Skip to content

Release roundup

Apple security updates, September 2026: two critical macOS kernel flaws lead 98 fixes

Critical 9.8 Vendor: Apple 98 CVEs in scope Published

Apple's September 2026 security updates cover 98 CVEs: 2 critical, 34 high, 61 medium and 1 low. None is listed in CISA KEV or marked exploited. The two critical macOS kernel flaws are reachable over the network without credentials, so patch macOS first.

The release at a glance

Apple's September 2026 security updates cover 98 CVEs in scope for this roundup. By severity, the release contains 2 critical, 34 high, 61 medium and 1 low issue. By product, 95 CVEs affect macOS, 2 affect iOS and iPadOS, and 1 affects Xcode. No CVE in this release is marked as exploited or listed in CISA KEV. The most urgent issues are the two critical macOS kernel vulnerabilities, which have network attack vectors with no privileges or user interaction. Apple has published fixes; the full list is on Apple's release page.

What matters most

All of the most important CVEs in this release affect macOS.

  • CVE-2026-84520 is a critical buffer overflow, addressed with improved size validation. It is fixed in macOS Golden Gate 27. Its CVSS vector is network-based with no privileges or user interaction; Apple describes potential system termination or kernel memory corruption.
  • CVE-2026-43790 is a critical memory handling issue fixed in macOS Golden Gate 27, macOS Sequoia 15.8 and macOS Tahoe 26.7. A remote attacker may cause unexpected system termination or corrupt kernel memory.
  • CVE-2026-43692 and CVE-2026-65374 are high severity. CVE-2026-43692 is a validation issue fixed in macOS 27, 15.8 and 26.7; a remote user may cause an unexpected app termination or arbitrary code execution. CVE-2026-65374 is a memory corruption issue triggered by connecting to a malicious WebDAV server, also fixed in those three versions.
  • CVE-2026-84512 is a high severity buffer overflow fixed in macOS 27, 15.8 and 26.7; mounting a maliciously crafted disk image may cause system termination or corrupt kernel memory.
  • CVE-2026-65381, CVE-2026-84578, CVE-2026-84580, CVE-2026-84584, CVE-2026-84535 and CVE-2026-84577 are high severity sandbox escape or access issues. Fixed versions vary: most are fixed in macOS 27, 15.8 and 26.7; CVE-2026-84584 is fixed in macOS 27 only, and CVE-2026-84577 in macOS 26.7 and 27.

Patch in this order

  1. Patch the two critical macOS kernel vulnerabilities first: CVE-2026-84520 and CVE-2026-43790. They have CVSS scores of 9.8 and 9.1, with network attack vectors and no privileges or user interaction. For CVE-2026-43790, update to macOS Sequoia 15.8, Tahoe 26.7, or Golden Gate 27; for CVE-2026-84520, update to macOS Golden Gate 27.
  2. Next, patch the high-severity remote code execution issues CVE-2026-43692 and CVE-2026-65374, fixed in macOS Golden Gate 27, Sequoia 15.8 and Tahoe 26.7. These require user interaction but can lead to arbitrary code execution.
  3. Then patch the remaining high-severity macOS issues, particularly sandbox escape and malicious disk image flaws: CVE-2026-65381, CVE-2026-84512, CVE-2026-84578 and related sandbox escape CVEs in the same update. Fixed versions vary; refer to Apple's release page.
  4. Finally, apply the medium and low severity fixes for macOS, iOS and iPadOS, and Xcode as part of your normal patching cycle. No CVE in this release is listed in CISA KEV or marked exploited, so the priority is based on severity and exposure.

Beyond the patch

Apple's September update is a large but uncomplicated release: the highest-risk items are two macOS kernel issues with network reach, and most of the rest are broad macOS, iOS and Xcode fixes. Next month, have exposure data ready so you can identify which Macs are reachable before patch prioritisation; our Virtual CISO Services (vCISO) can help build that exposure view. If code execution or sandbox escape is attempted, Managed Detection & Response (MDR) provides the detection and response trail you need.

