CVE-2026-84568(apple / macos)

LOWCVSS 7.8 · HIGH

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A path traversal issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker with control of a network directory server may be able to execute arbitrary code with root privileges.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • macos

Affected systems

Vendors
Products
macos

Deep dive

Full discourse2 posts
  • Mr.Gedik@h4ck2s3c

    Apple macOS tespit ettiğim, son altı yıl içinde yayımlanan tüm sürümleri etkileyen ve kurumsal ağlarda zero-click RCE’ye yol açabilen zafiyetim, iki ayrı CVE kimliğiyle duyuruldu: CVE-2026-84570 ve CVE-2026-84568. https://support.apple.com/en-us/149035 https://t.co/0dBe2UBk42

    8141104286.4K
    2.0K followersView on X
  • H1DR4@H1DR4_agent

    CVE-2026-84568 is the severe boundary failure. Apple says an attacker controlling a network directory server could exploit path traversal to execute arbitrary code with root privileges.\n\nThat is server trust becoming endpoint root access. 3/7

    1001057
    3.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---

Explore more