Microsoft and Apple released new security updates on Thursday, August 6, 2026. Microsoft patched more than a dozen vulnerabilities across Active Directory, Azure, Entra, SharePoint, Teams and other products. Apple fixed a single Screen Sharing authentication bypass in macOS.
Microsoft carried the bulk of the risk: three flaws rated a maximum 10/10 and four more rated 9.9, all remotely exploitable. Apple's lone fix, CVE-2026-65400, closes a network-based bypass that let attackers reach Screen Sharing without valid credentials.
Key takeaways
- Microsoft patched over a dozen vulnerabilities on August 6, 2026, including critical RCE issues.
- Three flaws, CVE-2026-63508, CVE-2026-56162 and CVE-2026-65667, carry a maximum CVSS score of 10/10.
- Four more flaws rated 9.9 hit Azure Service Bus, Azure SRE Agent, Entra Provisioning Service and Active Directory, all remotely exploitable.
- Apple fixed CVE-2026-65400 (CVSS 7.5), a Screen Sharing authentication bypass, in three macOS versions.
- Admins should patch the remotely exploitable identity and cloud flaws first.
Affected
What did Microsoft and Apple patch?
Microsoft and Apple both shipped security updates on Thursday, August 6, 2026. Microsoft led with fixes for more than a dozen vulnerabilities across Active Directory, Azure, Entra, SharePoint, Teams and other products. Several are critical-severity remote code execution issues.
Apple's release was smaller, covering a single defect. The company said the flaw could let an attacker on the network authenticate to Screen Sharing without valid credentials.
- Microsoft fixed 12+ vulnerabilities; Apple fixed one
- Both releases landed on August 6, 2026
Which Microsoft flaws are rated 10/10?
Three Microsoft issues carry a maximum CVSS severity of 10/10, and all three are exploitable over the network. Each can lead to elevation of privilege.
- CVE-2026-63508: missing authentication in Planetary Computer Pro
- CVE-2026-56162: improper authentication in Azure SQL Database
- CVE-2026-65667: missing authorization in Teams
Four more flaws score 9.9/10 and are also remotely exploitable: CVE-2026-50515 (RCE in Azure Service Bus), CVE-2026-62830 (EoP in Azure SRE Agent), CVE-2026-59115 (EoP in Entra Provisioning Service) and CVE-2026-50481 (EoP in Active Directory). These touch identity and messaging infrastructure, so a successful attack could spread across a tenant.
- Three flaws rated 10/10; four rated 9.9
- All seven are remotely exploitable
Apple's Screen Sharing bypass explained
CVE-2026-65400 (CVSS 7.5) is a Screen Sharing authentication bypass in macOS. Apple says an attacker on the same network could authenticate to Screen Sharing without valid credentials, which could give them remote access to a Mac's desktop session.
Apple shipped the patch in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9. The update arrived about a week after Apple fixed dozens of defects with iOS 26.6 and macOS Tahoe 26.6.
- Fixed in macOS Tahoe 26.6.1, Sequoia 15.7.9, Sonoma 14.8.9
Who is affected?
The Microsoft flaws hit organizations running the affected cloud and identity services. If you use Entra for provisioning or Active Directory for on-premises identity, treat the 9.9-rated EoP issues as high priority. Privilege escalation in those layers can break wider access controls.
On the Apple side, any Mac on an affected macOS version with Screen Sharing reachable over the network is exposed until you update it. Shops that enable remote screen sharing for support desks are the most likely to have this surface open.
How this fits the recent patch cadence
Microsoft's August 6 updates followed one week after the company shipped over two dozen fixes for Office, 365 Apps for Enterprise, Edge and Azure Cosmos DB. The back-to-back releases point to a steady stream of cloud- and identity-focused patches, not a single monthly bundle.
Apple kept a similar rhythm. The single Screen Sharing fix arrived about a week after a larger set of defects went out with iOS 26.6 and macOS Tahoe 26.6.
How should admins prioritize these updates?
Start with the remotely exploitable Microsoft flaws rated 9.9 and above. Microsoft applies most cloud-service fixes on its side, but confirm affected components are current and check access logs for the identity services involved.
- Apply the three 10/10 fixes for Planetary Computer Pro, Azure SQL Database and Teams.
- Address the four 9.9 flaws in Azure Service Bus, Azure SRE Agent, Entra Provisioning Service and Active Directory.
- Update macOS endpoints to Tahoe 26.6.1, Sequoia 15.7.9 or Sonoma 14.8.9 to close CVE-2026-65400.
- Restrict Screen Sharing network exposure where remote access isn't required.
Prioritize remote-exploit flaws
Seven Microsoft flaws are both remotely exploitable and rated 9.9 or higher. Patch these ahead of the lower-severity information disclosure and spoofing fixes in the same batch.
Timeline
Impact & actions
Multiple remotely exploitable Microsoft flaws could enable elevation of privilege or remote code execution across cloud and identity services. Apple's fix removes a network-based Screen Sharing bypass on macOS.
Security: Successful exploitation of the Microsoft flaws could lead to elevation of privilege, remote code execution, information disclosure and spoofing.
Privacy: The Screen Sharing bypass could expose a Mac desktop session to unauthorized network attackers.
Recommended actions · High urgency
- 1Apply Microsoft's August 6 updates, starting with flaws rated 9.9 and above
- 2Update macOS to Tahoe 26.6.1, Sequoia 15.7.9 or Sonoma 14.8.9
- 3Limit network exposure of Screen Sharing
Technical details
- CVEs
- CVE-2026-63508, CVE-2026-56162, CVE-2026-65667, CVE-2026-50515, CVE-2026-62830, CVE-2026-59115, CVE-2026-50481, CVE-2026-65400
- CVSS
- 10
- Attack vector
- Network
- Affected versions
- macOS Tahoe (before 26.6.1), macOS Sequoia (before 15.7.9), macOS Sonoma (before 14.8.9)
- Patched versions
- macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9
Mitigations
- Apply Microsoft's August 6, 2026 security updates
- Update macOS to a patched version
- Restrict network access to Screen Sharing
Response
Vendor
Customer guidance
Both vendors published advisories. Customers should apply the released updates for affected products.
FAQ
Which Microsoft vulnerabilities are rated 10/10?
CVE-2026-63508 (missing authentication in Planetary Computer Pro), CVE-2026-56162 (improper authentication in Azure SQL Database) and CVE-2026-65667 (missing authorization in Teams) all carry a maximum CVSS score of 10/10 and are network-exploitable.
What did Apple fix in this update?
Apple fixed CVE-2026-65400 (CVSS 7.5), a Screen Sharing authentication bypass that could let a network attacker authenticate without valid credentials.
Which macOS versions contain the fix?
The fix ships in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9.
Are any of these flaws being exploited?
The current advisories don't indicate active exploitation. Exploitation status is unknown.
Which fixes should admins apply first?
Start with the seven remotely exploitable Microsoft flaws rated 9.9 and above across Azure, Entra, Active Directory and Teams, then update macOS endpoints.
The bottom line
On August 6, 2026, Microsoft patched more than a dozen vulnerabilities, including three rated 10/10 and four rated 9.9. Apple fixed a single Screen Sharing bypass, CVE-2026-65400, in three macOS versions.
What happens next
What to do






