York Computer logo York Computer
Managed IT & Security
Cybersecurity News

CISA Flags SharePoint, Windows IKE, and VMware vCenter Flaws Being Actively Exploited

York Computer

On August 18, CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, and three of them sit squarely in tools small businesses use every day: on-premises SharePoint, Windows' IKE service, and VMware vCenter. Federal agencies have until August 21 to patch. Your business should not be far behind — proof-of-concept exploit code is already public for the SharePoint flaw, and attackers are firing it at internet-exposed servers.

What CISA added and why it matters

CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on Tuesday, stating they are being exploited in the wild. Three of the four are directly relevant to Windows-based small businesses:

CVE-2026-55040 (CVSS 9.1) is a weak authentication vulnerability in Microsoft SharePoint that could allow an unauthorized attacker to bypass a security feature over a network. The SharePoint bug chains four weak checks to forge a valid token, and Rapid7 published a full analysis and a public proof-of-concept. Defused researchers observed attackers using the Rapid7 PoC against SharePoint honeypots.

CVE-2026-59310 (CVSS 9.8) is a path traversal vulnerability in Broadcom VMware vCenter that could allow a threat actor with network access to vCenter to execute arbitrary code. If you run virtual servers in-house, vCenter is the crown jewel — a compromise there gives an attacker the keys to every VM on the host.

CVE-2026-33824 (CVSS 9.8) is a double free vulnerability in Microsoft Internet Key Exchange (IKE) Service Extensions. An unauthenticated attacker can send specially crafted packets to trigger the double free, leading to execution of arbitrary code with the privileges of the affected service. IKE is used for VPN tunnels, so any Windows server terminating a site-to-site or remote-worker VPN is in scope.

Why this hits small businesses harder than the enterprise

Large enterprises have dedicated patch teams and 21-day CISA deadlines to meet. Small businesses often don't know they're running SharePoint on-prem until an employee mentions the old intranet, don't know vCenter is exposed until someone opens a firewall rule for a vendor, and don't touch VPN concentrator patches for months at a time.

The CISA KEV catalog lists flaws that attackers already abuse. All four new entries score 9.1 or higher. They affect widely deployed enterprise systems. As a result, the blast radius is large. Attackers don't check company size before scanning — they scan the whole internet and hit whatever answers. A properly run managed IT provider should already be inventorying every internet-facing service, cross-referencing it against the KEV catalog daily, and pushing emergency patches within the same window CISA sets for federal agencies. That's the baseline standard covered under York Computer's managed IT services.

What your MSP should be doing this week

Ask your IT provider — internal or outsourced — three specific questions:

1. Do we run on-premises SharePoint, VMware vCenter, or any Windows server terminating a VPN? If yes, when was CVE-2026-55040, CVE-2026-59310, and CVE-2026-33824 patched, and can you send me the patch confirmation?

2. Is any of that infrastructure reachable from the public internet? vCenter and SharePoint management interfaces should never be exposed — if they are, that's a bigger conversation than one patch cycle.

3. Do we subscribe to the CISA KEV feed and act on it within a defined SLA? Federal agencies must patch by August 21, 2026 — a small business with the same exposure has the same risk on the same timeline.

If your provider can't answer those questions the same day you ask, that is the finding. Businesses with an in-house IT staffer who's stretched thin can layer co-managed IT support on top for 24/7 monitoring and after-hours patching muscle without replacing the person you already have.

What York Businesses Should Do

York County businesses with legacy SharePoint intranets, VMware-based server rooms, or Windows-based VPNs into the office should treat this as a same-week patch job, not a next-quarter project. If nobody at your company can confirm those systems are patched by Friday, that's the call to make to York Computer.

Sources

Worried whether your business is exposed to this? Talk to York Computer.

Managed IT & cybersecurity for York County small businesses.

← Back to all articles