Release-Überblick
Apple-Sicherheitsupdates September 2026: Fünf kritische Lücken im OS-Kern ragen aus 118 Korrekturen heraus
Das Apple-Sicherheitsupdate vom September 2026 behebt 118 CVEs in iOS, iPadOS, macOS, tvOS, visionOS, watchOS und Safari. Im Umfang dieses Updates ist keine CVE als aktiv ausgenutzt markiert, und keine erscheint im Katalog Known Exploited Vulnerabilities (KEV) der CISA. Fünf kritische und 28 Schwachstellen hoher Schwere, vor allem Speicherbeschädigungen und Berechtigungsprobleme, machen ein rasches und breites Einspielen von Sicherheitsupdates erforderlich.
Das Release im Überblick
Das Apple-Sicherheitsupdate vom September 2026 deckt 118 CVEs in iOS, iPadOS, macOS, tvOS, visionOS, watchOS und Safari ab. Die Verteilung umfasst fünf kritische, 28 hohe, 80 mittlere und fünf niedrige Schwachstellen. Keine der betrachteten CVEs ist als aktiv ausgenutzt markiert, und keine erscheint im Katalog Known Exploited Vulnerabilities (KEV) der CISA. Die größten Auswirkungen haben Speicherbeschädigungen sowie Berechtigungs- und Zertifikatsvalidierungsprobleme in zentralen Komponenten des Betriebssystems. Updates sind verfügbar für iOS 26.7 und iPadOS 26.7, iOS 27 und iPadOS 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, tvOS 27, visionOS 27 und watchOS 27. Siehe Apples Versionshinweise für die vollständige Zuordnung.
Was am meisten zählt
Diese CVEs sollten Sie zuerst prüfen:
Zentrale Betriebssysteme (iOS, iPadOS, macOS, tvOS, visionOS, watchOS)
- CVE-2026-65414: Schreibzugriff außerhalb der vorgesehenen Speichergrenzen; ein entfernter Angreifer kann möglicherweise das unerwartete Beenden von Apps oder die Ausführung beliebigen Codes verursachen. Behoben in iOS 26.7 und iPadOS 26.7, iOS 27 und iPadOS 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, tvOS 27, visionOS 27 und watchOS 27.
- CVE-2026-84561: doppelte Speicherfreigabe; eine App kann möglicherweise die unerwartete Beendigung des Systems verursachen oder den Kernel-Speicher beschädigen. Behoben in denselben Versionen wie CVE-2026-65414.
- CVE-2026-84609: Berechtigungsproblem; eine App kann möglicherweise geschützte Systemdateien verändern. Behoben in iOS 27 und iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27 und watchOS 27.
- CVE-2026-86881: Problem bei der Zertifikatsvalidierung; ein Angreifer mit einer kompromittierten Zwischenzertifizierungsstelle kann Zertifikate mit beliebigen erweiterten Schlüsselverwendungen ausstellen. Behoben in iOS 26.7 und iPadOS 26.7, iOS 27 und iPadOS 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, tvOS 27, visionOS 27 und watchOS 27.
- CVE-2026-43686: Eine Use-after-Free-Schwachstelle beim Verbinden mit einem bösartigen NFS-Server kann zu einer Beschädigung des Kernel-Speichers führen. Behoben in iOS 26.7 und iPadOS 26.7, iOS 27 und iPadOS 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, tvOS 27, visionOS 27 und watchOS 27.
- CVE-2026-65354: Sandbox-Ausbruch; eine bösartige App kann aus ihrer Sandbox ausbrechen. Behoben in iOS 27 und iPadOS 27 sowie macOS Golden Gate 27.
- CVE-2026-43689: Berechtigungsproblem; eine bösartige App kann Root-Rechte erlangen. Behoben in iOS 26.7 und iPadOS 26.7, iOS 27 und iPadOS 27, macOS Golden Gate 27 und visionOS 27.
In dieser Reihenfolge patchen
- Spielen Sie zuerst die aktuellen Apple-Betriebssystemupdates ein: iOS 26.7 oder iOS 27 für iPhone und iPad; macOS Sequoia 15.8, Tahoe 26.7 oder Golden Gate 27 für Mac; tvOS 27, visionOS 27 und watchOS 27. Damit werden die Schwachstellen in Bezug auf Remotecodeausführung, Beschädigung des Kernel-Speichers und die Veränderung geschützter Systemdateien behoben – CVE-2026-65414, CVE-2026-84561, CVE-2026-84609 und CVE-2026-86881.
- Priorisieren Sie innerhalb dieser Update-Welle Geräte, die das Unternehmensnetz verlassen, sowie Macs, die Verbindungen zu nicht vertrauenswürdigen Dateifreigaben – insbesondere NFS – herstellen, da CVE-2026-43686 durch die Verbindung mit einem bösartigen NFS-Server ausgelöst wird.
