Two KEV Entries, One Lesson: macOS Ventura Gets No Fix at Any Price, Windows 10 Gets One Only Behind ESU
On August 18, 2026 CISA added four actively exploited flaws to its Known Exploited Vulnerabilities catalog. Two of them are not patching stories — they are end-of-life stories. CVE-2026-65400, a macOS Screen Sharing authentication bypass, was fixed by Apple on August 6 in exactly three places: macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9. CVE-2026-33824, a CVSS 9.8 double free in the Windows IKE service reachable by unauthenticated packets on UDP 500/4500, was patched by Microsoft back on April 14 — including for Windows 10 22H2, but that update ships only to machines enrolled in Extended Security Updates, because Windows 10 left support on October 14, 2025.
Same day, same catalog, same federal deadline of August 21 — and two different shapes of the same problem. A Mac on Ventura or older cannot buy its way to this fix: Apple sells no extended support, so the patch simply does not exist for it. A Windows 10 machine can buy its way to the fix — ESU delivers it — but a machine that skipped ESU has been carrying a critical, now actively-exploited, wormable-class flaw since April. This page lays out exactly who has a fix, who does not, and what to do this week.
Key Dates at a Glance
- macOS Ventura 13: last macOS release to receive updates before Tahoe shipped — security updates ended 2025-09-15
- Windows 10 22H2: end of support 2025-10-14; commercial ESU ends 2028-10-10
- CVE-2026-33824: patched 2026-04-14 (KB5082200 for Windows 10 22H2, ESU-only)
- CVE-2026-65400: patched 2026-08-06 (Tahoe 26.6.1, Sequoia 15.7.9, Sonoma 14.8.9)
- Both CVEs: added to CISA KEV 2026-08-18; federal remediation due 2026-08-21
The macOS Case: No Fix, No Paid Route
CVE-2026-65400 lets an attacker on the network authenticate to macOS Screen Sharing without valid credentials — Apple's words: “An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.” The fix (“improved state management”) shipped August 6, 2026 in three security releases: macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9. That list is the whole list.
Apple maintains, in practice, the current macOS and the two before it. macOS Ventura 13 fell off that list when Tahoe shipped on September 15, 2025; Monterey and older have been unpatched for years. Apple publishes no end-of-life dates, offers no extended-support program, and does not list unsupported versions in its advisories — which is why this entry is not in our Exploited & Unpatchable feed (our rule requires the vendor to name the version as affected; Apple never does). The practical reading is unchanged: a Ventura-or-older Mac exposed to a network where an attacker can reach port 5900 is running an actively exploited authentication bypass that will never be fixed on that OS.
The exposure is real rather than theoretical: KEV listing requires evidence of active exploitation, and exploitation reporting around this flaw describes attackers gaining control of exposed machines. Screen Sharing is off by default, but it is precisely the kind of service that gets switched on for remote admin and forgotten.
The Windows Case: The Fix Exists — Behind ESU
CVE-2026-33824 is a double free in the Windows Internet Key Exchange (IKE) service: an unauthenticated attacker sends crafted packets to UDP 500/4500 on a machine with IKEv2 enabled and can execute code. Microsoft rates it CVSS 9.8 and patched it on April 14, 2026 across every supported Windows: Windows 11 (23H2 through 26H1), Windows Server 2016 through 2025 — and Windows 10: KB5082200 for 22H2 and 21H2 (LTSC), KB5082123 for 1809/Server 2019, KB5082198 for 1607/Server 2016.
The Windows 10 22H2 row is the one that matters here. 22H2 ended support on October 14, 2025 — six months before this patch — so KB5082200 reaches only machines enrolled in Extended Security Updates: the consumer ESU year (to October 13, 2026) or the commercial program (up to October 10, 2028). A Windows 10 machine outside ESU never received it and never will.
Two details worth being precise about. First, Microsoft's advisory assessed the flaw as “Exploited: No — Exploitation Less Likely” when it published in April; CISA's KEV addition on August 18 is the confirmation that this changed. Machines that skipped the April update on “low risk” grounds are now four months behind on an actively exploited pre-auth RCE. Second, Microsoft's own listed mitigation for machines that cannot patch — block inbound UDP 500/4500 where IKE is unused, or restrict to known peers — is available to everyone, ESU or not, and worth applying to any unmanaged Windows 10 fleet this week.
This is also not in our Exploited & Unpatchable feed, for the same reason Exchange ESU cases are excluded: a vendor fix route exists (ESU). “Unpatched unless you pay” and “unpatchable” are different claims, and the difference is the whole decision.
