Skip to content

Release roundup

Apple security updates, September 2026: four high-severity macOS flaws lead eight fixes

High 8.8 Vendor: Apple 8 CVEs in scope Published

Apple's September 2026 security updates cover eight macOS CVEs: four high, four medium. None is listed in CISA KEV or marked exploited. The standout is a remote afpfs handling flaw that can cause kernel memory corruption; two local privilege escalation issues also need prompt patching.

The release at a glance

Apple's September 2026 security update set covers eight macOS CVEs: four high and four medium severity. The highest-scoring item is CVE-2026-43815 at 8.8, a buffer overflow in afpfs handling; connecting to a malicious afpfs server may lead to kernel memory corruption. No CVE in this release is marked as exploited or listed in CISA KEV, and Apple does not state active exploitation. The remaining high-severity issues include two local privilege escalation flaws and one network-reachable authentication issue that may cause unexpected system termination. Patches are available across macOS Sequoia, Sonoma, Tahoe and Golden Gate depending on the CVE.

What matters most

All eight CVEs affect macOS. Start with CVE-2026-43815: a buffer overflow in afpfs handling fixed in macOS Sequoia 15.7.8, Sonoma 14.8.8 and Tahoe 26.6. It is the highest-scoring item at 8.8, and connecting to a malicious afpfs server may lead to kernel memory corruption.

Two local privilege escalation issues follow. CVE-2026-43783 is a race condition fixed only in macOS Tahoe 26.6; a malicious app may gain root privileges. CVE-2026-64701 is a permissions issue fixed in macOS Sequoia 15.7.8 and Tahoe 26.6; a malicious app may also gain root privileges.

CVE-2026-65375 is an authentication issue fixed in macOS Golden Gate 27, Sequoia 15.8 and Tahoe 26.6. It is network-reachable with no credentials or user interaction, and an app may cause unexpected system termination; CVSS 7.5.

The medium-severity items are CVE-2026-43761, an out-of-bounds write when mounting a malicious disk image; CVE-2026-28899, a logic issue that may allow an app to bypass Gatekeeper checks; CVE-2026-28933, a use-after-free that may cause unexpected system termination; and CVE-2026-84562, a race condition that may allow an app to access protected user data. Fixes are available for each across the macOS releases listed in the update.

Patch in this order

  1. Apply updates for CVE-2026-43815 first on Macs that may connect to untrusted AFP servers or networks. Fixed in macOS Sequoia 15.7.8, Sonoma 14.8.8 and Tahoe 26.6.
  1. Patch the two local privilege escalation issues next: CVE-2026-43783, fixed in macOS Tahoe 26.6, and CVE-2026-64701, fixed in macOS Sequoia 15.7.8 and Tahoe 26.6. These matter most where local users or unmanaged apps are present.
  1. Address CVE-2026-65375 on internet-facing or multi-user Macs. Fixed in macOS Golden Gate 27, Sequoia 15.8 and Tahoe 26.6.
  1. Apply the remaining medium-severity fixes: CVE-2026-43761 in macOS Sequoia 15.7.8, Sonoma 14.8.8 and Tahoe 26.6; CVE-2026-28899 in macOS Golden Gate 27, Sequoia 15.8, Tahoe 26.6 and Tahoe 26.7; CVE-2026-28933 in macOS Sequoia 15.7.8, Sonoma 14.8.8 and Tahoe 26.6; and CVE-2026-84562 in macOS Tahoe 26.6.

There is no CISA KEV due date because none of these CVEs is listed in KEV.

Beyond the patch

For the network-reachable items in this release, Virtual CISO Services gives you an external view of exposed Apple services and open ports before an update cycle forces priority decisions. Implementation & Assessment Services can test whether the local privilege and permissions flaws are reachable in your specific macOS baseline.

Every CVE in this release

CVEProductSeverity
CVE-2026-43815macOSHigh 8.8
CVE-2026-43783macOSHigh 7.8
CVE-2026-64701macOSHigh 7.8
CVE-2026-65375macOSHigh 7.5
CVE-2026-43761macOSMedium 6.5
CVE-2026-28899macOSMedium 5.5
CVE-2026-28933macOSMedium 5.5
CVE-2026-84562macOSMedium 4.7

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.