Our takeApple's AV26-823 advisory patches multiple flaws including CVE-2026-65400, which is under active exploitation. Update all macOS Tahoe, Sequoia, and Sonoma instances immediately.Cyber Resilience desk
Sources (1)
- cccs · cccs
What this means for you — Security leader:Apply the Apple security updates to macOS Tahoe (to 26.6.1), Sequoia (to 15.7.9) and Sonoma (to 14.8.9). CVE-2026-65400 is under active exploitation per CCCS.
What this means for you — Lean IT orgs:Update your Macs running macOS Tahoe, Sequoia, or Sonoma to the latest versions as soon as possible. One of the flaws is already being exploited in the wild.
What this means for you — MSP:Check client fleets for macOS Tahoe prior to 26.6.1, Sequoia prior to 15.7.9, and Sonoma prior to 14.8.9; push the Apple updates. CVE-2026-65400 is actively exploited.
What this means for you — Researcher:Review the CCCS advisory AV26-823 and associated Apple releases for technical details on CVE-2026-65400 and the other flaws.