Zum Inhalt springen

Release-Überblick

Apple-Sicherheitsupdates September 2026: Fünf kritische Lücken im OS-Kern ragen aus 118 Korrekturen heraus

Kritisch 9.8 Hersteller: Apple 118 relevante CVEs Veröffentlicht

Das Apple-Sicherheitsupdate vom September 2026 behebt 118 CVEs in iOS, iPadOS, macOS, tvOS, visionOS, watchOS und Safari. Im Umfang dieses Updates ist keine CVE als aktiv ausgenutzt markiert, und keine erscheint im Katalog Known Exploited Vulnerabilities (KEV) der CISA. Fünf kritische und 28 Schwachstellen hoher Schwere, vor allem Speicherbeschädigungen und Berechtigungsprobleme, machen ein rasches und breites Einspielen von Sicherheitsupdates erforderlich.

Das Release im Überblick

Das Apple-Sicherheitsupdate vom September 2026 deckt 118 CVEs in iOS, iPadOS, macOS, tvOS, visionOS, watchOS und Safari ab. Die Verteilung umfasst fünf kritische, 28 hohe, 80 mittlere und fünf niedrige Schwachstellen. Keine der betrachteten CVEs ist als aktiv ausgenutzt markiert, und keine erscheint im Katalog Known Exploited Vulnerabilities (KEV) der CISA. Die größten Auswirkungen haben Speicherbeschädigungen sowie Berechtigungs- und Zertifikatsvalidierungsprobleme in zentralen Komponenten des Betriebssystems. Updates sind verfügbar für iOS 26.7 und iPadOS 26.7, iOS 27 und iPadOS 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, tvOS 27, visionOS 27 und watchOS 27. Siehe Apples Versionshinweise für die vollständige Zuordnung.

Was am meisten zählt

Diese CVEs sollten Sie zuerst prüfen:

Zentrale Betriebssysteme (iOS, iPadOS, macOS, tvOS, visionOS, watchOS)

  • CVE-2026-65414: Schreibzugriff außerhalb der vorgesehenen Speichergrenzen; ein entfernter Angreifer kann möglicherweise das unerwartete Beenden von Apps oder die Ausführung beliebigen Codes verursachen. Behoben in iOS 26.7 und iPadOS 26.7, iOS 27 und iPadOS 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, tvOS 27, visionOS 27 und watchOS 27.
  • CVE-2026-84561: doppelte Speicherfreigabe; eine App kann möglicherweise die unerwartete Beendigung des Systems verursachen oder den Kernel-Speicher beschädigen. Behoben in denselben Versionen wie CVE-2026-65414.
  • CVE-2026-84609: Berechtigungsproblem; eine App kann möglicherweise geschützte Systemdateien verändern. Behoben in iOS 27 und iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27 und watchOS 27.
  • CVE-2026-86881: Problem bei der Zertifikatsvalidierung; ein Angreifer mit einer kompromittierten Zwischenzertifizierungsstelle kann Zertifikate mit beliebigen erweiterten Schlüsselverwendungen ausstellen. Behoben in iOS 26.7 und iPadOS 26.7, iOS 27 und iPadOS 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, tvOS 27, visionOS 27 und watchOS 27.
  • CVE-2026-43686: Eine Use-after-Free-Schwachstelle beim Verbinden mit einem bösartigen NFS-Server kann zu einer Beschädigung des Kernel-Speichers führen. Behoben in iOS 26.7 und iPadOS 26.7, iOS 27 und iPadOS 27, macOS Sequoia 15.8, macOS Tahoe 26.7, macOS Golden Gate 27, tvOS 27, visionOS 27 und watchOS 27.
  • CVE-2026-65354: Sandbox-Ausbruch; eine bösartige App kann aus ihrer Sandbox ausbrechen. Behoben in iOS 27 und iPadOS 27 sowie macOS Golden Gate 27.
  • CVE-2026-43689: Berechtigungsproblem; eine bösartige App kann Root-Rechte erlangen. Behoben in iOS 26.7 und iPadOS 26.7, iOS 27 und iPadOS 27, macOS Golden Gate 27 und visionOS 27.

