Release roundup
Apple security updates, September 2026: two critical macOS kernel flaws lead 98 fixes
Apple's September 2026 security updates cover 98 CVEs: 2 critical, 34 high, 61 medium and 1 low. None is listed in CISA KEV or marked exploited. The two critical macOS kernel flaws are reachable over the network without credentials, so patch macOS first.
The release at a glance
Apple's September 2026 security updates cover 98 CVEs in scope for this roundup. By severity, the release contains 2 critical, 34 high, 61 medium and 1 low issue. By product, 95 CVEs affect macOS, 2 affect iOS and iPadOS, and 1 affects Xcode. No CVE in this release is marked as exploited or listed in CISA KEV. The most urgent issues are the two critical macOS kernel vulnerabilities, which have network attack vectors with no privileges or user interaction. Apple has published fixes; the full list is on Apple's release page.
What matters most
All of the most important CVEs in this release affect macOS.
- CVE-2026-84520 is a critical buffer overflow, addressed with improved size validation. It is fixed in macOS Golden Gate 27. Its CVSS vector is network-based with no privileges or user interaction; Apple describes potential system termination or kernel memory corruption.
- CVE-2026-43790 is a critical memory handling issue fixed in macOS Golden Gate 27, macOS Sequoia 15.8 and macOS Tahoe 26.7. A remote attacker may cause unexpected system termination or corrupt kernel memory.
- CVE-2026-43692 and CVE-2026-65374 are high severity. CVE-2026-43692 is a validation issue fixed in macOS 27, 15.8 and 26.7; a remote user may cause an unexpected app termination or arbitrary code execution. CVE-2026-65374 is a memory corruption issue triggered by connecting to a malicious WebDAV server, also fixed in those three versions.
- CVE-2026-84512 is a high severity buffer overflow fixed in macOS 27, 15.8 and 26.7; mounting a maliciously crafted disk image may cause system termination or corrupt kernel memory.
- CVE-2026-65381, CVE-2026-84578, CVE-2026-84580, CVE-2026-84584, CVE-2026-84535 and CVE-2026-84577 are high severity sandbox escape or access issues. Fixed versions vary: most are fixed in macOS 27, 15.8 and 26.7; CVE-2026-84584 is fixed in macOS 27 only, and CVE-2026-84577 in macOS 26.7 and 27.
Patch in this order
- Patch the two critical macOS kernel vulnerabilities first: CVE-2026-84520 and CVE-2026-43790. They have CVSS scores of 9.8 and 9.1, with network attack vectors and no privileges or user interaction. For CVE-2026-43790, update to macOS Sequoia 15.8, Tahoe 26.7, or Golden Gate 27; for CVE-2026-84520, update to macOS Golden Gate 27.
- Next, patch the high-severity remote code execution issues CVE-2026-43692 and CVE-2026-65374, fixed in macOS Golden Gate 27, Sequoia 15.8 and Tahoe 26.7. These require user interaction but can lead to arbitrary code execution.
- Then patch the remaining high-severity macOS issues, particularly sandbox escape and malicious disk image flaws: CVE-2026-65381, CVE-2026-84512, CVE-2026-84578 and related sandbox escape CVEs in the same update. Fixed versions vary; refer to Apple's release page.
- Finally, apply the medium and low severity fixes for macOS, iOS and iPadOS, and Xcode as part of your normal patching cycle. No CVE in this release is listed in CISA KEV or marked exploited, so the priority is based on severity and exposure.
Beyond the patch
Apple's September update is a large but uncomplicated release: the highest-risk items are two macOS kernel issues with network reach, and most of the rest are broad macOS, iOS and Xcode fixes. Next month, have exposure data ready so you can identify which Macs are reachable before patch prioritisation; our Virtual CISO Services (vCISO) can help build that exposure view. If code execution or sandbox escape is attempted, Managed Detection & Response (MDR) provides the detection and response trail you need.
Every CVE in this release
| CVE | Product | Severity | |
|---|---|---|---|
| CVE-2026-84520 | macOS | Critical 9.8 | |
| CVE-2026-43790 | macOS | Critical 9.1 | |
| CVE-2026-43692 | macOS | High 8.8 | |
| CVE-2026-65374 | macOS | High 8.8 | |
| CVE-2026-65381 | macOS | High 8.8 | |
| CVE-2026-84512 | macOS | High 8.8 | |
| CVE-2026-84578 | macOS | High 8.8 | |
| CVE-2026-84580 | macOS | High 8.4 | |
| CVE-2026-84581 | macOS | High 8.4 | |
