s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2026-28978

📛 CVE Title

CVE-2026-28978

Description

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A malicious app may be able to break out of its sandbox.

Overview

State
PUBLISHED
Assigner (CNA)
apple
CVSS severity
high
CVSS score
CVSS 8.8 / 10 8.8 8.8 / 10
CVSS vector
AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Effective score
8.8 / 10 HIGH source: CNA overview
CWE(s)
Reserved
2026-03-03
Published
2026-05-11 22:07 UTC
Last updated
2026-05-13 14:06 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/28xxx/CVE-2026-28978.json
Linked Threat
CVE-2026-28978 — CVE-2026-28978

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2026-05-11 21:18:58 UTC
NVD last modified
2026-05-13 14:34:55 UTC
NVD CVSS v3.1
CVSS 8.8 / 10 8.8 8.8 / 10 HIGH source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
NVD CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitability subscore
2.0 / 10
Impact subscore
6.0 / 10
EPSS score
0.0001 (probability of exploitation in next 30 days)
EPSS percentile
0.98% vs all CVEs — higher = more likely to be exploited, as of 2026-05-25

NVD-assigned CWE(s): CWE-284 (differs from the CNA list above)

NVD / KEV / EPSS data refreshed 2026-05-25 17:22 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2026-29277
Assigner
apple
Published
May 11, 2026, 8:07:41 PM
Updated
May 13, 2026, 12:06:11 PM
EUVD base score (CVSS 3.1)
8.8 / 10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EUVD-reported EPSS
0.0100
Vendors
Apple
Products
macOS (0 <15.7.7)
macOS (0 <14.8.7)
macOS (0 <26.5)

ENISA description: A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A malicious app may be able to break out of its sandbox.

EUVD references (3)

Affected products (1)

VendorProductVersionsPlatforms
Apple macOS 0 (affected), 0 (affected), 0 (affected)

Affected products — CPE 2.3 (1) NVD

NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.

  • cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Vendor references (3)

References embedded in the original CVE record by the assigning CNA.

MITRE references (3) cveawg.mitre.org

Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.

Web references (7)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

NVD-tagged references (3)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

Remediations (16)

Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

  • web:cisa.gov

    Update (08/12/2025): CISA has updated this alert to provide clarification on identifying Exchange Servers on an organization's networks and provided further guidance on running the Microsoft Exchange Health Checker. Update (08/07/2025): CISA issued Emergency Directive (ED) 25-02: Mitigate Microsoft Exchange Vulnerability in response to CVE -2025-53786

    2026-05-23 21:00 UTC
  • web:krebsonsecurity.com

    Microsoft expects that exploitation is more likely. May's Patch Tuesday is a welcome respite from April, which saw Microsoft fix a near-record 167 security flaws.

    2026-05-23 21:00 UTC
  • web:nvd.nist.gov

    An official website of the United States government Here's how you know

    2026-05-23 21:00 UTC
  • web:securitricks.com

    CVE CVE-2026-28978 - Score : None - Source : product-security@apple.com - Description : A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5.

    2026-05-23 21:00 UTC
  • web:techcommunity.microsoft.com

    We wanted to tell you how to address the Exchange Server May 2026 vulnerability CVE - 2026 -42897.

    2026-05-23 21:00 UTC
  • web:windowsforum.com

    Microsoft's Fastest Fix Is a Mitigation , Not a Patch The important detail in Microsoft's May 14 notice is that there is no permanent Exchange security update available yet for CVE - 2026 -42897. Microsoft says it is working on one and will release it later for affected supported paths, but today's defensive action is mitigation .

    2026-05-23 21:00 UTC
  • web:www.bugcrowd.com

    Vulnerability mitigation is typically considered a temporary or interim solution. While mitigation measures can reduce the immediate risk associated with vulnerabilities, they may not provide a permanent fix . Organizations should aim to prioritize and plan for complete vulnerability remediation whenever feasible and allocate resources accordingly.

    2026-05-23 21:00 UTC
  • web:www.helient.com

    Conclusion Helient strongly recommends customers immediately review their Exchange Server environments for exposure to CVE - 2026 -42897 and enable the appropriate mitigation . Given the active exploitation and high severity, a rapid response and validation approach is critical.

