Microsoft Internet Key Exchange · Apple macOS · Red Hat Build of Keycloak
Date: 2026-08-19 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership
Executive Summary
CISA added four vulnerabilities to the KEV catalog on 2026-08-18, including CVE-2026-33824 (Microsoft IKE double-free RCE, deadline 2026-08-21) and CVE-2026-65400 (Apple macOS Screen Sharing improper authentication, confirmed exploited, deadline 2026-08-21). A new Python implant framework, TWINLOOT, abuses SharePoint and Teams for C2. Clop has been linked to a custom web shell targeting PTC Windchill/FlexPLM servers. Oracle released a large batch of critical Helidon Fusion Middleware patches, and Red Hat patched a critical Keycloak authentication bypass.
Critical Vulnerabilities
CVE-2026-33824 — Microsoft Internet Key Exchange (IKE) Service Extensions (Double-Free RCE)
- Severity: Not yet assigned (CWE-415 double-free)
- EPSS: Not yet scored; CISA KEV confirmed active exploitation
- Technical detail: A double-free memory corruption vulnerability in the Windows IKE Service Extensions component enables remote code execution. IKE is a core component of Windows IPsec VPN infrastructure, making this broadly relevant to enterprise environments using Windows-based VPN gateways or site-to-site IPsec tunnels. Network-accessible attack vector increases exposure significantly.
- Exploitation status: Actively exploited — CISA KEV added 2026-08-18.
- Remediation: Apply August 2026 Patch Tuesday updates immediately. CISA KEV deadline: 2026-08-21. Restrict IKE/IPsec management interfaces to trusted networks; monitor for anomalous IKE negotiation traffic.
CVE-2026-65400 — Apple macOS (Screen Sharing / Improper Authentication)
- Severity: Not yet assigned (CWE-287)
- EPSS: Not yet scored; CISA KEV confirmed active exploitation
- Technical detail: An improper authentication vulnerability in macOS Screen Sharing allows a network-adjacent attacker to authenticate to Screen Sharing without valid credentials. Heise Security reports active exploitation in the wild. The flaw was patched approximately two weeks ago in a prior Apple update cycle; organizations that have not yet deployed that patch are exposed to remote takeover of macOS endpoints.
- Exploitation status: Actively exploited — CISA KEV added 2026-08-18. Heise Security confirms exploit activity.
- Remediation: Apply macOS 26.6.2 (or the relevant patched build) immediately via MDM. CISA KEV deadline: 2026-08-21. Disable Screen Sharing on systems where it is not required.
CVE-2026-18963 — Red Hat Build of Keycloak (Unauthenticated Credential Reset Bypass)
- Severity: CVSS 9.1
- EPSS: 0.0 (newly published)
- Technical detail: A flaw in the
reset-credentialsflow ofkeycloak-servicesallows an unauthenticated attacker to bypass the credential reset process. Keycloak is the identity and access management backbone for many European enterprise and government deployments. Successful exploitation could allow account takeover without prior authentication, affecting all applications federated through the vulnerable Keycloak instance. Affects Red Hat Build of Keycloak 26.4 and 26.6. - Exploitation status: No confirmed in-the-wild exploitation; CVSS 9.1 unauthenticated auth bypass in a widely deployed IAM platform warrants urgent treatment.
- Remediation: Upgrade to Red Hat Build of Keycloak 26.6.6-1 / 26.6-12 or 26.4.15-1 / 26.4-23. Audit Keycloak reset-credentials flows and review recent password reset activity for anomalies.
CVE-2026-21582 — Atlassian Crowd Data Center (Broken Authentication / Session Management)
- Severity: CVSS 8.8
- EPSS: 0.0 (newly published)
- Technical detail: A broken authentication and session management vulnerability introduced in Crowd Data Center 7.2.1 allows session-related attacks against the centralized SSO platform. Crowd is widely used in enterprise environments to provide SSO across Atlassian and third-party applications; compromise of Crowd can cascade to all integrated services. Network-exploitable with no confirmed exploitation yet.
- Exploitation status: No confirmed exploitation; high severity in a critical SSO component.
- Remediation: Apply the Atlassian security patch for Crowd Data Center 7.2.1. Review Crowd session logs for anomalous authentication patterns.
CVE-2026-24301 — Microsoft Copilot Web (Command Injection / Information Disclosure)
- Severity: CVSS 8.8
- EPSS: 0.0 (newly published)
- Technical detail: A command injection vulnerability in Microsoft Copilot Web allows an unauthorized network attacker to disclose information. Varonis Threat Labs separately disclosed three related vulnerabilities (“CoSnitch”) in Microsoft Copilot Personal that enable single-click data exfiltration from connected apps via a crafted link and an undocumented URL parameter. These flaws are particularly relevant for organizations using Copilot with broad data connector integrations (M365, CRM, etc.).