In dieser Reihenfolge patchen

  1. Spielen Sie zuerst die aktuellen Apple-Betriebssystemupdates ein: iOS 26.7 oder iOS 27 für iPhone und iPad; macOS Sequoia 15.8, Tahoe 26.7 oder Golden Gate 27 für Mac; tvOS 27, visionOS 27 und watchOS 27. Damit werden die Schwachstellen in Bezug auf Remotecodeausführung, Beschädigung des Kernel-Speichers und die Veränderung geschützter Systemdateien behoben – CVE-2026-65414, CVE-2026-84561, CVE-2026-84609 und CVE-2026-86881.
  2. Priorisieren Sie innerhalb dieser Update-Welle Geräte, die das Unternehmensnetz verlassen, sowie Macs, die Verbindungen zu nicht vertrauenswürdigen Dateifreigaben – insbesondere NFS – herstellen, da CVE-2026-43686 durch die Verbindung mit einem bösartigen NFS-Server ausgelöst wird.
  3. Spielen Sie im selben Zyklus Sicherheitsupdates für die verbleibenden Schwachstellen hoher Schwere ein, die lokal oder über Apps ausgenutzt werden können: CVE-2026-84566, CVE-2026-65354, CVE-2026-43689 und CVE-2026-65415.
  4. Beziehen Sie Safari in den Updatezyklus ein; das Release enthält mittelschwere Schwachstellen im Zusammenhang mit Safari. Planen Sie die übrigen Schwachstellen mittlerer und niedriger Schwere anschließend über das normale Änderungsmanagement ein.

Über den Patch hinaus

Umfassende Apple-Updates wie dieses lassen sich leichter bewältigen, wenn Sie wissen, welche Geräte exponiert sind und welcher Update-Pfad am wichtigsten ist. Mit dem Angebot Virtual CISO Services unterstützen wir Sie dabei, diese Sicht von außen zu gewinnen und die Reihenfolge der Update-Einführung so zu planen, dass Geräte mit dem höchsten Risiko zuerst Sicherheitsupdates erhalten.

