusted administrative networks.
- Review firewall and access-control rules around vCenter and Syslog services.
- Inspect logs for unusual network connections and unexpected file activity.
- Treat an exposed, unpatched vCenter system as potentially compromised until checked.
Broadcom’s official security advisory is available through its support security advisory.

4. Microsoft IKE Service Extensions : CVE-2026-33824
This Microsoft vulnerability is a double-free memory flaw in the Internet Key Exchange, or IKE, Service Extensions.
A double-free error occurs when software attempts to release the same memory allocation more than once. Under the right conditions, that can corrupt memory and allow remote code execution.
The vulnerability is especially concerning on systems handling IKEv2 or IPsec traffic, including certain VPN and server configurations.
What you should do
- Install Microsoft’s April 2026 security update or any later cumulative update.
- Identify Windows systems with IKEv2 or IPsec enabled.
- Block inbound UDP ports 500 and 4500 where IKE is not required.
- Restrict IKE traffic to known VPN or IPsec peer addresses.
- Disable the IKEEXT service only after confirming it is not needed.
- Monitor for unusual IKE traffic, service crashes, or abnormal processes.
- Review internet-facing servers first.
Microsoft’s official details are available in the MSRC advisory for CVE-2026-33824.
5. Ray Project code injection : CVE-2025-62593
Ray is an open-source framework used for distributed computing and artificial intelligence workloads. This flaw can expose developers who run Ray as a local or shared development tool.
The attack path may involve a malicious website, DNS rebinding, and a browser-assisted request. CISA specifically identifies Firefox and Safari as browsers through which developers may be exposed.
You open a webpage without thinking twice. The page interacts with a local Ray endpoint. A request is sent. Code executes on the Ray head node.
That is how an ordinary browsing session can become a development-environment incident.
What you should do
- Upgrade Ray to version 2.52.0 or later.
- Keep Ray dashboards and APIs bound to localhost whenever possible.
- Do not expose Ray management interfaces directly to the internet.
- Place shared Ray environments behind authentication and access controls.
- Use a separate browser profile for development tools.
- Monitor for unexpected requests to Ray API endpoints.
- Investigate unusual jobs, commands, or processes launched by Ray.
- Perform forensic triage if an exposed system was running a vulnerable version.
You can review the Ray Project security advisory and the related security fix.
Your practical next step
Start by creating a short list of affected assets:
- Apple Macs with Screen Sharing enabled
- SharePoint servers and authentication services
- VMware vCenter and virtualization infrastructure
- Windows VPN or IKE-enabled systems
- Developer workstations and servers running Ray
Then patch, restrict access, verify the result, and investigate before moving to lower-priority work.
The goal is not to panic. It is to avoid leaving an unlocked door while attackers are actively checking the neighborhood.
If you need help identifying vulnerable systems, applying updates, reviewing exposure, or investigating suspicious activity, Platinum Web Services can help. We provide personalized cybersecurity solutions, proactive IT management, cloud support, and 24/7 assistance for IT emergencies throughout the St. Louis area.
Your systems do not need to be perfect. They do need to be watched, updated, and protected: especially when CISA tells you attackers are already looking.
Category: CISA Advisories


0 Comments