| CVE-2026-84584 | macOS | High 8.4 | |
| CVE-2026-84535 | macOS | High 8.2 | |
| CVE-2026-84577 | macOS | High 8.2 | |
| CVE-2026-84516 | macOS | High 8.1 | |
| CVE-2026-43684 | iOS and iPadOS | High 7.8 | |
| CVE-2026-43691 | macOS | High 7.8 | |
| CVE-2026-43786 | macOS | High 7.8 | |
| CVE-2026-64712 | macOS | High 7.8 | |
| CVE-2026-64790 | macOS | High 7.8 | |
| CVE-2026-65362 | macOS | High 7.8 | |
| CVE-2026-84505 | macOS | High 7.8 | |
| CVE-2026-84506 | macOS | High 7.8 | |
| CVE-2026-84515 | macOS | High 7.8 | |
| CVE-2026-84568 | macOS | High 7.8 | |
| CVE-2026-84631 | macOS | High 7.8 | |
| CVE-2026-86917 | macOS | High 7.8 | |
| CVE-2026-65364 | macOS | High 7.5 | |
| CVE-2026-84549 | macOS | High 7.5 | |
| CVE-2026-84553 | macOS | High 7.5 | |
| CVE-2026-84543 | macOS | High 7.5 | |
| CVE-2026-84544 | macOS | High 7.5 | |
| CVE-2026-84563 | macOS | High 7.5 | |
| CVE-2026-86894 | macOS | High 7.5 | |
| CVE-2026-43683 | macOS | High 7.1 | |
| CVE-2026-84565 | macOS | High 7.1 | |
| CVE-2026-84572 | macOS | High 7.1 | |
| CVE-2026-86901 | macOS | High 7.1 | |
| CVE-2026-43788 | macOS | Medium 6.6 | |
| CVE-2026-84537 | macOS | Medium 6.6 | |
| CVE-2026-28934 | macOS | Medium 6.5 | |
| CVE-2026-43677 | macOS | Medium 6.5 |
Show all 98
| CVE | Product | Severity | |
|---|---|---|---|
| CVE-2026-43719 | macOS | Medium 6.5 | |
| CVE-2026-43791 | macOS | Medium 6.5 | |
| CVE-2026-65365 | macOS | Medium 6.5 | |
| CVE-2026-84509 | macOS | Medium 6.5 | |
| CVE-2026-84536 | macOS | Medium 6.5 | |
| CVE-2026-84538 | macOS | Medium 6.5 | |
| CVE-2026-84588 | macOS | Medium 6.5 | |
| CVE-2026-86869 | iOS and iPadOS | Medium 6.5 | |
| CVE-2026-86900 | macOS | Medium 6.5 | |
| CVE-2026-84619 | macOS | Medium 6.1 | |
| CVE-2026-43787 | macOS | Medium 5.9 | |
| CVE-2026-84522 | macOS | Medium 5.9 | |
| CVE-2026-84554 | macOS | Medium 5.9 | |
| CVE-2026-43789 | macOS | Medium 5.5 | |
| CVE-2026-65342 | macOS | Medium 5.5 | |
| CVE-2026-65378 | macOS | Medium 5.5 | |
| CVE-2026-28937 | macOS | Medium 5.5 | |
| CVE-2026-43741 | macOS | Medium 5.5 | |
| CVE-2026-65361 | macOS | Medium 5.5 | |
| CVE-2026-65369 | macOS | Medium 5.5 | |
| CVE-2026-65376 | macOS | Medium 5.5 | |
| CVE-2026-65380 | macOS | Medium 5.5 | |
| CVE-2026-65382 | macOS | Medium 5.5 | |
| CVE-2026-65393 | Xcode | Medium 5.5 | |
| CVE-2026-65401 | macOS | Medium 5.5 | |
| CVE-2026-65413 | macOS | Medium 5.5 | |
| CVE-2026-84514 | macOS | Medium 5.5 | |
| CVE-2026-84517 | macOS | Medium 5.5 | |
| CVE-2026-84525 | macOS | Medium 5.5 | |
| CVE-2026-84540 | macOS | Medium 5.5 | |
| CVE-2026-84541 | macOS | Medium 5.5 | |
| CVE-2026-84548 | macOS | Medium 5.5 | |
| CVE-2026-84555 | macOS | Medium 5.5 | |
| CVE-2026-84556 | macOS | Medium 5.5 | |
| CVE-2026-84558 | macOS | Medium 5.5 | |
| CVE-2026-84559 | macOS | Medium 5.5 | |
| CVE-2026-84567 | macOS | Medium 5.5 | |
| CVE-2026-84569 | macOS | Medium 5.5 | |
| CVE-2026-84573 | macOS | Medium 5.5 | |
| CVE-2026-84576 | macOS | Medium 5.5 | |
| CVE-2026-84585 | macOS | Medium 5.5 | |
| CVE-2026-84586 | macOS | Medium 5.5 | |
| CVE-2026-84587 | macOS | Medium 5.5 | |
| CVE-2026-84589 | macOS | Medium 5.5 | |
| CVE-2026-84601 | macOS | Medium 5.5 | |
| CVE-2026-84618 | macOS | Medium 5.5 | |
| CVE-2026-86910 | macOS | Medium 5.5 | |
| CVE-2026-86911 | macOS | Medium 5.5 | |
| CVE-2026-43696 | macOS | Medium 5.3 | |
| CVE-2026-86889 | macOS | Medium 4.8 | |
| CVE-2026-43690 | macOS | Medium 4.7 | |
| CVE-2026-84550 | macOS | Medium 4.7 | |
| CVE-2026-65383 | macOS | Medium 4.4 | |
| CVE-2026-84570 | macOS | Medium 4.4 | |
| CVE-2026-84574 | macOS | Medium 4.4 | |
| CVE-2026-86909 | macOS | Medium 4.4 | |
| CVE-2026-43697 | macOS | Medium 4.3 | |
| CVE-2026-86891 | macOS | Low 3.5 |
References
CVE
- CVE-2026-84520 — cve.org
- CVE-2026-84520 — NVD
- CVE-2026-43790 — cve.org
- CVE-2026-43790 — NVD
- CVE-2026-43692 — cve.org
- CVE-2026-43692 — NVD
- CVE-2026-65374 — cve.org
- CVE-2026-65374 — NVD
- CVE-2026-65381 — cve.org
- CVE-2026-65381 — NVD
- CVE-2026-84512 — cve.org
- CVE-2026-84512 — NVD
- CVE-2026-84578 — cve.org
- CVE-2026-84578 — NVD
- CVE-2026-84580 — cve.org
- CVE-2026-84580 — NVD
- CVE-2026-84581 — cve.org
- CVE-2026-84581 — NVD
- CVE-2026-84584 — cve.org
- CVE-2026-84584 — NVD
- CVE-2026-84535 — cve.org
- CVE-2026-84535 — NVD
- CVE-2026-84577 — cve.org
- CVE-2026-84577 — NVD