- Spielen Sie im selben Zyklus Sicherheitsupdates für die verbleibenden Schwachstellen hoher Schwere ein, die lokal oder über Apps ausgenutzt werden können: CVE-2026-84566, CVE-2026-65354, CVE-2026-43689 und CVE-2026-65415.
- Beziehen Sie Safari in den Updatezyklus ein; das Release enthält mittelschwere Schwachstellen im Zusammenhang mit Safari. Planen Sie die übrigen Schwachstellen mittlerer und niedriger Schwere anschließend über das normale Änderungsmanagement ein.
Über den Patch hinaus
Umfassende Apple-Updates wie dieses lassen sich leichter bewältigen, wenn Sie wissen, welche Geräte exponiert sind und welcher Update-Pfad am wichtigsten ist. Mit dem Angebot Virtual CISO Services unterstützen wir Sie dabei, diese Sicht von außen zu gewinnen und die Reihenfolge der Update-Einführung so zu planen, dass Geräte mit dem höchsten Risiko zuerst Sicherheitsupdates erhalten.
Alle CVEs dieses Releases
| CVE | Produkt | Schweregrad | |
|---|---|---|---|
| CVE-2026-65414 | iOS and iPadOS | Kritisch 9.8 | |
| CVE-2026-84561 | iOS and iPadOS | Kritisch 9.8 | |
| CVE-2026-84609 | iOS and iPadOS | Kritisch 9.8 | |
| CVE-2026-84625 | iOS and iPadOS | Kritisch 9.1 | |
| CVE-2026-86881 | iOS and iPadOS | Kritisch 9.1 | |
| CVE-2026-43686 | iOS and iPadOS | Hoch 8.8 | |
| CVE-2026-84546 | iOS and iPadOS | Hoch 8.4 | |
| CVE-2026-84566 | iOS and iPadOS | Hoch 8.4 | |
| CVE-2026-65354 | iOS and iPadOS | Hoch 8.2 | |
| CVE-2026-65415 | iOS and iPadOS | Hoch 8.1 | |
| CVE-2026-43688 | iOS and iPadOS | Hoch 7.8 | |
| CVE-2026-43689 | iOS and iPadOS | Hoch 7.8 | |
| CVE-2026-65344 | iOS and iPadOS | Hoch 7.8 | |
| CVE-2026-65398 | iOS and iPadOS | Hoch 7.8 | |
| CVE-2026-84497 | iOS and iPadOS | Hoch 7.8 | |
| CVE-2026-84507 | iOS and iPadOS | Hoch 7.8 | |
| CVE-2026-84511 | iOS and iPadOS | Hoch 7.8 | |
| CVE-2026-84575 | iOS and iPadOS | Hoch 7.8 | |
| CVE-2026-84607 | iOS and iPadOS | Hoch 7.8 | |
| CVE-2026-65410 | iOS and iPadOS | Hoch 7.5 | |
| CVE-2026-84598 | iOS and iPadOS | Hoch 7.5 | |
| CVE-2026-84629 | iOS and iPadOS | Hoch 7.5 | |
| CVE-2026-86895 | iOS and iPadOS | Hoch 7.5 | |
| CVE-2026-86904 | iOS and iPadOS | Hoch 7.5 | |
| CVE-2026-64761 | iOS and iPadOS | Hoch 7.5 | |
| CVE-2026-84606 | iOS and iPadOS | Hoch 7.5 | |
| CVE-2026-84623 | iOS and iPadOS | Hoch 7.5 | |
| CVE-2026-64752 | iOS and iPadOS | Hoch 7.3 | |
| CVE-2026-84611 | iOS and iPadOS | Hoch 7.3 | |
| CVE-2026-84620 | iOS and iPadOS | Hoch 7.3 | |
| CVE-2026-84632 | iOS and iPadOS | Hoch 7.3 | |
| CVE-2026-20683 | iOS and iPadOS | Hoch 7.1 | |
| CVE-2026-65359 | iOS and iPadOS | Hoch 7.1 | |
| CVE-2026-43687 | iOS and iPadOS | Mittel 6.5 | |
| CVE-2026-65395 | iOS and iPadOS | Mittel 6.5 | |
| CVE-2026-65412 | iOS and iPadOS | Mittel 6.5 | |
| CVE-2026-84487 | iOS and iPadOS | Mittel 6.5 | |
| CVE-2026-84510 | iOS and iPadOS | Mittel 6.5 | |
| CVE-2026-84519 | iOS and iPadOS | Mittel 6.5 | |
| CVE-2026-86870 | iOS and iPadOS | Mittel 6.5 |
Alle 118 anzeigen
| CVE | Produkt | Schweregrad | |
|---|---|---|---|
| CVE-2026-86882 | iOS and iPadOS | Mittel 6.5 | |
| CVE-2026-64753 | Safari | Mittel 6.5 | |
| CVE-2026-84596 | iOS and iPadOS | Mittel 6.5 | |
| CVE-2026-84597 | iOS and iPadOS | Mittel 6.5 | |
| CVE-2026-84635 | Safari | Mittel 6.5 | |
| CVE-2026-86879 | iOS and iPadOS | Mittel 6.5 | |
| CVE-2026-86885 | iOS and iPadOS | Mittel 6.5 | |
| CVE-2026-84531 | iOS and iPadOS | Mittel 6.2 | |
| CVE-2026-84622 | iOS and iPadOS | Mittel 6.2 | |
| CVE-2026-84560 | iOS and iPadOS | Mittel 6.1 | |
