Apple: CVE-2026-65400 Zero-Day Added to CISA KEV Under Active Exploitation
CISA has added a critical Apple vulnerability, CVE-2026-65400, to its Known Exploited Vulnerabilities Catalog, confirming its active exploitation in the wild.

Key findings
- Apple's CVE-2026-65400 added to CISA KEV due to active exploitation.
- The vulnerability is a zero-day, currently being leveraged by threat actors.
- All organizations must prioritize patching to mitigate immediate risks.
- CISA mandates FCEB agencies remediate CVE-2026-65400 by February 18, 2027.
CISA recently updated its Known Exploited Vulnerabilities (KEV) Catalog to include CVE-2026-65400, an Apple vulnerability now confirmed to be under active exploitation. This addition signals a critical threat that federal civilian executive branch (FCEB) agencies must address immediately, highlighting the urgency for all organizations to prioritize remediation efforts.
CVE-2026-65400, identified simply by its identifier, represents a zero-day flaw impacting Apple products. While specific details regarding the nature of the vulnerability or the products affected have not been publicly disclosed, its presence in the KEV catalog indicates that threat actors are actively leveraging this weakness to compromise systems. The lack of public information often suggests a targeted exploitation campaign or a newly discovered flaw.
For defenders, the immediate priority is to identify and patch all instances of the affected Apple products. CISA's directive mandates that FCEB agencies remediate this vulnerability by February 18, 2027. All other organizations are strongly advised to follow this timeline and implement available patches or mitigation strategies without delay to protect against ongoing threats. Proactive patching is the most effective defense against actively exploited vulnerabilities.