CVE-2026-43804
Ein Angreifer kann mehrere Schwachstellen in Apple iOS und Apple iPadOS ausnutzen, um beliebigen Programmcode auszuführen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, und um Sicherheitsvorkehrungen zu umgehen.
CSIRTS triage
- What
- Multiple vulnerabilities in Apple iOS and iPadOS can be exploited to execute arbitrary code, escalate privileges, carry out a Denial of Service attack, disclose information, manipulate files, and bypass security measures.
- Who is affected
- Users of Apple iOS and iPadOS are affected by these vulnerabilities.
- Urgency
- Remediation is medium urgency as the vulnerabilities are exploitable but not confirmed to be actively exploited.
- Action
- Update to the latest version of iOS and iPadOS to address these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-43804
Get an email if CVE-2026-43804 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
Advisory coverage (8)
- medium[UPDATE] [mittel] Apple iOS und iPadOS: Mehrere Schwachstellencert-bund · 2026-09-15
- high[UPDATE] [hoch] WebKitGTK: Mehrere Schwachstellencert-bund · 2026-09-14
- unknownUSN-8703-1: WebKitGTK vulnerabilitiesubuntu · 2026-08-31
- unknownDSA-6463-1 webkit2gtk - security updatedebian · 2026-08-24
- medium[NEW] [medium] Apple Safari: Multiple vulnerabilitiescert-bund · 2026-07-28
- unknownNCSC-2026-0266 [1.00] [M/H] Vulnerabilities fixed in Apple iOS and iPadOSncsc-nl · 2026-07-28
- unknownMultiple vulnerabilities in Apple products (July 28, 2026)cert-fr-avis · 2026-07-28
- mediumCVE-2026-43804: This issue was addressed through improved state management. This issue is fixed in Safari 26.6…nvd · 2026-07-27
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-43804)