Microsoft: 2 Actively-Exploited Flaws Added to CISA KEV
Key findings • CISA added two actively-exploited Microsoft vulnerabilities to its KEV catalog. • CVE-2026-33824 and CVE-2026-55040 are confirmed under active exploitation. • No ransomware…

Key findings
- CISA added two actively-exploited Microsoft vulnerabilities to its KEV catalog.
- CVE-2026-33824 and CVE-2026-55040 are confirmed under active exploitation.
- No ransomware association is currently indicated for these flaws.
- Immediate patching is critical for all affected Microsoft systems.
- Federal agencies must adhere to CISA's KEV remediation deadlines.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert, adding two Microsoft vulnerabilities, CVE-2026-33824 and CVE-2026-55040, to its Known Exploited Vulnerabilities (KEV) Catalog. This addition on August 18, 2026, signifies that these flaws are under active exploitation in the wild, posing a significant risk to organizations that have not yet applied necessary patches. The KEV catalog serves as a critical resource, mandating federal civilian executive branch (FCEB) agencies to remediate these vulnerabilities by specific deadlines to protect against ongoing threats.
The newly cataloged vulnerabilities include:
- **CVE-2026-33824**: An actively exploited Microsoft flaw.
- **CVE-2026-55040**: Another actively exploited Microsoft flaw.
While specific details regarding the nature of these exploits are not publicly detailed in the KEV entry, their inclusion confirms that malicious actors are successfully leveraging these weaknesses to compromise systems.
There is no indication that either CVE-2026-33824 or CVE-2026-55040 are currently associated with ransomware campaigns, according to the available CISA KEV data. However, active exploitation of any vulnerability can serve as an initial access vector for a wide range of malicious activities, including data exfiltration, system disruption, and the eventual deployment of ransomware.
Organizations, particularly FCEB agencies, are strongly advised to prioritize the immediate patching of these vulnerabilities. CISA's KEV catalog provides specific remediation due dates, and all affected entities should consult the catalog for the latest guidance. Proactive patching and robust vulnerability management practices are essential to mitigate the risk posed by these actively exploited flaws and to maintain a strong security posture against evolving cyber threats.
CISA has officially added CVE-2026-55040, a critical authentication bypass vulnerability affecting on-premises Microsoft SharePoint Server, to its Known Exploited Vulnerabilities (KEV) catalog. This inclusion signifies that the vulnerability is actively being exploited in the wild, and CISA has mandated that federal agencies patch it by August 21, 2026. The flaw allows unauthenticated attackers to forge JSON Web Tokens, enabling them to impersonate users and gain unauthorized access to sensitive data and administrative functions.