# Four Critical CVEs Hit CISA's KEV List as China-Nexus Actors Deploy Ransomware and Backdoors
## The Threat
CISA added four high-severity vulnerabilities to its Known Exploited Vulnerabilities catalog on Tuesday, covering Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft's Internet Key Exchange (IKE) service. All four carry CVSS scores of 9.1 or higher, all four have been patched by their respective vendors, and all four are actively being exploited in the wild. That combination should focus minds immediately.
The most consequential entry from a nation-state perspective is the vCenter path traversal flaw (CVE-2026-59310). A suspected China-nexus APT has been using it to plant backdoors and drop reverse_ssh binaries — the kind of persistent access toolkit that survives reboots, credential rotations, and even partial remediation efforts. In at least one confirmed case, that foothold escalated into a Babuk-derived ransomware deployment. Across the entire campaign, 361 unique victim IPs across 47 countries have been compromised, with heaviest concentration in Germany, the United States, Turkey, Iran, and France.
Meanwhile, the Microsoft IKE double-free vulnerability (CVE-2026-33824) has been claimed by a second Chinese-speaking threat actor running what Palo Alto Networks Unit 42 describes as an AI-enabled autonomous hacking campaign powered by DeepSeek — running parallel to manual exploitation of the same vulnerability. That is a significant operational shift worth paying attention to: adversaries are no longer treating AI as experimental. It is operational, and it is running alongside human operators right now.
## Severity and Impact
| CVE | Product | CVSS | Vector | Attack Complexity | Auth Required | CWE |
|---|---|---|---|---|---|---|
| CVE-2026-65400 | Apple macOS (Screen Sharing) | 9.8 | Network | Low | None | CWE-287 (Improper Authentication) |
| CVE-2026-55040 | Microsoft SharePoint | 9.1 | Network | Low | None | CWE-287 (Improper Authentication) |
| CVE-2026-59310 | Broadcom VMware vCenter | 9.8 | Network | Low | None | CWE-22 (Path Traversal) |
| CVE-2026-33824 | Microsoft IKE Service Extensions | 9.8 | Network | Low | None | CWE-415 (Double Free) |
Every vulnerability here is remotely exploitable with no authentication and low attack complexity. There is no meaningful technical barrier to exploitation — the only real barrier is whether a patch has been applied.
## Affected Products
Apple
Microsoft
Broadcom VMware
Consult each vendor's official security advisory for exact build numbers and version strings, as specific branch coverage varies.
## Mitigations
Immediate priority: patch everything on this list. Federal civilian agencies under BOD 26-04 have until August 21, 2026 — two days from publication. Everyone else should treat that deadline as the floor, not the ceiling.
Beyond patching:
reverse_ssh binaries, unusual persistent service entries, and outbound SSH connections to non-standard ports. Assume compromised vCenter instances may have lateral movement risk across the entire virtualization layer.Network segmentation remains a durable defense: none of these vulnerabilities should be reachable from untrusted network segments. If your vCenter management interface is exposed to the internet or to flat internal networks with no access control, that architectural debt is now being directly weaponized.
## References
---
## HackWire Analysis
The vCenter campaign deserves more attention than it is getting. Path traversal to remote code execution on vCenter is not a lateral movement story — it is a crown-jewel story. vCenter manages the entire virtualization fabric of an enterprise. Compromising it means you effectively own every virtual machine it controls, including security tooling, domain controllers, and backup infrastructure. A Babuk-derived ransomware deployment as the endgame here is almost anticlimactic; the backdoor and reverse_ssh persistence are the real prize, and ransomware may have been deployed selectively as a monetization play or a distraction.
The IKE flaw being actively exploited by a threat actor running an AI-assisted autonomous campaign alongside manual operations is a genuinely new data point. Unit 42's attribution to a Chinese-speaking actor using DeepSeek for autonomous targeting suggests we are past the proof-of-concept phase for AI-augmented offensive operations. The model is apparently being used to identify and sequence attack paths, not just generate phishing lures. Defenders should expect this capability to become more common, more capable, and less distinguishable from human-paced operations over the next 12 to 18 months.
The macOS Screen Sharing flaw being weaponized to drop a Monero miner is the outlier in terms of sophistication, but it reveals something important: opportunistic actors scan for and exploit critical CVEs very quickly after they are made public. Organizations with any macOS fleet — especially those running headless or server-mode macOS instances — should treat unauthenticated remote access services as zero-tolerance exposure. The assumption that "attackers don't target Macs at scale" has not been operationally valid for some time, and this campaign confirms it again.
Patch this week. Hunt on vCenter now.
— HackWire Editorial
## Related Coverage