
Critical Bugs Being Exploited Now in IKE, SharePoint, vCenter, and macOS
Multiple critical security flaws across Apple macOS, Microsoft SharePoint, VMware vCenter, and Microsoft's Internet Key Exchange (IKE) are under active exploitation, posing serious risk to websites, servers, and enterpri…
A new security alert from The Hacker News reports that critical vulnerabilities in four widely used software products are being actively exploited, meaning attackers are already using these weaknesses in real attacks. The affected products are Apple macOS, the operating system that runs on Mac computers; Microsoft SharePoint, a web-based collaboration and document management platform often used for internal websites and file sharing; VMware vCenter, a centralized management tool that controls multiple virtual servers from one place; and Microsoft's Internet Key Exchange (IKE), a protocol used to set up encrypted virtual private network (VPN) connections. The presence of active exploitation leaves very little time for organizations to patch before they become victims.
For website owners and businesses, SharePoint is especially concerning because it frequently sits on the public internet or hosts sensitive internal portals. A vulnerable SharePoint server can allow an attacker to read or download confidential documents, inject malicious code into pages that visitors see, or gain full control of the underlying server. Since SharePoint is often connected to other company systems through single sign-on, a single compromise can quickly spread to email, file storage, and customer databases. The same risk applies to any web hosting environment that runs SharePoint as part of a larger intranet or extranet, because a hacked SharePoint site can be used to distribute malware to every visitor.
VMware vCenter is equally critical for hosting providers and IT teams. vCenter acts as the control panel for virtual servers, which are software-based computers that run multiple independent systems on a single physical machine. If an attacker takes over vCenter, they can create, delete, or modify virtual machines, steal data from every hosted server, and move laterally across the entire virtual infrastructure. This is a nightmare scenario for managed hosting companies and cloud providers, because a single compromised vCenter account can expose hundreds or thousands of customer websites at once. Active exploitation means attackers are already scanning for internet-facing vCenter installations and breaking in where patches have not been applied.
macOS and IKE vulnerabilities also deserve immediate attention. macOS is widely used by web developers, system administrators, and everyday business users, and a critical macOS flaw can let attackers run malicious programs or steal sensitive files on Mac computers. The IKE protocol is used by VPN software to automatically negotiate encrypted connections between devices, so a flaw in IKE can allow an attacker to bypass the encryption or trick a device into connecting to a malicious server. Many remote workers and businesses rely on VPNs to securely reach office networks, and a compromised VPN connection can expose all traffic, including passwords and private company data. These flaws are not limited to a single vendor, so every organization should check all four product categories immediately.
The most important action is to patch as soon as official updates are available. Check the security pages for Apple, Microsoft, and VMware right now and install any new updates. For systems that cannot be patched immediately, reduce risk by restricting access to management interfaces like vCenter and SharePoint admin panels so only trusted internal IP addresses can reach them. Enable two-factor authentication, which requires a second code from your phone in addition to a password, on every admin account. Monitor server and website logs for unusual login attempts or changes, and back up all critical data regularly so you can restore if an attack succeeds.
For organizations that manage their own servers, virtual infrastructure, or SharePoint portals, the window between vulnerability disclosure and active attack is often measured in hours. Working with a security-first IT and infrastructure partner can help prioritize patches, close exposed management interfaces, and monitor for signs of compromise before attackers strike. AEU-I, the security-first IT, infrastructure and consulting service from AEU Group, offers exactly this kind of assessment and remediation support, helping businesses reduce their exposure to actively exploited flaws across macOS, SharePoint, vCenter, and IKE without needing in-house security experts.
How to Protect Yourself
- Turn on automatic updates on all your computers and servers so security fixes install as soon as they are released.
- If you use Microsoft SharePoint or VMware vCenter, check the vendor's official security page right away and apply the latest patches immediately.
- Use strong, unique passwords and turn on two-factor authentication, which asks for a second code from your phone, for any admin account that manages websites, servers, or VPN connections.
- Restrict access to management pages like vCenter and SharePoint admin panels so only specific known devices or office network addresses can reach them.
- Back up your website and important files regularly, and store backups in a separate offline location so you can restore everything if an attack happens.
- Watch your website and server logs for unusual login attempts or changes, and ask your hosting provider or IT team to investigate anything suspicious.