CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Apple security advisory (AV26-823) – Update 1

unknownknown exploitedpublic exploitCVE-2026-65400
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial number: AV26-823 Date: August 17, 2026 Updated: August 18, 2026 As of August 6, 2026, Apple is affected by vulnerabilities in the following products: macOS Tahoe Prior to 26.6.1 macOS Sequoia Prior to 15.7.9 macOS Sonoma Prior to 14.8.9 Open-source reporting indicates that CVE-2026-65400 is being exploited in the wild. Update 1 On August 18, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-65400 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates. About the security content of macOS Tahoe 26.6.1 About the security content of macOS Sequoia 15.7.9 About the security content of macOS Sonoma 14.8.9 Apple security releases - Apple Support CISA KEV: CVE-2026-65400

CSIRTS triage

vendor: Appleproduct: macOSRemote code executionaffected: macOS Tahoe prior to 26.6.1, macOS Sequoia prior to 15.7.9, macOS Sonoma prior to 14.8.9
What
CVE-2026-65400 in macOS allows remote code execution and is being exploited in the wild.
Who is affected
Users running macOS Tahoe, Sequoia, and Sonoma prior to the specified patched versions are affected.
Urgency
Critical; confirmed active exploitation in the wild requires immediate patching.
Action
Update to macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, or macOS Sonoma 14.8.9 immediately.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch macOS

Get an email when a new macOS advisory drops — max one per day, one-click unsubscribe.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-08-18
Exploitation
Observed in the wild (CISA KEV)

Original advisory: https://cyber.gc.ca/en/alerts-advisories/apple-security-advisory-av26-823

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-65400coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Canadian Centre for Cyber Security