// Microsoft AzureCRITICAL
CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on August 18, 2026, including CVE-2026-33824 (Windows IKE remote code execution, CVSS 9.8) and CVE-2026-55040 (Microsoft SharePoint authentication bypass, CVSS 9.1). The SharePoint flaw enables unauthenticated attackers to forge authentication tokens and gain administrator access to on-premises SharePoint Server. Rapid7 published a proof-of-concept for CVE-2026-55040 on August 11; exploitation attempts using the PoC were reported within hours. CISA mandated remediation for federal systems by August 21, 2026.
// Get alerts for Microsoft Azure