CISA's Known Exploited Vulnerabilities catalog picked up four new entries on the 18th, and it's a broad spread rather than one vendor's bad day. The list: CVE-2026-33824, a double-free in Microsoft's Internet Key Exchange (IKE) service extensions; CVE-2026-55040, a weak-authentication flaw in SharePoint; CVE-2026-59310, a path-traversal bug in Broadcom's VMware vCenter; and CVE-2026-65400, an improper-authentication issue in Apple macOS. All four are on the list because there's evidence they're being used in the wild, not because someone found them interesting in a lab. For federal civilian agencies, BOD 22-01 turns a KEV listing into a hard clock — the catalog entry itself carries the remediation due date, and these are exactly the kind of vulnerabilities (auth bypass, path traversal, memory corruption in an internet-facing service) that attackers chain into full compromise. Everyone else should treat the KEV catalog as the prioritization signal it's become: if you run vCenter, SharePoint, or a Windows IKE/IPsec endpoint, these jump the patch queue. The macOS entry is the odd one out on an enterprise fleet, but worth a look at your MDM's update posture too.