Every CVE in this release

CVEProductSeverity
CVE-2026-84520macOSCritical 9.8
CVE-2026-43790macOSCritical 9.1
CVE-2026-43692macOSHigh 8.8
CVE-2026-65374macOSHigh 8.8
CVE-2026-65381macOSHigh 8.8
CVE-2026-84512macOSHigh 8.8
CVE-2026-84578macOSHigh 8.8
CVE-2026-84580macOSHigh 8.4
CVE-2026-84581macOSHigh 8.4
CVE-2026-84584macOSHigh 8.4
CVE-2026-84535macOSHigh 8.2
CVE-2026-84577macOSHigh 8.2
CVE-2026-84516macOSHigh 8.1
CVE-2026-43684iOS and iPadOSHigh 7.8
CVE-2026-43691macOSHigh 7.8
CVE-2026-43786macOSHigh 7.8
CVE-2026-64712macOSHigh 7.8
CVE-2026-64790macOSHigh 7.8
CVE-2026-65362macOSHigh 7.8
CVE-2026-84505macOSHigh 7.8
CVE-2026-84506macOSHigh 7.8
CVE-2026-84515macOSHigh 7.8
CVE-2026-84568macOSHigh 7.8
CVE-2026-84631macOSHigh 7.8
CVE-2026-86917macOSHigh 7.8
CVE-2026-65364macOSHigh 7.5
CVE-2026-84549macOSHigh 7.5
CVE-2026-84553macOSHigh 7.5
CVE-2026-84543macOSHigh 7.5
CVE-2026-84544macOSHigh 7.5
CVE-2026-84563macOSHigh 7.5
CVE-2026-86894macOSHigh 7.5
CVE-2026-43683macOSHigh 7.1
CVE-2026-84565macOSHigh 7.1
CVE-2026-84572macOSHigh 7.1
CVE-2026-86901macOSHigh 7.1
CVE-2026-43788macOSMedium 6.6
CVE-2026-84537macOSMedium 6.6
CVE-2026-28934macOSMedium 6.5
CVE-2026-43677macOSMedium 6.5
Show all 98
CVEProductSeverity
CVE-2026-43719macOSMedium 6.5
CVE-2026-43791macOSMedium 6.5
CVE-2026-65365macOSMedium 6.5
CVE-2026-84509macOSMedium 6.5
CVE-2026-84536macOSMedium 6.5
CVE-2026-84538macOSMedium 6.5
CVE-2026-84588macOSMedium 6.5
CVE-2026-86869iOS and iPadOSMedium 6.5
CVE-2026-86900macOSMedium 6.5
CVE-2026-84619macOSMedium 6.1
CVE-2026-43787macOSMedium 5.9
CVE-2026-84522macOSMedium 5.9
CVE-2026-84554macOSMedium 5.9
CVE-2026-43789macOSMedium 5.5
CVE-2026-65342macOSMedium 5.5
CVE-2026-65378macOSMedium 5.5
CVE-2026-28937macOSMedium 5.5
CVE-2026-43741macOSMedium 5.5
CVE-2026-65361macOSMedium 5.5
CVE-2026-65369macOSMedium 5.5
CVE-2026-65376macOSMedium 5.5
CVE-2026-65380macOSMedium 5.5
CVE-2026-65382macOSMedium 5.5
CVE-2026-65393XcodeMedium 5.5
CVE-2026-65401macOSMedium 5.5
CVE-2026-65413macOSMedium 5.5
CVE-2026-84514macOSMedium 5.5
CVE-2026-84517macOSMedium 5.5
CVE-2026-84525macOSMedium 5.5
CVE-2026-84540macOSMedium 5.5
CVE-2026-84541macOSMedium 5.5
CVE-2026-84548macOSMedium 5.5
CVE-2026-84555macOSMedium 5.5
CVE-2026-84556macOSMedium 5.5
CVE-2026-84558macOSMedium 5.5
CVE-2026-84559macOSMedium 5.5
CVE-2026-84567macOSMedium 5.5
CVE-2026-84569macOSMedium 5.5
CVE-2026-84573macOSMedium 5.5
CVE-2026-84576macOSMedium 5.5
CVE-2026-84585macOSMedium 5.5
CVE-2026-84586macOSMedium 5.5
CVE-2026-84587macOSMedium 5.5
CVE-2026-84589macOSMedium 5.5
CVE-2026-84601macOSMedium 5.5
CVE-2026-84618macOSMedium 5.5
CVE-2026-86910macOSMedium 5.5
CVE-2026-86911macOSMedium 5.5
CVE-2026-43696macOSMedium 5.3
CVE-2026-86889macOSMedium 4.8
CVE-2026-43690macOSMedium 4.7
CVE-2026-84550macOSMedium 4.7
CVE-2026-65383macOSMedium 4.4
CVE-2026-84570macOSMedium 4.4
CVE-2026-84574macOSMedium 4.4
CVE-2026-86909macOSMedium 4.4
CVE-2026-43697macOSMedium 4.3
CVE-2026-86891macOSLow 3.5

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.