| CVE-2026-28968 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-43664 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-43695 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-43737 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-43785 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-64756 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-65345 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-65348 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-65377 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-65402 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-65403 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-65405 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-65406 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-65408 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-65409 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-65411 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-84491 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-84513 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-84521 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-84523 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-84527 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-84534 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-84552 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-84583 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-84593 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-84602 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-84603 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-84612 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-84615 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-84616 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-84617 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-84621 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-84624 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-84628 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-84636 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-86878 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-86883 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-86884 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-86886 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-86892 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-86897 | Safari | Mittel 5.5 | |
| CVE-2026-86903 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-86905 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-86924 | iOS and iPadOS | Mittel 5.5 | |
| CVE-2026-84532 | iOS and iPadOS | Mittel 5.4 | |
| CVE-2026-84600 | iOS and iPadOS | Mittel 5.4 | |
| CVE-2026-86898 | Safari | Mittel 5.4 | |
| CVE-2026-84533 | iOS and iPadOS | Mittel 5.3 | |
| CVE-2026-86876 | iOS and iPadOS | Mittel 5.2 | |
| CVE-2026-65358 | iOS and iPadOS | Mittel 4.7 | |
| CVE-2026-65360 | iOS and iPadOS | Mittel 4.7 | |
| CVE-2026-84492 | iOS and iPadOS | Mittel 4.7 | |
| CVE-2026-84630 | iOS and iPadOS | Mittel 4.7 | |
| CVE-2026-43674 | iOS and iPadOS | Mittel 4.6 | |
| CVE-2026-86890 | iOS and iPadOS | Mittel 4.6 | |
| CVE-2026-65399 | iOS and iPadOS | Mittel 4.4 | |
| CVE-2026-84551 | iOS and iPadOS | Mittel 4.4 | |
| CVE-2026-28966 | iOS and iPadOS | Mittel 4.3 | |
| CVE-2026-84524 | iOS and iPadOS | Mittel 4.3 | |
| CVE-2026-84526 | iOS and iPadOS | Mittel 4.3 | |
| CVE-2026-84518 | Safari | Mittel 4.3 | |
| CVE-2026-84564 | iOS and iPadOS | Mittel 4.3 | |
| CVE-2026-84571 | iOS and iPadOS | Mittel 4.3 | |
| CVE-2026-84530 | iOS and iPadOS | Niedrig 3.3 | |
| CVE-2026-84626 | iOS and iPadOS | Niedrig 3.3 | |
| CVE-2026-86887 | iOS and iPadOS | Niedrig 3.3 | |
| CVE-2026-86888 | iOS and iPadOS | Niedrig 3.3 | |
| CVE-2026-86893 | iOS and iPadOS | Niedrig 3.3 |
Quellen
Herstellerhinweis
CVE
- CVE-2026-65414 — cve.org
- CVE-2026-65414 — NVD
- CVE-2026-84561 — cve.org
- CVE-2026-84561 — NVD
- CVE-2026-84609 — cve.org
- CVE-2026-84609 — NVD
- CVE-2026-84625 — cve.org
- CVE-2026-84625 — NVD
- CVE-2026-86881 — cve.org
- CVE-2026-86881 — NVD
- CVE-2026-43686 — cve.org
- CVE-2026-43686 — NVD
- CVE-2026-84546 — cve.org
- CVE-2026-84546 — NVD
- CVE-2026-84566 — cve.org
- CVE-2026-84566 — NVD
- CVE-2026-65354 — cve.org
- CVE-2026-65354 — NVD
- CVE-2026-65415 — cve.org
- CVE-2026-65415 — NVD
- CVE-2026-43688 — cve.org
- CVE-2026-43688 — NVD
- CVE-2026-43689 — cve.org
- CVE-2026-43689 — NVD