macOS 26.x < 26.7 Multiple Vulnerabilities (149042)

critical Nessus Plugin ID 345686

Synopsis

The remote host is missing a macOS update that fixes multiple vulnerabilities

Description

The remote host is running a version of macOS / Mac OS X that is 26.x prior to 26.7. It is, therefore, affected by multiple vulnerabilities:

- A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A malicious app may be able to break out of its sandbox. (CVE-2026-65381)

- A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory when presented with a maliciously small packet. This flaw allows a remote user to send specially crafted malicious data to the application, possibly resulting in a denial of service (DoS) attack. (CVE-2022-3437)

- An authentication issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27. An app may be able to use the Sign In With Apple authentication flow to access the user's Apple Account. (CVE-2026-20683)

- A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.6, macOS Tahoe 26.7. An app may bypass Gatekeeper checks. (CVE-2026-28899)

- A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a malicious disk image may cause unexpected system termination. (CVE-2026-28934)

Note that Nessus has not tested for these issues but has instead relied only on the operating system's self-reported version number.

Solution

Upgrade to macOS 26.7 or later.

See Also

https://support.apple.com/en-us/149042

Plugin Details

Severity: Critical

ID: 345686

File Name: macos_149042.nasl

Version: 1.4

Type: Local

Agent: macosx

Published: 9/14/2026

Updated: 9/29/2026

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.4

Percentile: 99.82

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-65381

CVSS v3

Risk Factor: Critical

Base Score: 10

Temporal Score: 9.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:apple:mac_os_x:26.0, cpe:/o:apple:macos:26.0

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/14/2026

Vulnerability Publication Date: 10/25/2022

CISA Known Exploited Vulnerability Due Dates: 8/21/2026

Reference Information

CVE: CVE-2022-3437, CVE-2026-20683, CVE-2026-28899, CVE-2026-28934, CVE-2026-28966, CVE-2026-28968, CVE-2026-28969, CVE-2026-43664, CVE-2026-43677, CVE-2026-43683, CVE-2026-43686, CVE-2026-43687, CVE-2026-43690, CVE-2026-43691, CVE-2026-43692, CVE-2026-43695, CVE-2026-43697, CVE-2026-43698, CVE-2026-43702, CVE-2026-43719, CVE-2026-43737, CVE-2026-43741, CVE-2026-43743, CVE-2026-43760, CVE-2026-43763, CVE-2026-43785, CVE-2026-43786, CVE-2026-43787, CVE-2026-43789, CVE-2026-43790, CVE-2026-43791, CVE-2026-64712, CVE-2026-64756, CVE-2026-64790, CVE-2026-65342, CVE-2026-65344, CVE-2026-65345, CVE-2026-65348, CVE-2026-65358, CVE-2026-65359, CVE-2026-65360, CVE-2026-65361, CVE-2026-65362, CVE-2026-65364, CVE-2026-65365, CVE-2026-65369, CVE-2026-65374, CVE-2026-65376, CVE-2026-65377, CVE-2026-65378, CVE-2026-65381, CVE-2026-65382, CVE-2026-65395, CVE-2026-65399, CVE-2026-65400, CVE-2026-65401, CVE-2026-65402, CVE-2026-65403, CVE-2026-65405, CVE-2026-65406, CVE-2026-65407, CVE-2026-65408, CVE-2026-65409, CVE-2026-65410, CVE-2026-65412, CVE-2026-65413, CVE-2026-65414, CVE-2026-84487, CVE-2026-84492, CVE-2026-84497, CVE-2026-84505, CVE-2026-84506, CVE-2026-84507, CVE-2026-84509, CVE-2026-84510, CVE-2026-84511, CVE-2026-84512, CVE-2026-84513, CVE-2026-84514, CVE-2026-84515, CVE-2026-84516, CVE-2026-84517, CVE-2026-84519, CVE-2026-84521, CVE-2026-84523, CVE-2026-84524, CVE-2026-84525, CVE-2026-84526, CVE-2026-84527, CVE-2026-84530, CVE-2026-84532, CVE-2026-84534, CVE-2026-84535, CVE-2026-84536, CVE-2026-84537, CVE-2026-84538, CVE-2026-84540, CVE-2026-84541, CVE-2026-84543, CVE-2026-84544, CVE-2026-84546, CVE-2026-84548, CVE-2026-84549, CVE-2026-84550, CVE-2026-84552, CVE-2026-84553, CVE-2026-84554, CVE-2026-84556, CVE-2026-84559, CVE-2026-84561, CVE-2026-84563, CVE-2026-84564, CVE-2026-84565, CVE-2026-84566, CVE-2026-84567, CVE-2026-84568, CVE-2026-84570, CVE-2026-84572, CVE-2026-84573, CVE-2026-84574, CVE-2026-84575, CVE-2026-84576, CVE-2026-84577, CVE-2026-84578, CVE-2026-84580, CVE-2026-84581, CVE-2026-84583, CVE-2026-84587, CVE-2026-84602, CVE-2026-84607, CVE-2026-84609, CVE-2026-84611, CVE-2026-84612, CVE-2026-84616, CVE-2026-84617, CVE-2026-84618, CVE-2026-84619, CVE-2026-84620, CVE-2026-84621, CVE-2026-84622, CVE-2026-84624, CVE-2026-84626, CVE-2026-84630, CVE-2026-84632, CVE-2026-86876, CVE-2026-86881, CVE-2026-86882, CVE-2026-86888, CVE-2026-86889, CVE-2026-86891, CVE-2026-86910, CVE-2026-86917, CVE-2026-86924

APPLE-SA: 149042

IAVA: 2026-A-1009