we_are_coded.by CODE · The world, decoded
БГ
CISA

Five holes entered the actively exploited catalogue in two days

CISASecurity

On 17 and 18 August the US agency CISA added five vulnerabilities to its catalogue of known exploited flaws. Inside are macOS, VMware vCenter, SharePoint, a Microsoft service for encrypted connections, and Ray, which sits under part of the world's AI training.

In short
  • Five vulnerabilities enter the KEV catalogue in two days: macOS, vCenter, SharePoint, Microsoft IKE and Ray.
  • Entering that catalogue means exploitation is confirmed, not presumed.
  • Ray is AI infrastructure. If you train or serve models, it is probably underneath you.
Checked on19 August 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

I opened the catalogue and checked all five numbers one by one before writing anything. They are all in there, exactly as the feed gives them.

The CISA KEV catalogue is not a list of discovered holes. Hundreds of those come out every week. Only what has confirmed use in real attacks goes in here. The difference between the two is the difference between could happen and already happening.

The facts: on 18 August 2026 the catalogue takes in CVE-2026-65400 (Apple macOS, improper authentication), CVE-2026-59310 (Broadcom VMware vCenter, path traversal), CVE-2026-55040 (Microsoft SharePoint, weak authentication) and CVE-2026-33824 (Microsoft Internet Key Exchange Service Extensions). On 17 August, CVE-2025-62593 (Ray-Project Ray, code injection) goes in. The deadline for US federal agencies to patch is 21 August for the four and 20 August for Ray. For none of the five does CISA note confirmed use by ransomware groups.

Which of the five I am watching

Ray. The other four matter, but they are the usual suspects: operating system, virtualisation, documents, network service. Every serious admin knows them by heart.

Ray is different. It spreads computation across machines, and that is exactly why it sits under a large share of model training and serving. Code injection there means somebody else's code on the machines holding your weights, your data and your keys.

AI infrastructure is now widespread enough to have its own holes in the actively exploited catalogue.

That is the quiet signal in this whole story. Two years ago a catalogue like this took in routers, mail servers and office suites. Today it takes in a framework for distributed machine learning, because there are enough installations to make it worth an attacker's time.

What the deadline means

The 20 and 21 August dates are an obligation for US federal agencies. For you they are not an obligation. But they are a good measure of how fast somebody who has seen the real attacks thinks you should move.

Three days. That is what you would have been given in their shoes, and that number says more than any severity score.

If you run vCenter or SharePoint, you know what to do. If you run Ray and it never occurred to you that it is part of your perimeter, now is the moment for it to occur to you.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→CISA: Known Exploited Vulnerabilities Catalog (official catalogue)→CVE-2026-65400, Apple macOS (NVD)→CVE-2026-59310, Broadcom VMware vCenter (NVD)→CVE-2026-55040, Microsoft SharePoint (NVD)→CVE-2026-33824, Microsoft IKE Service Extensions (NVD)→CVE-2025-62593, Ray-Project Ray (NVD)
Original: https://wearecoded.com/en/articles/cisa-pet-dupki-aktivna-eksploataciya.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news