[NEW] [high] Apple macOS, iOS and iPadOS: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Apple macOS, Apple iOS and Apple iPadOS to execute arbitrary code, bypass security measures, disclose confidential information, manipulate data, cause memory corruption, or create a denial-of-service condition.
CSIRTS triage
- What
- Multiple vulnerabilities across macOS, iOS, and iPadOS enable code execution, security bypass, information disclosure, data manipulation, memory corruption, and denial of service.
- Who is affected
- Apple macOS, iOS, and iPadOS devices running unpatched versions.
- Urgency
- High severity; affects multiple platforms with code execution and memory corruption potential; patch immediately.
- Action
- Update Apple macOS, iOS, and iPadOS to latest security releases addressing CVE-2026-28947, CVE-2026-28958, CVE-2026-28973, CVE-2026-28979, CVE-2026-28984, CVE-2026-28990, CVE-2026-28996, and CVE-2026-3783.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2872
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-289470.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289580.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289730.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289790.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289840.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289900.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289960.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-37830.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-37840.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-398680.96% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 59% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [medium] cURL: Multiple vulnerabilitiescert-bund
- unknownApple Products Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Apple products (August 18, 2026)cert-fr-avis
- mediumCVE-2026-43795: The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, i…nvd
- highCVE-2026-43794: A memory corruption issue was addressed with improved memory handling. This issue is fixed in …nvd
- mediumCVE-2026-43667: A reachable assertion was addressed with improved input validation. This issue is fixed in iOS…nvd
- mediumCVE-2026-28984: The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and …nvd
- medium[NEW] [medium] WebKitGTK: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Tenable Security Center (August 14, 2026)cert-fr-avis
- high[NEW] [high] Apple macOS (Tahoe, Sonoma, and Sequoia): Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] Apple iOS and iPadOS: Multiple vulnerabilitiescert-bund
- unknownNCSC-2026-0267 [1.00] [M/H] Vulnerabilities fixed in Apple MacOSncsc-nl
Recent advisories for Apple macOS
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalexploitedCVE-2026-65400: Apple macOS Improper Authentication Vulnerabilitycisa-kev · 2026-08-18
- high[NEW] [medium] Apple macOS (Sonoma, Sequoia and Tahoe): Vulnerability enables security feature bypasscert-bund · 2026-08-13
- unknownexploitedNCSC-2026-0280 [1.01] [M/H] Vulnerability patched in macOS Screen Sharing by Applencsc-nl · 2026-08-12
- unknownNCSC-2026-0280 [1.00] [M/H] Vulnerability fixed in macOS Screen Sharing by Applencsc-nl · 2026-08-07
- high[NEW] [high] Apple macOS (Tahoe, Sonoma, and Sequoia): Multiple vulnerabilitiescert-bund · 2026-08-07
- unknownexploitedApple macOS Security Restriction Bypass Vulnerabilityhkcert · 2026-08-07
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] Joomla: Multiple vulnerabilities2026-08-19
- medium[NEW] [medium] Axis Axis OS: Multiple vulnerabilities2026-08-19
- medium[NEW] [medium] CPython: Multiple vulnerabilities2026-08-19
- high[NEW] [high] Atlassian Products (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, and Jira): Multiple vulnera…2026-08-19
- high[NEW] [high] Microsoft Developer Tools: Multiple Vulnerabilities2026-08-19