CISA Added Four Actively Exploited Flaws to KEV, Including a 9.8 in macOS Screen Sharing
Key takeaways
- CVE-2026-65400 is a CVSS 9.8 authentication bypass letting a same-network attacker reach macOS Screen Sharing without credentials
- CVE-2026-55040 is a CVSS 9.1 SharePoint security feature bypass, exploitable over the network without authentication
- SAP Commerce Cloud's CVE-2026-58231 was exploited within 72 hours of disclosure, and a vCenter flaw is being chained to Babuk-derived ransomware
- Check Point disclosed attackers abusing Microsoft Defender's own signed boot-time driver for kernel-level file and registry operations
CISA has moved four vulnerabilities into its Known Exploited Vulnerabilities catalogue. That designation means one specific thing: these are being used against real targets right now, not theorised about in a write-up.
The CISA KEV August 2026 additions worth knowing by number
- CVE-2026-65400, CVSS 9.8, improper authentication in Apple macOS. An attacker on the same network can authenticate to Screen Sharing without valid credentials. Remote desktop access to a Mac, no password.
- CVE-2026-55040, CVSS 9.1, weak authentication in Microsoft SharePoint, letting an unauthorised attacker bypass a security feature over the network.
Alongside those, SAP Commerce Cloud's CVE-2026-58231 was exploited within 72 hours of public disclosure, and a China-nexus group is chaining a freshly patched VMware vCenter flaw to deploy Babuk-derived ransomware.
The Defender driver trick is the one to watch
Check Point separately disclosed a technique that abuses Microsoft Defender's own signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations.
That is the pattern worth flagging. Attackers are increasingly not bringing their own tooling. They are turning the security software's signed, trusted components against the machine underneath it. A driver that Microsoft ships and signs is not something most defences look at sideways, which is exactly what makes it useful to someone already inside.
What to do this week
Patch macOS and SharePoint first, because network-adjacent authentication bypasses need nobody to click anything. Then check vCenter and SAP Commerce exposure, and review what your endpoint agent is allowed to do at boot.
If you are weighing up how urgent a given score really is, our explainer on how to read a CVSS score covers what the number does and does not tell you, and CISA's three-day patch window explains the deadline federal agencies now work to. August has already been heavy on this front: Oracle shipped 943 security patches in a single quarterly cycle.
KEV is a binding directive for US federal agencies. Everyone else should read it the same way regardless: a list of things confirmed to work.