ON 14 September 2026, Apple released security updates addressing 273 CVEs across macOS 27 (Golden Gate), macOS Sequoia 15.8, macOS Tahoe 26.7, iOS and iPadOS 27 and 26.7, visionOS 27, watchOS 27, tvOS 27, Safari 27 and Xcode 27. The update includes 134 vulnerabilities with scores and 139 still listed as “TBD”, as Apple does not publish CVSS ratings. The most urgent issue is CVE-2026-65400, a 9.8-critical Screen Sharing Server flaw that CISA has confirmed is being actively exploited.
It allows a network attacker to authenticate to Screen Sharing without valid credentials or user interaction. The fix was first issued on 6 August and is included in macOS 27 and macOS Tahoe 26.7.
CVE-2026-65414, a 9.8-critical Bluetooth vulnerability affecting all eight operating-system platforms, allows remote arbitrary code execution without privileges or user interaction; CISA marked it “automatable: yes” with “technical impact: total”, although exploitation was not confirmed.
Other notable issues include CVE-2026-65346, an 8.8-high ImageIO flaw where processing a malicious image can result in arbitrary code execution, and unscored CVE-2026-84607, which could let a sandboxed app execute code with kernel privileges. The report also highlights unscored CVE-2026-43790, involving remote kernel memory corruption, plus high-severity CUPS and autofs flaws.
Users and organisations should apply the relevant Apple updates, prioritising systems exposed to Screen Sharing and devices handling untrusted images or Bluetooth connections.