Four more actively exploited security flaws were added to the US Cybersecurity and Infrastructure Security Agency's official watch list this week, affecting widely used business software including Microsoft SharePoint, VMware vCenter and Apple macOS.
- What it is: CISA confirmed real-world attacks exploiting a SharePoint authentication weakness, a VMware vCenter path traversal bug, an Apple macOS authentication flaw, and a Microsoft network security (IKE) vulnerability.
- Who is affected: Any business running on-premises SharePoint servers, VMware virtual infrastructure, or Apple devices without the latest security updates.
- The risk: These vulnerabilities let attackers bypass authentication or gain unauthorised access without needing a user to click anything.
- What to do: Apply vendor patches immediately if you run any of the affected products. If you are unsure whether your systems are exposed, ask your IT provider to check.
If your business runs SharePoint on-premises, VMware, or manages Apple devices, we recommend confirming patches are applied this week rather than waiting for the next scheduled maintenance window.