Skip to content

Release roundup

Apple security updates, September 2026: seven high-severity fixes across 34 CVEs

High 8.8 Vendor: Apple 34 CVEs in scope Published

Apple's September 2026 updates address 34 CVEs across Safari, iOS, iPadOS, macOS, tvOS, visionOS and watchOS. No CVE is in CISA KEV. Start with the seven high-severity web-content and kernel issues, then the medium and low items.

The release at a glance

Apple's September 2026 security updates cover 34 CVEs across Safari, iOS, iPadOS, macOS, tvOS, visionOS and watchOS. The release comprises 7 high-severity, 25 medium-severity and 2 low-severity issues. The high-severity items are concentrated in web-content memory corruption, image processing and kernel-memory handling.

None of the 34 CVEs appears in CISA KEV, and none is currently flagged as exploited. Apple fixes the main issues in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, macOS Tahoe 26.6.2, macOS Sequoia 15.8, tvOS 27, visionOS 27 and watchOS 27.

What matters most

Safari and web-content handling account for the most immediately reachable risk. CVE-2026-65390, CVE-2026-65391 and CVE-2026-43794 are memory-corruption issues triggered by maliciously crafted web content, each with a CVSS 3.1 base score of 8.8. They affect Safari before 26.6.1, iOS and iPadOS before 26.6.1, macOS Tahoe before 26.6.2, and tvOS, visionOS and watchOS before 27; CVE-2026-43794 also affects iOS and iPadOS before 18.7.10 and is fixed in 18.7.10. CVE-2026-64778 is a data-leak issue from a malicious website with a CVSS 3.1 base score of 6.5, fixed in the same Safari 26.6.1, iOS/iPadOS 18.7.10 and 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27 and watchOS 27 updates.

On Apple's operating systems, CVE-2026-65346 is an image-processing integer overflow that can lead to arbitrary code execution; it affects iOS and iPadOS before 26.6.1, macOS before Sequoia 15.8 or Tahoe 26.6.2, and tvOS, visionOS and watchOS before 27. CVE-2026-28935 and CVE-2026-65343 are remotely reachable without user interaction. CVE-2026-28935 may cause unexpected termination or corrupt kernel memory; CVE-2026-65343 may cause unexpected system termination. CVE-2026-28935 is fixed in iOS/iPadOS 26.6.1, macOS Sequoia 15.8 and Tahoe 26.6.2, and tvOS/visionOS/watchOS 27. CVE-2026-65343 is fixed in iOS/iPadOS 26.6.1, macOS Tahoe 26.6.2, and tvOS/visionOS/watchOS 27. CVE-2026-64736 is a locally triggered high-severity kernel-memory issue fixed in iOS/iPadOS 26.6.1, macOS Sequoia 15.8 and Tahoe 26.6.2, and tvOS/visionOS/watchOS 27.

Patch in this order

  1. Patch Safari to 26.6.1, iOS and iPadOS to 26.6.1, and macOS Tahoe to 26.6.2 first. This closes the three high-severity web-content issues CVE-2026-65390, CVE-2026-65391 and CVE-2026-43794, the remotely reachable termination issue CVE-2026-65343, and the data leak CVE-2026-64778.
  1. For devices remaining on the previous supported iOS and iPadOS branch, deploy iOS 18.7.10 and iPadOS 18.7.10. This addresses CVE-2026-43794, CVE-2026-64715, CVE-2026-64778 and CVE-2026-64787.
  1. Update macOS Sequoia to 15.8. This includes the image-processing arbitrary code execution issue CVE-2026-65346 and the kernel-memory issues CVE-2026-28935 and CVE-2026-64736.
  1. Update tvOS, visionOS and watchOS to 27 wherever those platforms are used. Apple's fix lists for these releases include CVE-2026-65390, CVE-2026-65391, CVE-2026-65346, CVE-2026-43794, CVE-2026-28935, CVE-2026-65343 and CVE-2026-64736.
  1. Apply the remaining medium and low items as part of the same platform update cycle. There is no CISA KEV due date because no CVE in this release is listed in KEV.

Beyond the patch

For an Apple estate, the practical work next month is not reading 34 individual CVEs but keeping the device and browser inventory accurate and testing before deployment. Supply Chain Defense & Third-Party Risk can place Apple updates alongside the rest of your third-party software risk, while Managed Detection & Response can watch for code execution or unexpected termination behaviour that might indicate an unpatched device reaching a malicious page or image.

Every CVE in this release

CVEProductSeverity
CVE-2026-65390SafariHigh 8.8
CVE-2026-65391SafariHigh 8.8
CVE-2026-65346iOS and iPadOSHigh 8.8
CVE-2026-43794SafariHigh 8.8
CVE-2026-28935iOS and iPadOSHigh 7.5
CVE-2026-65343iOS and iPadOSHigh 7.5
CVE-2026-64736iOS and iPadOSHigh 7.1
CVE-2026-65349iOS and iPadOSMedium 6.6
CVE-2026-64715SafariMedium 6.5
CVE-2026-64778SafariMedium 6.5
CVE-2026-64787SafariMedium 6.5
CVE-2026-65330iOS and iPadOSMedium 6.5
CVE-2026-65347iOS and iPadOSMedium 6.5
CVE-2026-64788iOS and iPadOSMedium 5.4
CVE-2026-65341SafariMedium 5.4
CVE-2026-65339iOS and iPadOSMedium 5.0
CVE-2026-65352iOS and iPadOSMedium 4.3
CVE-2026-65355iOS and iPadOSMedium 4.3
CVE-2026-64780SafariMedium 4.3
CVE-2026-43795SafariMedium 4.3
CVE-2026-64781SafariMedium 4.3
CVE-2026-64784SafariMedium 4.3
CVE-2026-65331SafariMedium 4.3
CVE-2026-65332SafariMedium 4.3
CVE-2026-65333SafariMedium 4.3
CVE-2026-65334SafariMedium 4.3
CVE-2026-65335SafariMedium 4.3
CVE-2026-65336SafariMedium 4.3
CVE-2026-65337SafariMedium 4.3
CVE-2026-65338SafariMedium 4.3
CVE-2026-65340SafariMedium 4.3
CVE-2026-65351SafariMedium 4.3
CVE-2026-64779SafariLow 3.1
CVE-2026-64782SafariLow 3.1

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.