• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-65374: remote code execution in Apple macOS

An attacker can execute arbitrary code on macOS by causing a memory corruption when the system connects to a malicious WebDAV server. CVE-2026-65374 affects macOS Sequoia 15.x before 15.8, Tahoe 26.x before 26.7, and Golden Gate 27.x before 27. An attacker needs network access to host a malicious WebDAV service and a user on the target macOS system to connect or be tricked into connecting (requires user interaction).

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
8.8HIGH
EPSS
0.00528
CWE
CWE-787
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: patch immediately where possible because public exploit code exists for this flaw. Prioritize upgrading internet-facing or frequently exposed macOS hosts to the fixed releases listed by Apple.

What is CVE-2026-65374?

An attacker can execute arbitrary code on macOS by causing a memory corruption when the system connects to a malicious WebDAV server. CVE-2026-65374 affects macOS Sequoia 15.x before 15.8, Tahoe 26.x before 26.7, and Golden Gate 27.x before 27. An attacker needs network access to host a malicious WebDAV service and a user on the target macOS system to connect or be tricked into connecting (requires user interaction). The weakness is classified as CWE-787 (Out-of-bounds Write).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Which versions of Apple macOS are affected?

BRANCHAFFECTEDFIXED
15.xbefore 15.815.8
26.xbefore 26.726.7
27.xbefore 2727

Is CVE-2026-65374 being exploited?

Public exploit code is available.

How to fix CVE-2026-65374

  1. Upgrade macOS Sequoia 15.x to 15.8, Tahoe 26.x to 26.7, or Golden Gate 27.x to 27.
  2. Block or restrict access to untrusted WebDAV servers at network boundaries and web proxies.
  3. Advise users not to connect to unknown WebDAV links or servers and disable automatic connections to WebDAV where configurable.
  4. Monitor endpoint logs for unexpected WebDAV connections and signs of exploitation and follow Apple's security guidance.

Frequently asked questions

Is CVE-2026-65374 being actively exploited?

Public exploit code is available for CVE-2026-65374.

Which macOS versions are affected by CVE-2026-65374?

macOS Sequoia 15.x before 15.8, Tahoe 26.x before 26.7, and Golden Gate 27.x before 27 are listed as affected.

Is there a patch for CVE-2026-65374?

Yes; Apple released fixes in macOS Sequoia 15.8, Tahoe 26.7, and Golden Gate 27.

Does CVE-2026-65374 require authentication?

No authentication is required, but the vulnerability requires a user to connect or be lured to a malicious WebDAV server (user interaction is needed).

References