The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are listed below - CVE-2026-65400 (CVSS score: 9.8) - An improper authentication vulnerability impacting Apple macOS that could allow an

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert regarding four critical vulnerabilities that are reportedly under active exploitation. These flaws affect Apple macOS, Microsoft SharePoint, VMware vCenter Server, and Microsoft Internet Key Exchange (IKE). CISA has added these vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating that federal civilian executive branch agencies are required to address them within a specified timeframe.
One of the vulnerabilities, identified as CVE-2026-65400 with a CVSS score of 9.8, is described as an improper authentication flaw impacting Apple macOS. This type of vulnerability typically arises when a system fails to correctly verify the identity of a user or process attempting to access a resource. An attacker exploiting such a flaw could potentially bypass authentication mechanisms, gaining unauthorized access to the affected macOS system and its resources.
Another critical flaw affects Microsoft SharePoint, a widely used web-based collaborative platform. While specific details about the SharePoint vulnerability were not provided in the summary, critical flaws in such platforms often involve remote code execution, privilege escalation, or data exfiltration. Exploitation could lead to unauthorized access to sensitive documents, compromise of the SharePoint server, or further lateral movement within an organization's network.
VMware vCenter Server is also impacted by a critical vulnerability under active exploitation. vCenter Server is a centralized management utility for VMware vSphere environments, making it a high-value target for attackers. Flaws in vCenter often involve remote code execution, which could allow an attacker to gain full control over the virtualized infrastructure, impacting numerous virtual machines and critical services.
Finally, a critical vulnerability in Microsoft Internet Key Exchange (IKE) is also being actively exploited. IKE is a protocol used to set up a security association in the IPsec protocol suite, essential for secure VPN connections. Vulnerabilities in IKE could potentially allow attackers to bypass VPN protections, intercept encrypted traffic, or gain unauthorized access to networks protected by IPsec VPNs.
For vulnerabilities of this nature, typical mitigation guidance includes applying vendor-supplied patches immediately. Organizations are also advised to implement strong authentication mechanisms, segment networks to limit the blast radius of a compromise, and monitor systems for unusual activity. Regular security audits and vulnerability scanning can help identify and address potential weaknesses before they are exploited.
The inclusion of these vulnerabilities in CISA's KEV catalog underscores the ongoing threat landscape where critical flaws in widely used enterprise and operating system software are quickly weaponized by threat actors. This highlights the persistent challenge for organizations to maintain a robust patching regimen and proactive security posture to defend against evolving cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]