VORANT. Threat Intelligence Sign in Get the full feed

Apple Patches Over 200 macOS Vulnerabilities

high vulnerability

NCSC-NL advisory catalogs 200+ Apple-fixed macOS flaws (Golden Gate 27, Sequoia 15.8, Tahoe 26.7), several critical, enabling RCE, sandbox/Gatekeeper bypass, or privilege escalation.

The Dutch National Cyber Security Center (NCSC-NL) published a bulk advisory summarizing a large batch of vulnerabilities that Apple has patched across macOS Golden Gate 27, Sequoia 15.8, and Tahoe 26.7 (the title also references Samba, though no Samba-specific CVEs are enumerated in the body). The bug classes span heap-based buffer overflows, use-after-free conditions, integer overflows, out-of-bounds reads/writes, race conditions, improper access control, argument injection, path traversal, XSS, and missing authorization checks. Several of the listed CVEs carry high CVSS scores (up to 9.8), and per Apple's characterization these issues can lead to unexpected application or system termination, kernel memory corruption, unauthorized access to sensitive user data, sandbox and Gatekeeper bypass, and in some cases remote code execution or denial of service.

The advisory does not indicate any of the listed CVEs are currently being exploited in the wild; it is a standard patch-rollup notification rather than an active-exploitation alert. Given the scale (over 200 CVEs) and the presence of multiple critical/high-severity memory-corruption and privilege-escalation bugs, organizations running affected macOS versions should prioritize applying Apple's updates promptly, particularly on systems exposed to untrusted content or network input where RCE or sandbox-escape chains could be leveraged.

Defenders should track asset inventories for macOS devices on Golden Gate 27, Sequoia 15.8, and Tahoe 26.7, confirm patch deployment through MDM, and monitor for post-patch anomalies (crashes, unexpected privilege changes) that could indicate exploitation attempts predating remediation. No IOCs, malware, or threat-actor attribution are associated with this advisory as it is a vulnerability/patch disclosure rather than an incident report.

Mentioned in this report

Vulnerabilities CVE-2022-3437CVE-2026-28930CVE-2026-28969CVE-2026-34979CVE-2026-43677CVE-2026-43686CVE-2026-43687CVE-2026-43689CVE-2026-43691CVE-2026-43692CVE-2026-43698CVE-2026-43738CVE-2026-43743CVE-2026-43760CVE-2026-43763CVE-2026-43786CVE-2026-64712CVE-2026-64718CVE-2026-64736CVE-2026-64752CVE-2026-64753CVE-2026-64758CVE-2026-64760CVE-2026-65330CVE-2026-65339CVE-2026-65346CVE-2026-65349CVE-2026-65362CVE-2026-65364CVE-2026-65374CVE-2026-65395CVE-2026-65400KEVCVE-2026-65414CVE-2026-65415CVE-2026-84489CVE-2026-84492CVE-2026-84505CVE-2026-84506CVE-2026-84518CVE-2026-84519

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0371.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free