Apple Releases macOS Tahoe 26.6.2 Fixing 28 Vulnerabilities Including Kernel Flaws
Apple has released macOS Tahoe 26.6.2 for Mac systems on August 17, 2026, local time. The update resolves 28 vulnerabilities tracked by CVE identifiers and includes corresponding Safari updates for older operating systems.
The patch set covers three kernel vulnerabilities. These include the Use After Free issue CVE-2026-65343, the out-of-bounds memory read CVE-2026-65349, and the memory corruption flaw CVE-2026-65330. Twenty-one additional vulnerabilities affect the WebKit rendering engine, while further fixes address components such as Audio, ImageIO, and IOGPUFamily.
The corrections in macOS Tahoe 26.6.2 reflect changes that were first made available in the macOS Golden Gate 27 beta. On August 18, Apple released Safari 26.6.1 for macOS Sonoma and macOS Sequoia, resolving the same 21 WebKit vulnerabilities.
The complete list of addressed CVEs is as follows:
- CVE-2026-43794
- CVE-2026-43795
- CVE-2026-64715
- CVE-2026-64778
- CVE-2026-64779
- CVE-2026-64780
- CVE-2026-64781
- CVE-2026-64782
- CVE-2026-64784
- CVE-2026-64787
- CVE-2026-64788
- CVE-2026-65330
- CVE-2026-65331
- CVE-2026-65332
- CVE-2026-65333
- CVE-2026-65334
- CVE-2026-65335
- CVE-2026-65336
- CVE-2026-65337
- CVE-2026-65338
- CVE-2026-65339
- CVE-2026-65340
- CVE-2026-65341
- CVE-2026-65343
- CVE-2026-65346
- CVE-2026-65347
- CVE-2026-65349
- CVE-2026-65351
Related articles
Dissecting CVE-2026-83557 in jackson-databind: Why Not Every CVE Requires Immediate Panic
A detailed analysis of CVE-2026-83557 reveals that the vulnerability in jackson-databind affects only a narrow set of configurations involving polymorphic deserialization with the Comparable base type. The flaw stems from an incomplete denylist in DefaultBaseTypeLimitingValidator, which overlooks java.lang.Comparable when the MapperFeature.BLOCK_UNSAFE_POLYMORPHIC_BASE_TYPES flag is explicitly enabled. Researchers constructed working proof-of-concept exploits showing that an attacker can instantiate classes such as java.io.File, but only when the property is declared as Comparable<?> and the protective flag is active. The issue impacts versions 2.11 through 2.22.1, yet the CVSS score of 5.6 reflects its moderate real-world risk because most applications lack the required Comparable-typed polymorphic fields. Patching introduces its own trade-off by blocking legitimate Comparable subclasses, forcing developers to implement custom BasicPolymorphicTypeValidator allowlists. The case highlights how dependency scanners often flag CVEs without considering application-specific configuration and DTO structures.
Multiple Critical Vulnerabilities Found in Citrix NetScaler ADC and Gateway, Two Actively Exploited
Cloud Software Group disclosed eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway products on September 27, 2026. Two of the issues, CVE-2026-88771 and CVE-2026-88772, have already been confirmed as exploited in the wild, prompting urgent remediation advice. CVE-2026-88771 stems from insufficient input validation and allows unauthenticated remote code execution across all default configurations. CVE-2026-88772 involves a memory overflow that can lead to code execution or denial of service when DTLS is enabled, which occurs by default on VPN vServers. The remaining six vulnerabilities cover code execution, denial of service, and HTTP request smuggling risks, with the advisory rated Critical overall. Organizations are urged to apply patches immediately and investigate potential breaches.
YApi Abandoned Since 2022: Fork Yapix Exposes Forgable Project Tokens and Critical Sandbox Flaws
YApi, a widely used open-source API documentation and mocking platform with 27.7k GitHub stars, has received no updates since its 1.12 release in November 2022. The project accumulated 1,629 open issues, including an unaddressed remote code execution report via mock scripts. Security researcher Perruer created the Yapix fork to address broken dependencies, Node.js 22 incompatibility with deprecated crypto.createCipher, and 244 known vulnerabilities in production dependencies. Analysis revealed that project tokens could be forged by any user because the default passsalt key was a hardcoded five-character string published on GitHub. The original implementation used vm2 and Node vm for script execution, both of which are unsafe, allowing arbitrary server-side code execution. Yapix migrates to isolated-vm with strict memory and time limits, replaces SHA-1 password hashing with scrypt, and blocks MongoDB operator injection in API parameters.
Researchers Bypass RP2350 Secure Debug Lock with Laser Fault Injection and Photon Emission Microscopy
Security researchers have demonstrated a hardware attack that restores Secure Debug access on the RP2350 microcontroller revision A4 despite permanent OTP fuses disabling it. Using photon emission microscopy they first located the exact physical bits of the DEBUGEN register, then applied precisely timed 980 nm laser pulses to flip two critical bits and re-enable the Mem-AP ports. The attack requires decapping the chip from the backside and laboratory equipment costing around $250,000, but succeeds in seconds once calibrated. It bypasses the CRIT1.DEBUG_DISABLE fuse, TrustZone restrictions, and glitch detectors by resetting the device before firmware can re-lock the OTP page. The technique was developed against the updated A4 silicon released after the first Raspberry Pi Hacking Challenge. The work highlights that even heavily hardened microcontrollers remain vulnerable to sophisticated physical attacks when an attacker has direct silicon access.