What Our Risk Scores Say
We publish an EOL Risk Score (0–100) for every tracked version — lifecycle recency, attack surface, KEV exposure, extended-support availability — recalculated at every build.
| Version | EOL Risk Score | What drives it |
|---|---|---|
| macOS Ventura 13 | 90 | Off Apple's update list since September 15, 2025; OS attack surface; KEV exposure; no extended support exists. |
| macOS Sonoma 14 | 60 | Still updated (14.8.9) — but next in line to fall off the three-version list. |
| Windows 10 22H2 | 80 | Out of support October 14, 2025; KEV exposure; ESU exists — which is the one lever that changes this machine's reality. |
What to Do by August 21
- Supported Macs: install 26.6.1 / 15.7.9 / 14.8.9 now.
- Ventura and older: System Settings → General → Sharing → turn off Screen Sharing; never expose port 5900 beyond a trusted network. Then upgrade to a supported macOS, or replace hardware that cannot run one — there is no third option that ends with a patched machine.
- Windows 11 / supported Server: confirm April 2026 cumulative updates are applied; this one is four months old.
- Windows 10 with ESU: confirm KB5082200 (or your channel's equivalent) is actually installed — enrollment without deployment is a common gap.
- Windows 10 without ESU: block inbound UDP 500/4500 (or restrict to known peers) today, then make the real decision: enroll in ESU (consumer to October 2026, commercial to October 2028), upgrade to Windows 11, or retire the machine. The decision framework with costs is in Windows 10: upgrade, buy ESU, or replace?
Frequently Asked Questions
Is macOS Ventura patched for CVE-2026-65400?
No. Apple fixed the Screen Sharing authentication bypass on August 6, 2026 in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9 — the three macOS versions Apple currently maintains. macOS Ventura 13, which stopped receiving updates when Tahoe shipped on September 15, 2025, and everything older are not in any of the three advisories, and Apple does not sell extended support for old macOS versions. The only fix for a Ventura or older Mac is upgrading to a supported macOS, or replacing hardware that cannot run one.
What is CVE-2026-65400?
An improper-authentication flaw in macOS Screen Sharing: an attacker on the network can authenticate to Screen Sharing without valid credentials. Apple's advisory credits the discovery and describes the fix as improved state management. CISA added it to the Known Exploited Vulnerabilities catalog on August 18, 2026 with a federal remediation deadline of August 21 — KEV listing means exploitation in the wild is confirmed.
Is Windows 10 patched for CVE-2026-33824?
Only behind ESU. Microsoft patched the IKE double free (CVSS 9.8, unauthenticated remote code execution over UDP 500/4500) on April 14, 2026, and Windows 10 22H2 is in the update list — KB5082200. But Windows 10 22H2 ended support on October 14, 2025, so that update is delivered only to devices enrolled in Extended Security Updates. A Windows 10 machine without ESU has been exposed to a now actively-exploited critical flaw since April.
Does the KEV listing mean these bugs are being exploited?
Yes — that is the entry criterion. CISA adds a CVE to the Known Exploited Vulnerabilities catalog only on reliable evidence of active exploitation. Both entries carry an August 21, 2026 remediation deadline for US federal civilian agencies. Notably, Microsoft's own advisory assessed CVE-2026-33824 as 'Exploited: No' when it was published in April; the KEV listing four months later is what changed.
What can I do if I can't patch?
For Windows machines that cannot get the IKE fix, Microsoft's listed mitigation is to block inbound UDP 500 and 4500 where IKE is not used, or restrict them to known peer addresses — a stopgap, not a substitute. For Macs on Ventura or older, disable Screen Sharing (System Settings → General → Sharing) and keep port 5900 off the internet. Then fix the lifecycle problem: upgrade the OS, enroll in ESU (Windows), or replace the device.
Where do I check whether my OS version still gets security fixes?
Our macOS page lists every version's status under Apple's three-version practice, and the Windows page tracks every servicing channel including the ESU windows — Windows 10 22H2 consumer ESU runs to October 13, 2026 and commercial ESU to October 10, 2028. The EOL Checker answers for any product and version.
Related Resources
- macOS end of life — Apple's three-version practice and every version's status
- Windows 10 end of life · Windows 10: upgrade, buy ESU, or replace?
- vCenter 7.0 and CVE-2026-59310 — the third EOL story in the same KEV batch
- Exploited & Unpatchable — the KEV × end-of-life feed and its rules
- EOL Watch · EOL Checker · EOL Risk Score methodology