- Exploitation status: No confirmed exploitation; proof-of-concept details published by Varonis.
- Remediation: Apply Microsoft patches for Copilot Web. Review Copilot connector permissions and enforce least-privilege data access. Monitor for anomalous Copilot session activity.
ONGOING:
CVE-2026-59310(VMware vCenter): STATUS CHANGE — CISA KEV deadline now 2026-08-21 (previously 2026-08-25 per prior KEV entry); China-nexus APT exploitation confirmed — patch immediately.CVE-2026-55040(SharePoint): STATUS CHANGE — CISA KEV deadline now 2026-08-21; active exploitation confirmed — apply July 2026 Patch Tuesday.CVE-2025-62593(Anyscale Ray): CISA KEV deadline was 2026-08-20 — verify patch applied.CVE-2026-69414(Microsoft Defender ShieldBreak): Unpatched zero-day — monitor MSRC, enforce least privilege.CVE-2026-19478(GitLab): Unauthenticated project deletion — upgrade to patched release.CVE-2026-15748(Forminator Forms): CVSS 9.8 unauthenticated RCE — update immediately.CVE-2026-47686/CVE-2026-47698(vm2): CVSS 9.9/9.8 sandbox escapes — upgrade to 3.11.6.CVE-2026-68820(Windows AFD/Lazarus): CISA KEV deadline 2026-08-25 — apply August Patch Tuesday.CVE-2026-48907(Joomla JCE): Public Metasploit module — treat unpatched as compromised.CVE-2026-18438(Templately): EPSS 0.98 RCE — update immediately.CVE-2026-15826(User Profile Builder): EPSS 0.81 auth bypass — update immediately.CVE-2026-58231(SAP Commerce Cloud): Active exploitation — patch and initiate IR review.CVE-2026-63077(JetBrains TeamCity): Actively exploited — upgrade to 2026.1.3.CVE-2026-0257(PAN-OS GlobalProtect): Qilin ransomware exploitation — patch immediately.CVE-2026-16232(Check Point SmartConsole): Actively exploited — treat unpatched as compromised.CVE-2026-8037(Progress Kemp LoadMaster): Ransomware exploitation — patch immediately.
European Advisories
BSI — New Advisories (2026-08-18):
WID-SEC-2026-2886 (GeoServer — kritisch): A new BSI advisory covers a critical unauthenticated SQL injection vulnerability in GeoServer with potential for remote code execution. GeoServer is widely deployed in European public sector and geospatial organizations. Apply the latest GeoServer update immediately; restrict public access to GeoServer endpoints where possible.
WID-SEC-2026-2884 (Citrix ShareFile StorageZones Controller — hoch): Multiple vulnerabilities enabling arbitrary code execution and data manipulation. Organizations using on-premises ShareFile StorageZones should apply the Citrix patch immediately.
WID-SEC-2026-2883 (Wazuh — hoch): Multiple vulnerabilities including SQL injection, RCE, and information disclosure in the Wazuh SIEM/XDR platform. Apply the latest Wazuh update; note that compromise of a SIEM platform has significant detection-evasion implications.
WID-SEC-2026-2880 (Roundcube Webmail — hoch): Multiple vulnerabilities including RCE, privilege escalation, and XSS. Roundcube is widely used in European organizations and government entities. Apply the latest Roundcube update immediately.
WID-SEC-2026-2882 (GitLab — hoch): Covered in Critical Vulnerabilities (CVE-2026-19478).
WID-SEC-2026-2872 (Apple macOS/iOS/iPadOS — hoch): Covered in Critical Vulnerabilities (CVE-2026-65400).
WID-SEC-2026-2878 (JetBrains PyCharm — hoch): Multiple RCE vulnerabilities in PyCharm. Apply the latest JetBrains update; relevant for developer workstations.
WID-SEC-2026-2869 (Redis — hoch): Multiple vulnerabilities including potential RCE, impersonation, and memory corruption. Apply Redis security updates.
WID-SEC-2026-2870 (SuiteCRM — hoch): Authenticated SQL injection. Apply the SuiteCRM patch; review for signs of exploitation in CRM audit logs.
WID-SEC-2026-2871 (HP Web JetAdmin — hoch): Unauthenticated file manipulation. Apply HP patch; restrict Web JetAdmin access to management networks.
BSI also published updates for Linux Kernel (multiple advisories), vm2 (covered in Critical Vulnerabilities), Microsoft Windows Products, HAProxy, Rsync, GStreamer, Red Hat Enterprise Linux, and ffmpeg — apply vendor patches per standard cycle.
