endoflife.ai
EOL Checker Products EOL Watch Get Support

Two KEV Entries, One Lesson: macOS Ventura Gets No Fix at Any Price, Windows 10 Gets One Only Behind ESU

By Scott Bissett  ·  Published: August 19, 2026  ·  Verified against CISA's KEV feed, Apple security releases 148170/148171/148172 and Microsoft's MSRC entry with its full update list — methodology

On August 18, 2026 CISA added four actively exploited flaws to its Known Exploited Vulnerabilities catalog. Two of them are not patching stories — they are end-of-life stories. CVE-2026-65400, a macOS Screen Sharing authentication bypass, was fixed by Apple on August 6 in exactly three places: macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9. CVE-2026-33824, a CVSS 9.8 double free in the Windows IKE service reachable by unauthenticated packets on UDP 500/4500, was patched by Microsoft back on April 14 — including for Windows 10 22H2, but that update ships only to machines enrolled in Extended Security Updates, because Windows 10 left support on October 14, 2025.

Same day, same catalog, same federal deadline of August 21 — and two different shapes of the same problem. A Mac on Ventura or older cannot buy its way to this fix: Apple sells no extended support, so the patch simply does not exist for it. A Windows 10 machine can buy its way to the fix — ESU delivers it — but a machine that skipped ESU has been carrying a critical, now actively-exploited, wormable-class flaw since April. This page lays out exactly who has a fix, who does not, and what to do this week.

The one-paragraph version: Macs on Tahoe, Sequoia or Sonoma: update now (26.6.1 / 15.7.9 / 14.8.9). Macs on Ventura or older: no fix exists — disable Screen Sharing and plan the OS upgrade or hardware replacement. Windows 11 and supported Servers: April's Patch Tuesday covered you. Windows 10 with ESU: confirm KB5082200 is installed. Windows 10 without ESU: block UDP 500/4500 today, then enroll in ESU or migrate — the flaw is being exploited and your machine will never receive the fix otherwise.

Key Dates at a Glance

Running Windows 10 past end of life?
Extended support past the official EOL date exists for many products in this position — whether it covers Windows 10 is exactly what we check. Tell us where to reach you and we’ll reply with matched options and pricing guidance — or an honest “no vendor covers this.” Free, no obligation.

Free · No obligation · Independent — we track the dates, vendors don’t pay for placement · dates verified against vendor sources. See all support options →

The macOS Case: No Fix, No Paid Route

CVE-2026-65400 lets an attacker on the network authenticate to macOS Screen Sharing without valid credentials — Apple's words: “An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.” The fix (“improved state management”) shipped August 6, 2026 in three security releases: macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9. That list is the whole list.

Apple maintains, in practice, the current macOS and the two before it. macOS Ventura 13 fell off that list when Tahoe shipped on September 15, 2025; Monterey and older have been unpatched for years. Apple publishes no end-of-life dates, offers no extended-support program, and does not list unsupported versions in its advisories — which is why this entry is not in our Exploited & Unpatchable feed (our rule requires the vendor to name the version as affected; Apple never does). The practical reading is unchanged: a Ventura-or-older Mac exposed to a network where an attacker can reach port 5900 is running an actively exploited authentication bypass that will never be fixed on that OS.

The exposure is real rather than theoretical: KEV listing requires evidence of active exploitation, and exploitation reporting around this flaw describes attackers gaining control of exposed machines. Screen Sharing is off by default, but it is precisely the kind of service that gets switched on for remote admin and forgotten.

The Windows Case: The Fix Exists — Behind ESU

CVE-2026-33824 is a double free in the Windows Internet Key Exchange (IKE) service: an unauthenticated attacker sends crafted packets to UDP 500/4500 on a machine with IKEv2 enabled and can execute code. Microsoft rates it CVSS 9.8 and patched it on April 14, 2026 across every supported Windows: Windows 11 (23H2 through 26H1), Windows Server 2016 through 2025 — and Windows 10: KB5082200 for 22H2 and 21H2 (LTSC), KB5082123 for 1809/Server 2019, KB5082198 for 1607/Server 2016.

The Windows 10 22H2 row is the one that matters here. 22H2 ended support on October 14, 2025 — six months before this patch — so KB5082200 reaches only machines enrolled in Extended Security Updates: the consumer ESU year (to October 13, 2026) or the commercial program (up to October 10, 2028). A Windows 10 machine outside ESU never received it and never will.

Two details worth being precise about. First, Microsoft's advisory assessed the flaw as “Exploited: No — Exploitation Less Likely” when it published in April; CISA's KEV addition on August 18 is the confirmation that this changed. Machines that skipped the April update on “low risk” grounds are now four months behind on an actively exploited pre-auth RCE. Second, Microsoft's own listed mitigation for machines that cannot patch — block inbound UDP 500/4500 where IKE is unused, or restrict to known peers — is available to everyone, ESU or not, and worth applying to any unmanaged Windows 10 fleet this week.

