• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-84568: path traversal remote code execution in Apple macOS

An attacker who controls a network directory server can cause macOS to follow crafted paths and execute arbitrary code as root. CVE-2026-84568 is a path traversal vulnerability that impacted multiple macOS branches; it is fixed in macOS Sequoia 15.8, Tahoe 26.7, and Golden Gate 27. An attacker needs control of a network directory server reachable by the target system; no user interaction is required according to the available facts.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
7.8HIGH
EPSS
0.00194
CWE
CWE-22
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Treat this as urgent: public exploit code exists that targets a vulnerability allowing root code execution, so prioritize installing the vendor fixes for affected macOS branches immediately.

What is CVE-2026-84568?

An attacker who controls a network directory server can cause macOS to follow crafted paths and execute arbitrary code as root. CVE-2026-84568 is a path traversal vulnerability that impacted multiple macOS branches; it is fixed in macOS Sequoia 15.8, Tahoe 26.7, and Golden Gate 27. An attacker needs control of a network directory server reachable by the target system; no user interaction is required according to the available facts. The weakness is classified as CWE-22 (Path Traversal).

Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of Apple macOS are affected?

BRANCHAFFECTEDFIXED
15.xbefore 15.815.8
26.xbefore 26.726.7
27.xbefore 2727

Is CVE-2026-84568 being exploited?

Public exploit code is available.

How to fix CVE-2026-84568

  1. Upgrade affected macOS installs to the fixed releases: 15.8, 26.7, or 27 as appropriate for your branch.
  2. If you cannot upgrade immediately, restrict access to network directory servers from macOS hosts and limit which directory servers are trusted on the network.
  3. Apply vendor guidance and security updates from Apple as soon as they are available and tested.
  4. Monitor systems for signs of compromise and review logs for unexpected connections to or from directory services.

Frequently asked questions

Is CVE-2026-84568 being actively exploited?

Public exploit code is available for CVE-2026-84568.

Which macOS versions are affected by CVE-2026-84568?

macOS releases before Sequoia 15.8, Tahoe 26.7, and Golden Gate 27 are listed as affected; the fixes appear in 15.8, 26.7, and 27 respectively.

Is there a patch for CVE-2026-84568?

Yes. Apple fixed the issue in macOS Sequoia 15.8, Tahoe 26.7, and Golden Gate 27; apply those updates to remediate the vulnerability.

Does CVE-2026-84568 require authentication?

The vulnerability requires an attacker to control a network directory server reachable by the macOS host, not a local authenticated user; no user interaction is indicated in the available facts.

References