Active Threats and Campaigns
NEW — TWINLOOT Python Implant (SharePoint/Teams C2): Ontinue researchers disclosed a previously undocumented modular Python implant framework, TWINLOOT, that routes its entire C2 infrastructure through Microsoft SharePoint Online and Teams. The framework is PyArmor-hardened and designed to blend with legitimate M365 traffic, making network-layer detection difficult. Organizations should review SharePoint and Teams audit logs for anomalous file access patterns and automated API calls from non-standard clients. (The Hacker News)
NEW — Clop Custom Web Shell (PTC Windchill/FlexPLM): Clop ransomware has deployed a custom Java web shell specifically engineered for PTC Windchill PLM and FlexPLM servers, with built-in credential decryption and file enumeration capabilities. Organizations in manufacturing, engineering, and supply chain sectors using these platforms should treat unpatched or internet-exposed instances as potentially compromised and initiate threat hunting. (Bleeping Computer)
NEW — MLflow SSRF Active Exploitation (Cloud Credential Theft): Active scanning and exploitation of a critical SSRF vulnerability in MLflow is being observed in the wild, with attackers targeting cloud credentials and secrets from ML infrastructure. Organizations running MLflow in cloud environments should patch immediately and audit cloud credential stores for unauthorized access. (The Hacker News)
NEW — “City Forum” Campaign (Salesforce/ServiceNow Scraping): A single threat actor infrastructure (IP 158.220.87.79) has been systematically scraping Salesforce and ServiceNow customer portals across multiple industries since 2025. Organizations using these platforms should audit portal access logs for requests from this IP and review data exposure. (The Hacker News)
NEW — StubMaker RubyGems Typosquatting: 16 typosquatted RubyGems packages deploying a Windows-based information stealer targeting browser credentials and crypto wallets. Audit Ruby/Gem dependencies in CI/CD pipelines and developer environments. (The Hacker News)
ONGOING — Cavern C2 (Iranian APT): No new developments; review DNS logs for tunneling anomalies. ONGOING — Azure Account Records Claim (TheHatman): Unit 42 published updated guidance on mitigating large-scale Microsoft Entra credential attacks. Enforce MFA and review Entra sign-in logs. (Unit 42) ONGOING — Clop / Shell, Philips, GE: No new developments beyond previously reported confirmed investigation status.
Security News and Context
- Ransomware extortion scheme “Ransom Busters”: A ransomware affiliate is emailing victim organizations claiming to delete stolen data from ransomware group servers for $20,000–$60,000 — treat as a secondary extortion scam, not a legitimate recovery service. (The Hacker News)
- AI “mind virus” propagation research: Anthropic/EPFL researchers demonstrated self-propagating prompt injection payloads spreading between AI agents via shared system prompt files — relevant for organizations deploying multi-agent AI pipelines. (The Hacker News)
- Microsoft removing WMIC: Microsoft is removing the WMIC LOLBin from Windows 11 24H2/25H2 builds, reducing a commonly abused attacker tool. (Bleeping Computer)
Recommended Actions
CVE-2026-33824(Microsoft IKE): Apply August 2026 Patch Tuesday immediately — CISA KEV deadline 2026-08-21. Restrict IKE management interfaces.CVE-2026-65400(Apple macOS Screen Sharing): Deploy macOS 26.6.2 via MDM — CISA KEV deadline 2026-08-21. Disable Screen Sharing where not required.CVE-2026-59310(VMware vCenter): KEV deadline moved to 2026-08-21 — patch immediately if not already done.CVE-2026-55040(SharePoint): KEV deadline moved to 2026-08-21 — apply July 2026 Patch Tuesday.CVE-2026-18963(Keycloak): Upgrade to patched build; audit recent password reset activity.- GeoServer (
WID-SEC-2026-2886): Apply latest update; restrict public endpoint access. - Roundcube / Wazuh / Redis: Apply vendor patches; Wazuh compromise has SIEM-evasion implications — prioritize.
- TWINLOOT: Audit SharePoint and Teams API access logs for anomalous automated activity.
- MLflow SSRF: Patch immediately; audit cloud credential stores for unauthorized access.
- Continue remediation of previously reported items:
CVE-2025-62593(Ray — deadline 2026-08-20),CVE-2026-68820(Windows/Lazarus — deadline 2026-08-25),CVE-2026-69414(Defender ShieldBreak — no patch),CVE-2026-19478(GitLab),CVE-2026-15748(Forminator),CVE-2026-47686/CVE-2026-47698(vm2),CVE-2026-58231(SAP),CVE-2026-63077(TeamCity),CVE-2026-0257(PAN-OS),CVE-2026-16232(Check Point).