This is also not in our Exploited & Unpatchable feed, for the same reason Exchange ESU cases are excluded: a vendor fix route exists (ESU). “Unpatched unless you pay” and “unpatchable” are different claims, and the difference is the whole decision.

What Our Risk Scores Say

We publish an EOL Risk Score (0–100) for every tracked version — lifecycle recency, attack surface, KEV exposure, extended-support availability — recalculated at every build.

VersionEOL Risk ScoreWhat drives it
macOS Ventura 1390Off Apple's update list since September 15, 2025; OS attack surface; KEV exposure; no extended support exists.
macOS Sonoma 1460Still updated (14.8.9) — but next in line to fall off the three-version list.
Windows 10 22H280Out of support October 14, 2025; KEV exposure; ESU exists — which is the one lever that changes this machine's reality.

What to Do by August 21

  1. Supported Macs: install 26.6.1 / 15.7.9 / 14.8.9 now.
  2. Ventura and older: System Settings → General → Sharing → turn off Screen Sharing; never expose port 5900 beyond a trusted network. Then upgrade to a supported macOS, or replace hardware that cannot run one — there is no third option that ends with a patched machine.
  3. Windows 11 / supported Server: confirm April 2026 cumulative updates are applied; this one is four months old.
  4. Windows 10 with ESU: confirm KB5082200 (or your channel's equivalent) is actually installed — enrollment without deployment is a common gap.
  5. Windows 10 without ESU: block inbound UDP 500/4500 (or restrict to known peers) today, then make the real decision: enroll in ESU (consumer to October 2026, commercial to October 2028), upgrade to Windows 11, or retire the machine. The decision framework with costs is in Windows 10: upgrade, buy ESU, or replace?

Frequently Asked Questions

Is macOS Ventura patched for CVE-2026-65400?

No. Apple fixed the Screen Sharing authentication bypass on August 6, 2026 in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9 — the three macOS versions Apple currently maintains. macOS Ventura 13, which stopped receiving updates when Tahoe shipped on September 15, 2025, and everything older are not in any of the three advisories, and Apple does not sell extended support for old macOS versions. The only fix for a Ventura or older Mac is upgrading to a supported macOS, or replacing hardware that cannot run one.

What is CVE-2026-65400?

An improper-authentication flaw in macOS Screen Sharing: an attacker on the network can authenticate to Screen Sharing without valid credentials. Apple's advisory credits the discovery and describes the fix as improved state management. CISA added it to the Known Exploited Vulnerabilities catalog on August 18, 2026 with a federal remediation deadline of August 21 — KEV listing means exploitation in the wild is confirmed.

Is Windows 10 patched for CVE-2026-33824?

Only behind ESU. Microsoft patched the IKE double free (CVSS 9.8, unauthenticated remote code execution over UDP 500/4500) on April 14, 2026, and Windows 10 22H2 is in the update list — KB5082200. But Windows 10 22H2 ended support on October 14, 2025, so that update is delivered only to devices enrolled in Extended Security Updates. A Windows 10 machine without ESU has been exposed to a now actively-exploited critical flaw since April.

Does the KEV listing mean these bugs are being exploited?

Yes — that is the entry criterion. CISA adds a CVE to the Known Exploited Vulnerabilities catalog only on reliable evidence of active exploitation. Both entries carry an August 21, 2026 remediation deadline for US federal civilian agencies. Notably, Microsoft's own advisory assessed CVE-2026-33824 as 'Exploited: No' when it was published in April; the KEV listing four months later is what changed.

What can I do if I can't patch?

For Windows machines that cannot get the IKE fix, Microsoft's listed mitigation is to block inbound UDP 500 and 4500 where IKE is not used, or restrict them to known peer addresses — a stopgap, not a substitute. For Macs on Ventura or older, disable Screen Sharing (System Settings → General → Sharing) and keep port 5900 off the internet. Then fix the lifecycle problem: upgrade the OS, enroll in ESU (Windows), or replace the device.

Where do I check whether my OS version still gets security fixes?

Our macOS page lists every version's status under Apple's three-version practice, and the Windows page tracks every servicing channel including the ESU windows — Windows 10 22H2 consumer ESU runs to October 13, 2026 and commercial ESU to October 10, 2028. The EOL Checker answers for any product and version.

The Monthly EOL Digest™

Once a month — critical EOL dates, CVE blind spots, and lifecycle changes worth knowing.

© 2026 endoflife.ai · How we verify our dates · API · About · Data from endoflife.date (MIT)