www.securityweek.com 8/7/2026, 9:40:55 AM · external

Microsoft, Apple issue patches for critical RCE and auth bypass

Microsoft, Apple issue patches for critical RCE and auth bypass
CyberSIXT Evidence Panel
Primary Source msrc.microsoft.com
CISA KEV Not in KEV
Patch Patch Available

MICROSOFT and Apple recently announced security updates addressing multiple vulnerabilities in their products. Microsoft led the charge with over a dozen patches, including critical remote code execution (RCE) issues rated 10/10, specifically CVE-2026-63508, CVE-2026-56162, and CVE-2026-65667. These vulnerabilities involve missing authentication and improper authorization across various services like Active Directory and Azure.

Additionally, other serious issues were identified in services like Azure Service Bus and Entra Provisioning. Apple also released a patch for a vulnerability (CVE-2026-65400) that could allow attackers to bypass authentication in Screen Sharing, with a CVSS score of 7.5. These updates come after Apple previously patched dozens of vulnerabilities in iOS and macOS.

View Primary Source Via www.securityweek.com

Article by CyberSIXT