VYPR
AI Brief2026-08-20· generated Aug 19, 2026

What you need to know today.

CISA adds actively exploited Microsoft, Apple, and VMware flaws to KEV; critical vulnerabilities in Joomla and Mozilla also under attack.

CISA has added a critical Microsoft Internet Key Exchange (IKE) Extension vulnerability, CVE-2026-33824, to its Known Exploited Vulnerabilities (KEV) catalog. This double-free flaw allows remote code execution over a network without authentication. Microsoft has released patches, and organizations are urged to apply them immediately to prevent exploitation. As reported by Cyber Security News, this vulnerability poses a significant risk due to its ease of exploitation and potential impact.

Apple is facing active exploitation of a critical authentication vulnerability in its Screen Sharing service, tracked as CVE-2026-65400. This flaw, addressed in recent macOS updates (macOS Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1), allows network attackers to authenticate without proper authorization. Reports from Help Net Security indicate that attackers have been using this vulnerability in the wild, often to deploy cryptominers on exposed Macs.

VMware vCenter Server is under active attack due to a directory traversal vulnerability, CVE-2026-59310, now listed on CISA's KEV catalog. This critical flaw enables authenticated attackers with network access to execute arbitrary code on the underlying system. Cyber Security News reports that attackers are leveraging this vulnerability to drop JSP webshells, disguised as performance updates, to maintain persistence and control. Immediate patching is crucial as exploitation is widespread.

Mozilla's Firefox and Thunderbird are impacted by critical vulnerabilities, including CVE-2022-26486 and CVE-2022-26485, which have reportedly been exploited in the wild. CVE-2022-26486, a use-after-free flaw in the WebGPU IPC framework, can lead to a sandbox escape. CVE-2022-26485, another use-after-free vulnerability, arises from improper handling of XSLT parameters during processing. Both vulnerabilities affect specific versions of Firefox and Firefox ESR, and users are advised to update to the latest versions to mitigate these risks.

Microsoft SharePoint is experiencing active exploitation of a weak authentication vulnerability, CVE-2026-55040, which has been added to the CISA KEV list. This critical flaw allows unauthenticated attackers to bypass security features over a network. Help Net Security notes that exploitation began shortly after a proof-of-concept (PoC) was released, highlighting the rapid threat posed by publicly available exploit code.

Several critical vulnerabilities have been disclosed in Joomla extensions, including arbitrary file upload, deletion, and PHP code injection flaws. CVE-2026-75949 in J-BusinessDirectory and CVE-2026-74803 in Yootheme's Zoo extension allow unauthenticated attackers to upload or delete arbitrary files. Additionally, CVE-2026-67364 in Balbooa Forms presents a critical pre-authentication PHP code injection risk. These vulnerabilities, detailed by Vypr Intelligence, pose a significant threat to Joomla sites if not patched promptly.

Oracle has released numerous security patches, including fixes for critical vulnerabilities in its Hyperion and Fusion Middleware products. CVE-2026-70921 and CVE-2026-70880 affect Oracle Hyperion Financial Management and Data Relationship Management, respectively, allowing unauthenticated network attackers to compromise the system. CVE-2026-61241 in Oracle Internet Directory (OID) also presents an easily exploitable vulnerability for unauthenticated attackers. As noted by Cyber Security News, these updates are essential for securing Oracle environments.

Synthesized by Vypr AI
KEV Additions: Microsoft, Apple, VMware Exploited; Joomla, Mozilla Under Fire · VYPR