CISA Flags Critical macOS, SharePoint, vCenter, and Windows IKE Bugs

What happened
CISA has added four more actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, spanning Apple macOS, Microsoft SharePoint, VMware vCenter, and the Microsoft Windows IKE (Internet Key Exchange) component. According to reporting from The Hacker News via feeds.feedburner.com, the macOS flaw (CVE-2026-65400) carries a CVSS score of 9.8 and involves an improper authentication weakness. The other three cover on-prem SharePoint, vCenter Server, and the IKE protocol used by Windows for IPsec VPN key negotiation.
The source article lists the CVE identifiers but does not spell out every affected build and patch level. Before you take action, verify the exact CVE numbers and the vendor-fixed versions for each product against Apple, Microsoft, and Broadcom/VMware advisories — those are the authoritative references CISA points back to.

Why this matters for Pittsburgh SMBs
For a 10 to 200-person business in western PA, this KEV drop hits closer to home than it may look at first glance. Four quick reasons:
- On-prem SharePoint is still everywhere in this market. Law firms, CPA practices, and manufacturers we talk to across Pittsburgh, Cranberry, Robinson, and the Mon Valley frequently keep a SharePoint Server on-prem for matter files, workpapers, or engineering drawings — often because a line-of-business app requires it. These servers are internet-adjacent and have been a favorite ransomware entry point for two years running.
- vCenter is the crown jewel. If an attacker owns vCenter, they own every VM in your rack — file servers, domain controllers, EHR databases, ERP. For the manufacturers and healthcare groups running virtualized workloads in a Southpointe or Downtown colo, this is a "drop everything" patch.
- Windows IKE affects any server terminating IPsec. Site-to-site VPNs between offices, plant floors, or a defense contractor's enclave and a prime's network commonly ride IKE. A pre-auth flaw here is exactly the kind of thing that lands you in an incident-response conversation with your cyber insurer.
- macOS at 9.8 matters for the partner track. Legal, accounting, and creative teams in this region skew heavily Mac. An improper-auth flaw at that severity should be treated as urgent, not "we'll get to it next MDM cycle."
Compliance angle: if you're pursuing CMMC Level 2 as a DoD sub, or you carry HIPAA, SOC 2, or FTC Safeguards obligations, CISA KEV items are effectively the floor for "reasonable" patch timelines. Federal civilian agencies get 21 days under BOD 22-01; auditors and insurers increasingly expect private-sector organizations handling CUI or PHI to move at least that fast. Counting from today (August 19, 2026), that puts you at a September 9, 2026 internal deadline as a reasonable target.
What to do this week
- Inventory exposure first, patch second. Pull an asset list from your RMM and filter for: SharePoint Server (any on-prem version), VMware vCenter Server, Windows Server hosts terminating IPsec/IKE VPNs, and macOS endpoints. If you can't produce that list in under an hour, that's the real finding.
- Match each asset to the specific CVE and fixed build. Don't rely on the summary — pull the Apple security advisory, MSRC entries for the SharePoint and IKE CVEs, and the Broadcom advisory for vCenter. Document the fixed version next to each host before you schedule the change window.
- Prioritize internet-exposed and management-plane systems. Any SharePoint front-end reachable from the public internet, any vCenter accessible outside a dedicated management VLAN, and any Windows host with IKE/500 UDP exposed should be patched or isolated within days, not weeks.
- Compensating controls where you can't patch tonight. Put SharePoint behind a WAF or geo-restrict, lock vCenter to a jump host, restrict IKE peers by source IP at the firewall, and force macOS updates through MDM with a hard deadline.
- Hunt, don't just patch. Ask your SOC or MDR provider to review the last 30 days of logs on these systems for indicators tied to these CVEs — new local admins, unusual scheduled tasks, w3wp child processes on SharePoint, and unexpected vpxd activity on vCenter.
- Confirm backups are clean and offline. Before touching vCenter especially, verify immutable backups exist and can restore. This is the checkpoint that saves the weekend if a patch goes sideways.
- Update your change log and compliance evidence. For CMMC, SOC 2, and HIPAA auditors, the artifact that matters is a dated record showing you identified the KEV entry, assessed exposure, and remediated. Save it now while it's fresh.

How we help
PGH Networks runs patch management, vulnerability scanning, and 24/7 monitoring for SMBs across Pittsburgh's professional services, healthcare, and defense-contractor communities. We track CISA KEV additions daily and map them against each client's actual asset inventory, so the "do we have that?" question is already answered when a bulletin like this drops. If you also want a longer-horizon view — vCIO planning, a Microsoft 365 hardening review, or an AI readiness assessment before you turn on Copilot — we can bundle that into the same conversation.
Talk to us
Call 724.888.7007 or reach out through the contact form and we'll get a technician looking at your exposure this week.
Related reading

Active SharePoint Exploit: What Pittsburgh SMBs Should Do Now
Attackers are exploiting a critical Microsoft SharePoint flaw in the wild. Here is what Pittsburgh SMBs should verify, patch, and monitor this week.

CISA Warns: SharePoint Flaw Now Used in Ransomware Attacks
CISA confirms ransomware crews are exploiting a SharePoint RCE flaw. Here is what Pittsburgh SMBs should patch, verify, and monitor this week.

Microsoft 365 AitM Phishing Is Hunting Your Payroll Inbox
An active Microsoft 365 AitM phishing campaign is hijacking finance and payroll mailboxes at SMBs. Here is what Pittsburgh businesses should do this week.