Release roundup
Apple security updates, September 2026: five critical core OS flaws lead 118 fixes
Apple's September 2026 update addresses 118 CVEs across iOS, iPadOS, macOS, tvOS, visionOS, watchOS and Safari. No in-scope CVE is exploited or in CISA KEV. Five critical and 28 high severity flaws, chiefly memory corruption and permission issues, call for prompt broad patching.
The release at a glance
Apple's September 2026 security release covers 118 CVEs across iOS, iPadOS, macOS, tvOS, visionOS, watchOS and Safari. The distribution is five critical, 28 high, 80 medium and five low severity issues. No in-scope CVE is marked as exploited and none appears in CISA's Known Exploited Vulnerabilities catalog. The highest-impact items are memory corruption, permissions and certificate validation flaws in core operating system components. Updates are available for iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, tvOS 27, visionOS 27 and watchOS 27. See Apple's release notes for the full mapping.
What matters most
These are the first CVEs to review:
Core operating systems (iOS, iPadOS, macOS, tvOS, visionOS, watchOS)
- CVE-2026-65414: out-of-bounds write; a remote attacker may be able to cause unexpected app termination or arbitrary code execution. Fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, tvOS 27, visionOS 27 and watchOS 27.
- CVE-2026-84561: double free; an app may be able to cause unexpected system termination or corrupt kernel memory. Fixed in the same versions as CVE-2026-65414.
- CVE-2026-84609: permissions issue; an app may be able to modify protected system files. Fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27 and watchOS 27.
- CVE-2026-86881: certificate validation issue; an attacker with a compromised intermediate certificate authority may issue certificates with arbitrary extended key usages. Fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, tvOS 27, visionOS 27 and watchOS 27.
- CVE-2026-43686: use-after-free when connecting to a malicious NFS server; may lead to kernel memory corruption. Fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, tvOS 27, visionOS 27 and watchOS 27.
- CVE-2026-65354: sandbox escape; a malicious app may break out of its sandbox. Fixed in iOS 27 and iPadOS 27, and macOS Golden Gate 27.
- CVE-2026-43689: permissions issue; a malicious app may gain root privileges. Fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, and visionOS 27.
Patch in this order
- Apply the current Apple OS updates first: iOS 26.7 or iOS 27 for iPhone and iPad; macOS Sequoia 15.8, Tahoe 26.7 or Golden Gate 27 for Mac; tvOS 27, visionOS 27 and watchOS 27. This addresses the remote code execution, kernel memory corruption and protected system file modification flaws CVE-2026-65414, CVE-2026-84561, CVE-2026-84609 and CVE-2026-86881.
- Within that rollout, prioritise devices that leave the corporate network and Macs that connect to untrusted file shares, particularly NFS, because CVE-2026-43686 is triggered by connecting to a malicious NFS server.
- Patch remaining high-severity local or app-mediated issues in the same cycle: CVE-2026-84566, CVE-2026-65354, CVE-2026-43689 and CVE-2026-65415.
- Include Safari in the update cycle; the release contains Safari-related medium-severity items. Then schedule the remaining medium and low severity patches through normal change management.
Beyond the patch
Broad Apple releases such as this become easier to manage when you know which devices are exposed and which update path matters most. Virtual CISO Services can provide that outside-in view and help sequence the rollout so the highest-risk devices are patched first.
Every CVE in this release
| CVE | Product | Severity | |
|---|---|---|---|
| CVE-2026-65414 | iOS and iPadOS | Critical 9.8 | |
| CVE-2026-84561 | iOS and iPadOS | Critical 9.8 | |
| CVE-2026-84609 | iOS and iPadOS | Critical 9.8 | |
| CVE-2026-84625 | iOS and iPadOS | Critical 9.1 | |
| CVE-2026-86881 | iOS and iPadOS | Critical 9.1 | |
| CVE-2026-43686 | iOS and iPadOS | High 8.8 | |
| CVE-2026-84546 | iOS and iPadOS | High 8.4 | |
| CVE-2026-84566 | iOS and iPadOS | High 8.4 | |
| CVE-2026-65354 | iOS and iPadOS | High 8.2 | |
| CVE-2026-65415 | iOS and iPadOS | High 8.1 | |
| CVE-2026-43688 | iOS and iPadOS | High 7.8 | |
| CVE-2026-43689 | iOS and iPadOS | High 7.8 | |
| CVE-2026-65344 | iOS and iPadOS | High 7.8 | |
| CVE-2026-65398 | iOS and iPadOS | High 7.8 | |
| CVE-2026-84497 | iOS and iPadOS | High 7.8 | |
| CVE-2026-84507 | iOS and iPadOS | High 7.8 | |
| CVE-2026-84511 | iOS and iPadOS | High 7.8 | |
| CVE-2026-84575 | iOS and iPadOS | High 7.8 | |
| CVE-2026-84607 | iOS and iPadOS | High 7.8 | |
| CVE-2026-65410 | iOS and iPadOS | High 7.5 | |
| CVE-2026-84598 | iOS and iPadOS | High 7.5 | |
| CVE-2026-84629 | iOS and iPadOS | High 7.5 | |
| CVE-2026-86895 | iOS and iPadOS | High 7.5 | |
| CVE-2026-86904 | iOS and iPadOS | High 7.5 | |
| CVE-2026-64761 | iOS and iPadOS | High 7.5 | |
| CVE-2026-84606 | iOS and iPadOS | High 7.5 | |
| CVE-2026-84623 | iOS and iPadOS | High 7.5 | |
| CVE-2026-64752 | iOS and iPadOS | High 7.3 | |
| CVE-2026-84611 | iOS and iPadOS | High 7.3 | |
| CVE-2026-84620 | iOS and iPadOS | High 7.3 | |
| CVE-2026-84632 | iOS and iPadOS | High 7.3 | |
| CVE-2026-20683 | iOS and iPadOS | High 7.1 | |
| CVE-2026-65359 | iOS and iPadOS | High 7.1 | |
