KEV Additions: Windows, macOS, VMware; Joomla, Mozilla Flaws Disclosed
CISA flags actively exploited flaws in Windows, macOS, and VMware, while multiple critical vulnerabilities in Joomla and Mozilla products are disclosed.

CISA has added a critical Microsoft Windows IKE Extension vulnerability (CVE-2026-33824) to its Known Exploited Vulnerabilities catalog. This double-free flaw allows remote code execution over a network and is being actively exploited in the wild, as reported by Cyber Security News. The vulnerability carries a CVSS score of 9.8 and a high exploit prediction score, indicating a significant risk to organizations. Microsoft has released patches, and users are urged to apply them immediately to mitigate the threat.
Apple's Screen Sharing service is under active exploitation due to a critical authentication vulnerability (CVE-2026-65400). This flaw, detailed by Cyber Security News, allows network attackers to authenticate without proper authorization. CISA has added this to its KEV catalog, emphasizing the urgency of patching. Affected versions include macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, and macOS Tahoe 26.6.1. Exploitation has been observed in the wild, with reports of cryptominers being deployed on internet-exposed Macs.
VMware vCenter Server is facing a critical directory traversal vulnerability (CVE-2026-59310) that allows for remote code execution. This vulnerability has been added to CISA's KEV list due to active exploitation, with threat actors reportedly dropping JSP webshells disguised as performance updates, as noted by Cyber Security News. The flaw affects multiple versions of vCenter, including vCenter 7.0, 8.0, and 9.0. Exploitation has been observed shortly after disclosure, highlighting the rapid pace at which vulnerabilities are weaponized.
Mozilla products are impacted by several critical vulnerabilities, including a use-after-free flaw in the WebGPU IPC framework (CVE-2022-26486) and an exploitable use-after-free in XSLT processing (CVE-2022-26485). Both vulnerabilities have been reported as actively exploited in the wild and affect Firefox versions prior to 97.0.2 and Firefox ESR versions prior to 91.6.1. Additionally, a sandbox escape in the Remote Settings Client component (CVE-2026-75874) and multiple internally found bugs in Thunderbird (CVE-2026-74990, CVE-2026-74987) have been disclosed, with some showing evidence of memory corruption.
Tenable Security Center is vulnerable to command injection attacks through multiple vectors. CVE-2026-19682 allows unauthenticated remote attackers to execute arbitrary commands, while CVE-2026-19681 requires authentication and exploits a file upload vulnerability. A third vulnerability, CVE-2026-64879, allows command injection via the audit file upload functionality due to improper sanitization of filenames. These critical flaws, with CVSS scores of 9.9, pose a significant risk of system compromise.
Joomla and its extensions are affected by a significant number of critical vulnerabilities. These include arbitrary file upload and deletion in J-BusinessDirectory (CVE-2026-75949), unauthenticated arbitrary file upload in Zoo (CVE-2026-74803), and pre-authentication PHP code injection in Balbooa Forms (CVE-2026-67364). These flaws, detailed in a Vypr Intelligence report, allow attackers to execute arbitrary code or gain unauthorized access to systems.
Microsoft SharePoint is affected by a critical weak authentication vulnerability (CVE-2026-55040), which allows unauthorized attackers to bypass security features over a network. This vulnerability has been added to CISA's KEV list due to active exploitation following the public release of a Proof of Concept, as reported by Help Net Security. The flaw enables attackers to bypass authentication mechanisms, potentially leading to unauthorized access and further compromise.