August 30, 2026

4 Actively Exploited Vulnerabilities You Should Patch Now

4 Actively Exploited Vulnerabilities You Should Patch Now

These Aren’t Theoretical Bugs

When CISA adds something to its Known Exploited Vulnerabilities catalog, it means attackers are already using it in the wild. Not “could use it someday.” Right now. That distinction matters a lot when you’re deciding whether to push patches this week or wait until next month’s maintenance window.

Four new entries just landed in the KEV catalog, and if your business runs Microsoft products, VMware infrastructure, or Apple devices, at least one of them probably applies to you.

What Got Added and Why You Should Care

The four vulnerabilities cover Microsoft’s IKE service, SharePoint, Broadcom’s VMware vCenter, and Apple macOS. I’ll give you the plain version of each.

The Microsoft IKE flaw is a double free vulnerability, which is a memory corruption issue that can let an attacker run arbitrary code on a system. If you’re using Windows servers or VPN configurations that rely on IKE for key exchange, this is relevant to you.

The SharePoint weakness involves authentication. A weak authentication vulnerability in SharePoint means someone could potentially access data or functionality they shouldn’t be able to reach. If your team uses SharePoint for document storage or internal collaboration through Microsoft 365, this one deserves attention fast.

The VMware vCenter path traversal bug affects businesses running virtualized infrastructure. If you have an on-premise VMware environment, vCenter is probably managing your virtual machines. A path traversal vulnerability can let an attacker read files or execute code outside of the intended directory. In a virtualized environment, that’s a very bad day.

The Apple macOS improper authentication flaw rounds out the list. Macs in business environments are more common than they used to be, especially in creative, finance, and professional services firms. Don’t assume Apple hardware is immune to this kind of thing.

The Patching Gap Is Where Breaches Happen

Here’s the part that frustrates me when I talk to business owners. Most of these vulnerabilities have patches available. The problem isn’t that there’s no fix. The problem is that patches sit undeployed for weeks because nobody has a clear process for applying them, or because the business doesn’t want the downtime, or because there’s no IT person watching this stuff consistently.

The average time between a patch release and active exploitation of a vulnerability has been shrinking for years. In some cases it’s under a week. Waiting for your quarterly IT review to handle this is genuinely dangerous.

What a Small Business Should Actually Do

First, figure out what you’re running. You can’t patch what you don’t know about. A basic asset inventory, even a spreadsheet, is better than nothing. If you’re using Microsoft 365 and Intune, you can pull device compliance reports and see which machines are missing patches. Windows Update for Business gives you more control over when and how updates roll out across company devices.

Second, prioritize the KEV catalog specifically. CISA publishes it publicly and updates it regularly. If a vulnerability shows up there, treat it as urgent, not routine. The federal government requires agencies to patch KEV items within defined deadlines. Your business doesn’t have to follow federal rules, but the logic is sound.

Third, check your VMware environment if you have one. vCenter vulnerabilities tend to get less attention than Windows issues because they feel more “infrastructure level,” but they can give an attacker control over every virtual machine you’re running. That’s every server, every application, potentially everything.

Fourth, don’t forget the Macs. If your team uses Apple devices for work, those machines need patch management too. It’s a common blind spot, especially when the rest of your environment is Windows-centric.

The Realistic Takeaway

You don’t need to panic, but you do need a process. Knowing what’s in your environment, applying critical patches within days instead of weeks, and having someone actually watching for alerts like this one is the baseline. It’s not complicated in concept, just hard to maintain consistently without dedicated attention.

If your current IT setup doesn’t include regular patch review and vulnerability monitoring, that’s a gap worth closing. Exine works with small and mid-size businesses across NJ and NYC to keep this kind of thing from falling through the cracks.

Tomasz Sobolewski, founder of Exine LLC
About the author
Tomasz Sobolewski
Founder of Exine LLC. Hands-on IT, cybersecurity and backup for growing New Jersey businesses, with 15+ years in the field. The kind of support that knows your systems and picks up the phone.