# Four Critical CVEs Hit CISA's KEV List as China-Nexus Actors Deploy Ransomware and Backdoors


## The Threat


CISA added four high-severity vulnerabilities to its Known Exploited Vulnerabilities catalog on Tuesday, covering Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft's Internet Key Exchange (IKE) service. All four carry CVSS scores of 9.1 or higher, all four have been patched by their respective vendors, and all four are actively being exploited in the wild. That combination should focus minds immediately.


The most consequential entry from a nation-state perspective is the vCenter path traversal flaw (CVE-2026-59310). A suspected China-nexus APT has been using it to plant backdoors and drop reverse_ssh binaries — the kind of persistent access toolkit that survives reboots, credential rotations, and even partial remediation efforts. In at least one confirmed case, that foothold escalated into a Babuk-derived ransomware deployment. Across the entire campaign, 361 unique victim IPs across 47 countries have been compromised, with heaviest concentration in Germany, the United States, Turkey, Iran, and France.


Meanwhile, the Microsoft IKE double-free vulnerability (CVE-2026-33824) has been claimed by a second Chinese-speaking threat actor running what Palo Alto Networks Unit 42 describes as an AI-enabled autonomous hacking campaign powered by DeepSeek — running parallel to manual exploitation of the same vulnerability. That is a significant operational shift worth paying attention to: adversaries are no longer treating AI as experimental. It is operational, and it is running alongside human operators right now.


## Severity and Impact


| CVE | Product | CVSS | Vector | Attack Complexity | Auth Required | CWE |

|---|---|---|---|---|---|---|

| CVE-2026-65400 | Apple macOS (Screen Sharing) | 9.8 | Network | Low | None | CWE-287 (Improper Authentication) |

| CVE-2026-55040 | Microsoft SharePoint | 9.1 | Network | Low | None | CWE-287 (Improper Authentication) |

| CVE-2026-59310 | Broadcom VMware vCenter | 9.8 | Network | Low | None | CWE-22 (Path Traversal) |

| CVE-2026-33824 | Microsoft IKE Service Extensions | 9.8 | Network | Low | None | CWE-415 (Double Free) |


Every vulnerability here is remotely exploitable with no authentication and low attack complexity. There is no meaningful technical barrier to exploitation — the only real barrier is whether a patch has been applied.


## Affected Products


Apple

  • macOS (Screen Sharing service) — all versions prior to the August 2026 security update

  • Microsoft

  • SharePoint Server (multiple supported versions) — pre-August 2026 patch
  • Windows (Internet Key Exchange Service Extensions) — pre-August 2026 Patch Tuesday update

  • Broadcom VMware

  • vCenter Server — pre-remediation builds across affected release branches

  • Consult each vendor's official security advisory for exact build numbers and version strings, as specific branch coverage varies.


    ## Mitigations


    Immediate priority: patch everything on this list. Federal civilian agencies under BOD 26-04 have until August 21, 2026 — two days from publication. Everyone else should treat that deadline as the floor, not the ceiling.


    Beyond patching:


  • macOS Screen Sharing: Disable the service entirely on systems where it is not operationally required. If it must remain enabled, enforce network-layer controls to restrict which hosts can reach it.
  • SharePoint: Apply the August cumulative update immediately. Review SharePoint access logs for anomalous authentication events, particularly unauthenticated or low-privilege sessions accessing sensitive libraries.
  • vCenter: Patch and then hunt for indicators of backdoor implants — specifically look for unexpected reverse_ssh binaries, unusual persistent service entries, and outbound SSH connections to non-standard ports. Assume compromised vCenter instances may have lateral movement risk across the entire virtualization layer.
  • Windows IKE: Apply the August Patch Tuesday update. IKE is enabled by default on Windows systems that participate in VPN or IPsec policies — audit exposure broadly.

  • Network segmentation remains a durable defense: none of these vulnerabilities should be reachable from untrusted network segments. If your vCenter management interface is exposed to the internet or to flat internal networks with no access control, that architectural debt is now being directly weaponized.


    ## References


  • [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
  • [Apple Security Updates](https://support.apple.com/en-us/100100)
  • [Microsoft Security Response Center — August 2026 Advisories](https://msrc.microsoft.com/update-guide/)
  • [Broadcom VMware Security Advisories](https://support.broadcom.com/web/ecx/security-advisory)
  • [Palo Alto Networks Unit 42 Threat Intelligence](https://unit42.paloaltonetworks.com/)

  • ---


    ## HackWire Analysis


    The vCenter campaign deserves more attention than it is getting. Path traversal to remote code execution on vCenter is not a lateral movement story — it is a crown-jewel story. vCenter manages the entire virtualization fabric of an enterprise. Compromising it means you effectively own every virtual machine it controls, including security tooling, domain controllers, and backup infrastructure. A Babuk-derived ransomware deployment as the endgame here is almost anticlimactic; the backdoor and reverse_ssh persistence are the real prize, and ransomware may have been deployed selectively as a monetization play or a distraction.


    The IKE flaw being actively exploited by a threat actor running an AI-assisted autonomous campaign alongside manual operations is a genuinely new data point. Unit 42's attribution to a Chinese-speaking actor using DeepSeek for autonomous targeting suggests we are past the proof-of-concept phase for AI-augmented offensive operations. The model is apparently being used to identify and sequence attack paths, not just generate phishing lures. Defenders should expect this capability to become more common, more capable, and less distinguishable from human-paced operations over the next 12 to 18 months.


    The macOS Screen Sharing flaw being weaponized to drop a Monero miner is the outlier in terms of sophistication, but it reveals something important: opportunistic actors scan for and exploit critical CVEs very quickly after they are made public. Organizations with any macOS fleet — especially those running headless or server-mode macOS instances — should treat unauthenticated remote access services as zero-tolerance exposure. The assumption that "attackers don't target Macs at scale" has not been operationally valid for some time, and this campaign confirms it again.


    Patch this week. Hunt on vCenter now.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)