Apple security advisory (AV26-823) – Update 1
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial number: AV26-823 Date: August 17, 2026 Updated: August 18, 2026 As of August 6, 2026, Apple is affected by vulnerabilities in the following products: macOS Tahoe Prior to 26.6.1 macOS Sequoia Prior to 15.7.9 macOS Sonoma Prior to 14.8.9 Open-source reporting indicates that CVE-2026-65400 is being exploited in the wild. Update 1 On August 18, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-65400 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates. About the security content of macOS Tahoe 26.6.1 About the security content of macOS Sequoia 15.7.9 About the security content of macOS Sonoma 14.8.9 Apple security releases - Apple Support CISA KEV: CVE-2026-65400
CSIRTS triage
- What
- CVE-2026-65400 in macOS allows remote code execution and is being exploited in the wild.
- Who is affected
- Users running macOS Tahoe, Sequoia, and Sonoma prior to the specified patched versions are affected.
- Urgency
- Critical; confirmed active exploitation in the wild requires immediate patching.
- Action
- Update to macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, or macOS Sonoma 14.8.9 immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch macOS
Get an email when a new macOS advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/apple-security-advisory-av26-823
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-65400Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 52% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-65400 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highexploitedCISA Adds Four Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2026-65400: Apple macOS Improper Authentication Vulnerabilitycisa-kev
- high[NEW] [medium] Apple macOS (Sonoma, Sequoia and Tahoe): Vulnerability enables security feature bypasscert-bund
- unknownexploitedNCSC-2026-0280 [1.01] [M/H] Vulnerability patched in macOS Screen Sharing by Applencsc-nl
- unknownNCSC-2026-0280 [1.00] [M/H] Vulnerability fixed in macOS Screen Sharing by Applencsc-nl
- unknownexploitedApple macOS Security Restriction Bypass Vulnerabilityhkcert
- unknownVulnerability in Apple macOS (August 07, 2026)cert-fr-avis
- highCVE-2026-65400: An authentication issue was addressed with improved state management. This issue is fixed in m…nvd
More from Canadian Centre for Cyber Security
- unknownCitrix security advisory (AV26-833)2026-08-19
- unknownMLflow security advisory (AV26-832)2026-08-19
- criticalOracle Corporation security advisory (AV26-831)2026-08-19
- unknownNVIDIA security advisory (AV26-830)2026-08-19
- unknownAtlassian security advisory (AV26-829)2026-08-19