| CVE-2026-43687 | iOS and iPadOS | Medium 6.5 | |
| CVE-2026-65395 | iOS and iPadOS | Medium 6.5 | |
| CVE-2026-65412 | iOS and iPadOS | Medium 6.5 | |
| CVE-2026-84487 | iOS and iPadOS | Medium 6.5 | |
| CVE-2026-84510 | iOS and iPadOS | Medium 6.5 | |
| CVE-2026-84519 | iOS and iPadOS | Medium 6.5 | |
| CVE-2026-86870 | iOS and iPadOS | Medium 6.5 |
Show all 118
| CVE | Product | Severity | |
|---|---|---|---|
| CVE-2026-86882 | iOS and iPadOS | Medium 6.5 | |
| CVE-2026-64753 | Safari | Medium 6.5 | |
| CVE-2026-84596 | iOS and iPadOS | Medium 6.5 | |
| CVE-2026-84597 | iOS and iPadOS | Medium 6.5 | |
| CVE-2026-84635 | Safari | Medium 6.5 | |
| CVE-2026-86879 | iOS and iPadOS | Medium 6.5 | |
| CVE-2026-86885 | iOS and iPadOS | Medium 6.5 | |
| CVE-2026-84531 | iOS and iPadOS | Medium 6.2 | |
| CVE-2026-84622 | iOS and iPadOS | Medium 6.2 | |
| CVE-2026-84560 | iOS and iPadOS | Medium 6.1 | |
| CVE-2026-28968 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-43664 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-43695 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-43737 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-43785 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-64756 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-65345 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-65348 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-65377 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-65402 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-65403 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-65405 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-65406 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-65408 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-65409 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-65411 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-84491 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-84513 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-84521 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-84523 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-84527 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-84534 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-84552 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-84583 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-84593 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-84602 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-84603 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-84612 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-84615 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-84616 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-84617 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-84621 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-84624 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-84628 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-84636 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-86878 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-86883 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-86884 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-86886 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-86892 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-86897 | Safari | Medium 5.5 | |
| CVE-2026-86903 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-86905 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-86924 | iOS and iPadOS | Medium 5.5 | |
| CVE-2026-84532 | iOS and iPadOS | Medium 5.4 | |
| CVE-2026-84600 | iOS and iPadOS | Medium 5.4 | |
| CVE-2026-86898 | Safari | Medium 5.4 | |
| CVE-2026-84533 | iOS and iPadOS | Medium 5.3 | |
| CVE-2026-86876 | iOS and iPadOS | Medium 5.2 | |
| CVE-2026-65358 | iOS and iPadOS | Medium 4.7 | |
| CVE-2026-65360 | iOS and iPadOS | Medium 4.7 | |
| CVE-2026-84492 | iOS and iPadOS | Medium 4.7 | |
| CVE-2026-84630 | iOS and iPadOS | Medium 4.7 | |
| CVE-2026-43674 | iOS and iPadOS | Medium 4.6 | |
| CVE-2026-86890 | iOS and iPadOS | Medium 4.6 | |
| CVE-2026-65399 | iOS and iPadOS | Medium 4.4 | |
| CVE-2026-84551 | iOS and iPadOS | Medium 4.4 | |
| CVE-2026-28966 | iOS and iPadOS | Medium 4.3 | |
| CVE-2026-84524 | iOS and iPadOS | Medium 4.3 | |
| CVE-2026-84526 | iOS and iPadOS | Medium 4.3 | |
| CVE-2026-84518 | Safari | Medium 4.3 | |
| CVE-2026-84564 | iOS and iPadOS | Medium 4.3 | |
| CVE-2026-84571 | iOS and iPadOS | Medium 4.3 | |
| CVE-2026-84530 | iOS and iPadOS | Low 3.3 | |
| CVE-2026-84626 | iOS and iPadOS | Low 3.3 | |
| CVE-2026-86887 | iOS and iPadOS | Low 3.3 | |
| CVE-2026-86888 | iOS and iPadOS | Low 3.3 | |
| CVE-2026-86893 | iOS and iPadOS | Low 3.3 |
References
Vendor advisory
CVE
- CVE-2026-65414 — cve.org
- CVE-2026-65414 — NVD
- CVE-2026-84561 — cve.org
- CVE-2026-84561 — NVD
- CVE-2026-84609 — cve.org
- CVE-2026-84609 — NVD
- CVE-2026-84625 — cve.org
- CVE-2026-84625 — NVD
- CVE-2026-86881 — cve.org
- CVE-2026-86881 — NVD
- CVE-2026-43686 — cve.org
- CVE-2026-43686 — NVD
- CVE-2026-84546 — cve.org
- CVE-2026-84546 — NVD
- CVE-2026-84566 — cve.org
- CVE-2026-84566 — NVD
- CVE-2026-65354 — cve.org
- CVE-2026-65354 — NVD
- CVE-2026-65415 — cve.org
- CVE-2026-65415 — NVD
- CVE-2026-43688 — cve.org
- CVE-2026-43688 — NVD
- CVE-2026-43689 — cve.org
- CVE-2026-43689 — NVD