    2026-05-23 21:00 UTC
  • web:www.kiteworks.com

    Microsoft's May 2026 Patch Tuesday, released just 48 hours earlier, fixed 137 vulnerabilities and contained zero zero-days. Then this landed — out of band, with no permanent patch in sight, only temporary mitigations through the Exchange Emergency Mitigation Service or the Exchange On-premises Mitigation Tool.

    2026-05-23 21:00 UTC
  • web:zecurit.com

    Get the complete breakdown of Microsoft's May 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .

    2026-05-23 21:00 UTC
  • web:blackbeltsecure.com

    Discover what businesses must do about the critical Microsoft Exchange Server zero-day CVE - 2026 -42897 actively exploited in the wild. This guide details immediate mitigations for Exchange Server 2016/2019, long-term recommendations, and how to protect your organization from this XSS vulnerability in OWA. Don't wait for the patch — act now.

    2026-05-26 02:51 UTC
  • web:cibersafety.com

    Microsoft has released an emergency mitigation for a Cross-Site Scripting (XSS) vulnerability in Exchange Server that is being actively exploited CVE - 2026 -42897 affects Exchange Server 2016, 2019 and the Subscription (SE) edition, and allows an attacker to execute arbitrary JavaScript code in the victim's browser through a specially crafted email.

    2026-05-26 02:51 UTC
  • web:securereading.com

    Microsoft confirms active exploitation of CVE - 2026 -42897 in on-prem Exchange Server, allowing attackers to use crafted emails for spoofing and browser-based code execution.

    2026-05-26 02:51 UTC
  • web:www.forbes.com

    Updated May 17: This article, originally published May 16, has been updated to include further details on the emergency mitigation process recommended after the CVE - 2026 -42897 Microsoft Exchange ...

    2026-05-26 02:51 UTC
  • web:www.harperfoley.com

    Microsoft Shipped Exchange CVE - 2026 -42897 Without a Patch . The DDQ Should Ask Whether Your Mailbox Tier's Emergency Mitigation Service Is Still Running. Microsoft's advisory for CVE - 2026 -42897 ships no security update and depends on the Exchange Emergency Mitigation Service applying M2.1.x.

    2026-05-26 02:51 UTC
  • web:www.messageware.com

    CVE - 2026 -42897 is an actively exploited Exchange Server vulnerability. Learn what's affected, the current risk level, and how Microsoft is mitigating it.

    2026-05-26 02:51 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2026-28978.json.

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "LOCAL",
              "availabilityImpact": "HIGH",
              "baseScore": 8.8,
              "baseSeverity": "HIGH",
              "confidentialityImpact": "HIGH",
              "integrityImpact": "HIGH",
              "privilegesRequired": "LOW",
              "scope": "CHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2026-28978",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-05-13T03:57:47.389519Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-284",
                "description": "CWE-284 Improper Access Control",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-05-13T12:06:11.860Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "macOS",
          "vendor": "Apple",
          "versions": [
            {
              "lessThan": "14.8.7",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            },
            {
              "lessThan": "15.7.7",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            },
            {
              "lessThan": "26.5",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A malicious app may be able to break out of its sandbox."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "A malicious app may be able to break out of its sandbox",
              "lang": "en"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-05-11T20:07:41.365Z",
        "orgId": "286789f9-fbc2-4510-9f9a-43facdede74c",
        "shortName": "apple"
      },
      "references": [
        {
          "url": "https://support.apple.com/en-us/127115"
        },
        {
          "url": "https://support.apple.com/en-us/127116"
        },
        {
          "url": "https://support.apple.com/en-us/127117"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "286789f9-fbc2-4510-9f9a-43facdede74c",
    "assignerShortName": "apple",
    "cveId": "CVE-2026-28978",
    "datePublished": "2026-05-11T20:07:41.365Z",
    "dateReserved": "2026-03-03T16:36:03.993Z",
    "dateUpdated": "2026-05-13T12:06:11.860Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}