CISA Flags Four Actively Exploited Vulnerabilities as AI-Driven Reconnaissance Shrinks Patch Windows to Five Days

CISA Flags Four Actively Exploited Vulnerabilities as AI-Driven Reconnaissance Shrinks Patch Windows to Five Days

CISA Flags Four Actively Exploited Vulnerabilities as AI-Driven Reconnaissance Shrinks Patch Windows to Five Days

WASHINGTON — The Cybersecurity and Infrastructure Security Agency added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog on August 18, confirming active exploitation across Apple macOS, VMware vCenter, Microsoft SharePoint, and Windows. The listing is notable not just for the breadth of affected platforms but for the speed at which attackers moved: researchers found exploitation of the VMware flaw began within five calendar days of the patch release, with roughly 95 percent of identified victims compromised within the first 48 hours.

Man in hoodie working on cybersecurity code with multiple screens

The Four CVEs: What Got Hit

The KEV catalog only includes flaws where real-world attacks have been confirmed, not theoretical risk. Getting four listed in a single week, all rated above CVSS 9.0, signals an unusually active exploitation period.

CVE-2026-65400: macOS Screen Sharing Authentication Bypass

A state-management bug in macOS Screen Sharing let attackers on the network connect without a valid password, gaining root access on compromised Macs. The Dutch National Cyber Security Centre confirmed active exploitation in an official advisory, reporting that attackers installed Monero cryptocurrency miners. Apple patched the flaw on August 6 for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. Malwarebytes notes the highest-risk systems are Macs with Screen Sharing's port 5900 reachable from the internet, though internal network exposure remains a real risk if an attacker has already gained a foothold elsewhere.

CVE-2026-59310: VMware vCenter Path Traversal

A directory traversal bug in the vCenter Syslog component allows unauthenticated attackers to write files into privileged system directories, effectively gaining root-level code execution. Broadcom confirmed there is no workaround, only a patch. A China-linked threat group reportedly compromised over 350 vCenter instances across dozens of countries within days of the patch going public, according to incident response documentation cited by security researchers.

CVE-2026-55040: Microsoft SharePoint Weak Authentication

This flaw allows an unauthenticated attacker to forge a valid authentication token against on-premises SharePoint Server, bypassing security controls entirely. It does not affect SharePoint Online in Microsoft 365. A public proof-of-concept exploit is already circulating, making urgent patching essential for on-premises deployments.

CVE-2026-33824: Windows IKE Service Double Free

A memory corruption bug in the Windows service that manages IPsec VPN handshakes lets an unauthenticated attacker send a malformed packet to corrupt memory and potentially execute code. It was patched in Microsoft's April 2026 update cycle, so current Windows systems should already be covered.

The Real Story: Patch Windows Have Collapsed

The number that should concern every security team is not the CVE count but the timeline. Researchers investigating the vCenter flaw found exploitation began within five calendar days of the patch becoming public, and 95 percent of identified victims were compromised within the first 48 hours of active exploitation starting. That is a dramatically shorter window than the one-to-three-week patch-testing cycle most organizations still operate on.

When a vendor publishes a security advisory with a high severity score, that advisory functions as a roadmap for attackers. A "no workaround available, patch immediately" notice tells sophisticated threat actors exactly where to dig. The organizations hit first are not necessarily the highest-value targets. They are the ones still running the vulnerable software a week after the fix shipped.

Hacker in hoodie typing on keyboard with code on screens

AI Is Now Doing the Scouting

Alongside the four CVEs, Palo Alto Networks' Unit 42 threat intelligence team published research documenting the first large-scale example of a threat actor wiring a commercial AI language model into an open-source attack framework to autonomously scout targets. In one recovered session, the operator gave a single high-level instruction. Everything after that — surveying target categories, searching for trending public exploits, evaluating which vulnerability would affect the largest number of internet-facing systems, and identifying more than 647,000 potential targets — happened without further human input.

The autonomous session itself did not result in a successful breach; the group's confirmed compromises came from more conventional manual exploitation. But the capability is now documented, functional, and built from publicly available tools. Unit 42's conclusion: autonomous AI-driven reconnaissance is operationally viable today, not a future risk. That lowers the bar for who can run a wide-scale scanning and targeting operation, and it means unpatched, internet-facing systems get found faster than ever.

For most organizations, this does not mean becoming a personal target of a nation-state group. It means the automated net that used to take days to sweep the internet for vulnerable systems now takes minutes, and an unpatched server does not need to be interesting to get caught in it.

SonicWall SMA1000: A Parallel Campaign

While the CISA KEV additions dominated headlines, a separate exploitation campaign has been accelerating since early August. The INC Ransomware group has emerged as the most active threat actor chaining CVE-2026-15409 (CVSS 10) and CVE-2026-15410 (CVSS 7.2) in SonicWall SMA1000 secure remote access appliances, according to Resecurity. Both flaws were patched on July 14 and added to the KEV catalog the same day, but had been exploited as zero-days since at least June 22.

INC Ransomware has listed new victims on its data leak site from the United States, Australia, the United Arab Emirates, Colombia, and Switzerland over the past several weeks. Resecurity notes that many victims received emails and phone calls from unknown organizations claiming to assist with ransomware issues — pressure tactics that included a domain registered after the exploitation activity through a Chinese registrar and a caller identifying as "Andrew" representing a group of hackers.

What This Means for Defenders

The convergence of five-day exploitation windows and AI-accelerated reconnaissance changes the math for every security team, not just those running the specific affected products.

Patch cadence must shrink. Critical, actively-exploited vulnerabilities need same-week remediation, not same-quarter. This requires either a managed provider actively monitoring advisories and pushing emergency patches, or an internal process that does not wait for a scheduled maintenance window.

Inventory internet-facing assets. A surprising number of organizations do not have a current inventory of which systems, ports, and services are reachable from the outside. A network security audit answers that question directly.

"Patched" does not mean "clean." If systems were exposed during a known exploitation window, patching alone is not enough. Teams need to check for indicators of compromise — unexpected accounts, unfamiliar processes, unusual outbound traffic — before considering an incident closed.

Endpoint monitoring catches what patching misses. Not every flaw gets caught before exploitation. Endpoint detection and response is what flags a compromised machine mining cryptocurrency or phoning home to a command server, even after the initial breach.

The Compliance Angle

Organizations subject to the FTC Safeguards Rule — including car dealerships handling customer financial data — are already required to maintain a written information security program with ongoing risk assessment and timely response to newly identified vulnerabilities. A five-day exploitation window does not fit neatly into an annual compliance review cycle. If an IT provider cannot say whether any system was exposed during an active exploitation window for a KEV-listed vulnerability, that gap is worth closing before an examiner or a breach forces the question.


Sources: CISA Adds Four Known Exploited Vulnerabilities to Catalog, Palo Alto Networks Unit 42: Autonomous AI Cyber Attack Campaign, Resecurity: INC Ransomware and SonicWall SMA Exploit Chain

Internal links: Cybersecurity, AI

Keywords: CISA, KEV catalog, vulnerability management, AI-driven reconnaissance, ransomware, SonicWall, INC Ransomware, patch management, macOS, VMware, SharePoint, Windows

← Back to Home