Alle CVEs dieses Releases

CVEProduktSchweregrad
CVE-2026-65414iOS and iPadOSKritisch 9.8
CVE-2026-84561iOS and iPadOSKritisch 9.8
CVE-2026-84609iOS and iPadOSKritisch 9.8
CVE-2026-84625iOS and iPadOSKritisch 9.1
CVE-2026-86881iOS and iPadOSKritisch 9.1
CVE-2026-43686iOS and iPadOSHoch 8.8
CVE-2026-84546iOS and iPadOSHoch 8.4
CVE-2026-84566iOS and iPadOSHoch 8.4
CVE-2026-65354iOS and iPadOSHoch 8.2
CVE-2026-65415iOS and iPadOSHoch 8.1
CVE-2026-43688iOS and iPadOSHoch 7.8
CVE-2026-43689iOS and iPadOSHoch 7.8
CVE-2026-65344iOS and iPadOSHoch 7.8
CVE-2026-65398iOS and iPadOSHoch 7.8
CVE-2026-84497iOS and iPadOSHoch 7.8
CVE-2026-84507iOS and iPadOSHoch 7.8
CVE-2026-84511iOS and iPadOSHoch 7.8
CVE-2026-84575iOS and iPadOSHoch 7.8
CVE-2026-84607iOS and iPadOSHoch 7.8
CVE-2026-65410iOS and iPadOSHoch 7.5
CVE-2026-84598iOS and iPadOSHoch 7.5
CVE-2026-84629iOS and iPadOSHoch 7.5
CVE-2026-86895iOS and iPadOSHoch 7.5
CVE-2026-86904iOS and iPadOSHoch 7.5
CVE-2026-64761iOS and iPadOSHoch 7.5
CVE-2026-84606iOS and iPadOSHoch 7.5
CVE-2026-84623iOS and iPadOSHoch 7.5
CVE-2026-64752iOS and iPadOSHoch 7.3
CVE-2026-84611iOS and iPadOSHoch 7.3
CVE-2026-84620iOS and iPadOSHoch 7.3
CVE-2026-84632iOS and iPadOSHoch 7.3
CVE-2026-20683iOS and iPadOSHoch 7.1
CVE-2026-65359iOS and iPadOSHoch 7.1
CVE-2026-43687iOS and iPadOSMittel 6.5
CVE-2026-65395iOS and iPadOSMittel 6.5
CVE-2026-65412iOS and iPadOSMittel 6.5
CVE-2026-84487iOS and iPadOSMittel 6.5
CVE-2026-84510iOS and iPadOSMittel 6.5
CVE-2026-84519iOS and iPadOSMittel 6.5
CVE-2026-86870iOS and iPadOSMittel 6.5
Alle 118 anzeigen
CVEProduktSchweregrad
CVE-2026-86882iOS and iPadOSMittel 6.5
CVE-2026-64753SafariMittel 6.5
CVE-2026-84596iOS and iPadOSMittel 6.5
CVE-2026-84597iOS and iPadOSMittel 6.5
CVE-2026-84635SafariMittel 6.5
CVE-2026-86879iOS and iPadOSMittel 6.5
CVE-2026-86885iOS and iPadOSMittel 6.5
CVE-2026-84531iOS and iPadOSMittel 6.2
CVE-2026-84622iOS and iPadOSMittel 6.2
CVE-2026-84560iOS and iPadOSMittel 6.1
CVE-2026-28968iOS and iPadOSMittel 5.5
CVE-2026-43664iOS and iPadOSMittel 5.5
CVE-2026-43695iOS and iPadOSMittel 5.5
CVE-2026-43737iOS and iPadOSMittel 5.5
CVE-2026-43785iOS and iPadOSMittel 5.5
CVE-2026-64756iOS and iPadOSMittel 5.5
CVE-2026-65345iOS and iPadOSMittel 5.5
CVE-2026-65348iOS and iPadOSMittel 5.5
CVE-2026-65377iOS and iPadOSMittel 5.5
CVE-2026-65402iOS and iPadOSMittel 5.5
CVE-2026-65403iOS and iPadOSMittel 5.5
CVE-2026-65405iOS and iPadOSMittel 5.5
CVE-2026-65406iOS and iPadOSMittel 5.5
CVE-2026-65408iOS and iPadOSMittel 5.5
CVE-2026-65409iOS and iPadOSMittel 5.5
CVE-2026-65411iOS and iPadOSMittel 5.5
CVE-2026-84491iOS and iPadOSMittel 5.5
CVE-2026-84513iOS and iPadOSMittel 5.5
CVE-2026-84521iOS and iPadOSMittel 5.5
CVE-2026-84523iOS and iPadOSMittel 5.5
CVE-2026-84527iOS and iPadOSMittel 5.5
CVE-2026-84534iOS and iPadOSMittel 5.5
CVE-2026-84552iOS and iPadOSMittel 5.5
CVE-2026-84583iOS and iPadOSMittel 5.5
CVE-2026-84593iOS and iPadOSMittel 5.5
CVE-2026-84602iOS and iPadOSMittel 5.5
CVE-2026-84603iOS and iPadOSMittel 5.5
CVE-2026-84612iOS and iPadOSMittel 5.5
CVE-2026-84615iOS and iPadOSMittel 5.5
CVE-2026-84616iOS and iPadOSMittel 5.5
CVE-2026-84617iOS and iPadOSMittel 5.5
CVE-2026-84621iOS and iPadOSMittel 5.5
CVE-2026-84624iOS and iPadOSMittel 5.5
CVE-2026-84628iOS and iPadOSMittel 5.5
CVE-2026-84636iOS and iPadOSMittel 5.5
CVE-2026-86878iOS and iPadOSMittel 5.5
CVE-2026-86883iOS and iPadOSMittel 5.5
CVE-2026-86884iOS and iPadOSMittel 5.5
CVE-2026-86886iOS and iPadOSMittel 5.5
CVE-2026-86892iOS and iPadOSMittel 5.5
CVE-2026-86897SafariMittel 5.5
CVE-2026-86903iOS and iPadOSMittel 5.5
CVE-2026-86905iOS and iPadOSMittel 5.5
CVE-2026-86924iOS and iPadOSMittel 5.5
CVE-2026-84532iOS and iPadOSMittel 5.4
CVE-2026-84600iOS and iPadOSMittel 5.4
CVE-2026-86898SafariMittel 5.4
CVE-2026-84533iOS and iPadOSMittel 5.3
CVE-2026-86876iOS and iPadOSMittel 5.2
CVE-2026-65358iOS and iPadOSMittel 4.7
CVE-2026-65360iOS and iPadOSMittel 4.7
CVE-2026-84492iOS and iPadOSMittel 4.7
CVE-2026-84630iOS and iPadOSMittel 4.7
CVE-2026-43674iOS and iPadOSMittel 4.6
CVE-2026-86890iOS and iPadOSMittel 4.6
CVE-2026-65399iOS and iPadOSMittel 4.4
CVE-2026-84551iOS and iPadOSMittel 4.4
CVE-2026-28966iOS and iPadOSMittel 4.3
CVE-2026-84524iOS and iPadOSMittel 4.3
CVE-2026-84526iOS and iPadOSMittel 4.3
CVE-2026-84518SafariMittel 4.3
CVE-2026-84564iOS and iPadOSMittel 4.3
CVE-2026-84571iOS and iPadOSMittel 4.3
CVE-2026-84530iOS and iPadOSNiedrig 3.3
CVE-2026-84626iOS and iPadOSNiedrig 3.3
CVE-2026-86887iOS and iPadOSNiedrig 3.3
CVE-2026-86888iOS and iPadOSNiedrig 3.3
CVE-2026-86893iOS and iPadOSNiedrig 3.3

Quellen

Quellen: der CVE-Eintrag (MITRE), NVD, CISA KEV und SSVC, FIRST EPSS und der Hinweis des Herstellers. Werte und Daten wie von diesen Quellen veröffentlicht.

Mit KI-Unterstützung aus den obigen Quellen verfasst und vor der Veröffentlichung automatisch gegen sie geprüft.