Skip to content

Release roundup

Apple security updates, September 2026: nine CVEs led by network privacy and memory-handling flaws

High 7.8 Vendor: Apple 9 CVEs in scope Published

Apple's September 2026 release covers 9 CVEs across iOS, iPadOS, macOS, tvOS, watchOS and visionOS. Three high, five medium, one low; none in CISA KEV or exploited. Patch iOS/iPadOS 26.6 first for the network-reachable fingerprinting flaw, then memory-handling fixes.

The release at a glance

Apple's September 2026 security release covers nine CVEs. The severity split is three high, five medium and one low. None of the CVEs is recorded as exploited and none appears in CISA KEV, so there is no active exploitation indicated in this set. The issues are concentrated in memory-handling and data-access paths, with the main exposure being an iOS/iPadOS privacy flaw reachable over the network without credentials.

The updates are published in Apple's central release note at Apple security updates, September 2026. Fixes are spread across iOS and iPadOS, macOS, tvOS, watchOS and visionOS.

What matters most

iOS and iPadOS. CVE-2026-28938 is the first to review: fixed in iOS 26.6 and iPadOS 26.6, it is a high-severity privacy flaw that may allow an app to fingerprint the user, with a network vector and no privileges or user interaction required. CVE-2026-43702 is a high-severity memory-handling issue fixed in iOS/iPadOS 26.6 and 26.7; processing a maliciously crafted video file may terminate the app unexpectedly or corrupt process memory. CVE-2026-65357, also high severity, is fixed in iOS/iPadOS 26.6 and may cause unexpected system termination or write kernel memory. Medium-severity issues include CVE-2026-64717, a race condition that can corrupt kernel memory; CVE-2026-43762 and CVE-2026-65353, which allow an app to access sensitive user data; and CVE-2026-43808 and CVE-2026-65407, memory-management flaws that can cause unexpected system termination.

macOS. Several of the same fixes extend to macOS. CVE-2026-43702 is fixed in macOS Sequoia 15.8, Tahoe 26.6 and Tahoe 26.7. CVE-2026-65357 is fixed in Tahoe 26.6. CVE-2026-64717 is fixed in Sequoia 15.7.8 and Tahoe 26.6. CVE-2026-43762 and CVE-2026-65353 are fixed in Tahoe 26.6. CVE-2026-65407 has the broadest macOS coverage, with fixes in macOS Golden Gate 27, Sequoia 15.8, Tahoe 26.6 and Tahoe 26.7.

tvOS, watchOS and visionOS. These platforms share several of the same memory-handling and access issues. CVE-2026-43702 is fixed in tvOS 26.6 and watchOS 26.6. CVE-2026-65357 and CVE-2026-64717 are fixed in tvOS 26.6, visionOS 26.6 and watchOS 26.6; they can lead to kernel memory corruption or unexpected system termination.

Patch in this order

  1. Start with iOS and iPadOS. Apply iOS 26.6 and iPadOS 26.6 to close CVE-2026-28938, the only flaw in this release with a network vector and no privileges or user interaction required.
  2. Patch the high-severity memory-handling flaws next. For CVE-2026-43702, apply iOS/iPadOS 26.6 or 26.7, macOS Sequoia 15.8, Tahoe 26.6 or Tahoe 26.7, tvOS 26.6 and watchOS 26.6. For CVE-2026-65357, apply iOS/iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6 and watchOS 26.6.
  3. Move through the medium-severity set. CVE-2026-64717 is fixed in iOS/iPadOS 18.7.10 or 26.6, macOS Sequoia 15.7.8 or Tahoe 26.6, tvOS 26.6, visionOS 26.6 and watchOS 26.6. CVE-2026-43762 is fixed in iOS/iPadOS 26.6, macOS Tahoe 26.6 and visionOS 26.6. CVE-2026-65353 is fixed in iOS/iPadOS 26.6 and macOS Tahoe 26.6. CVE-2026-43808 is fixed in iOS/iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6 and watchOS 26.6. CVE-2026-65407 is fixed in iOS/iPadOS 26.6, 26.7 or 27, macOS Sequoia 15.8, Tahoe 26.6, Tahoe 26.7 or Golden Gate 27, tvOS 26.6 or 27, visionOS 26.6 or 27, and watchOS 26.6 or 27.
  4. Apply the remaining low-severity fix, CVE-2026-65371, as part of the same update cycle. It is fixed in iOS/iPadOS 26.6, macOS Sequoia 15.8, Tahoe 26.6, tvOS 26.6, visionOS 26.6 and watchOS 26.6.

Beyond the patch

This is a standard vendor release rather than an emergency: no CVE is listed in CISA KEV or recorded as exploited, which makes September a prioritisation exercise. Supply Chain Defense & Third-Party Risk helps keep Apple software across your estate visible as a third-party risk, while Virtual CISO Services (vCISO) adds exposure management for reachable services and open ports so a future network-vector issue does not sit unnoticed.

Every CVE in this release

CVEProductSeverity
CVE-2026-43702iOS and iPadOSHigh 7.8
CVE-2026-65357iOS and iPadOSHigh 7.8
CVE-2026-28938iOS and iPadOSHigh 7.5
CVE-2026-64717iOS and iPadOSMedium 6.3
CVE-2026-43762iOS and iPadOSMedium 5.5
CVE-2026-43808iOS and iPadOSMedium 5.5
CVE-2026-65353iOS and iPadOSMedium 5.5
CVE-2026-65407iOS and iPadOSMedium 5.5
CVE-2026-65371iOS and iPadOSLow 3.3

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.