Threat Brief — 2026-08-19 — Four KEV additions, two due tomorrow
Four CVEs were added to CISA's Known Exploited Vulnerabilities catalog today, with VMware vCenter and Microsoft SharePoint carrying remediation deadlines of 2026-08-21 — giving orgs roughly 48 hours to patch. Windows IKE Extension and macOS Screen Sharing were also formally KEV-listed, corroborating active exploitation we've tracked over the past week. Separately, Huntress reports a 155× year-over-year surge in password-spraying volume, driven by legacy-authentication gaps and incomplete MFA coverage.
Top items
- VMware vCenter path traversal RCE — exploited in the wild, patch due 2026-08-21. CVE-2026-59310KEV·R allows network-adjacent attackers to achieve arbitrary code execution on vCenter via path traversal. CISA added it to the KEV catalog today with a two-day remediation window. Any exposed vCenter instance should be treated as potentially compromised. (src: CISA KEV)
- Microsoft SharePoint weak authentication bypass — exploited in the wild, patch due 2026-08-21. CVE-2026-55040KEV lets an unauthenticated attacker bypass a security feature over the network. Same 48-hour KEV deadline as vCenter. Externally reachable SharePoint farms are the priority target surface. (src: CISA KEV)
- Windows IKE Extension double-free RCE — now formally in CISA KEV (developing). CVE-2026-33824KEV enables remote code execution via the IKE Service Extensions. This vulnerability was first reported as actively exploited on 2026-08-19 (BleepingComputer); today's KEV listing formalises the requirement to remediate. (src: CISA KEV)
- macOS Screen Sharing authentication bypass — now in CISA KEV (developing). CVE-2026-65400KEV allows network attackers to authenticate to Screen Sharing without valid credentials. Active exploitation was first reported 2026-08-14 when the flaw was abused to deploy Monero miners (BleepingComputer); today's KEV addition raises the mandate to patch or disable Screen Sharing on all managed Macs. (src: CISA KEV)
- Password-spraying attacks surge 155× year-over-year. Huntress observed a 155× increase in H1 2026, including one campaign that generated 81 million login attempts in two weeks. Attackers are exploiting legacy authentication endpoints and MFA policy gaps — particularly accounts with no MFA or push-fatigue-susceptible configurations. Audit Conditional Access and disable legacy auth if not already done. (src: BleepingComputer)
Themes
Authentication bypass is the dominant vector this cycle. Three of today's four KEV additions — SharePoint, macOS Screen Sharing, and the password-spraying surge — all hinge on weak or missing authentication controls. The IKE double-free is the outlier (memory-safety RCE), but the pattern reinforces that identity-layer hardening remains the highest-leverage defensive investment.
48-hour patch windows are becoming the norm for critical infrastructure CVEs. Both vCenter and SharePoint carry 2026-08-21 deadlines. Ensure emergency-patch runbooks are current and that change-freeze exceptions for CISA KEV entries are pre-authorised.
