Multiple vulnerabilities in Apple products (July 28, 2026)
Multiple vulnerabilities have been discovered in Apple products. Some of them allow an attacker to cause arbitrary code execution, privilege escalation, and a breach of data confidentiality.
CSIRTS triage
- What
- Multiple vulnerabilities in Apple products can lead to arbitrary code execution, privilege escalation, and information disclosure.
- Who is affected
- Users of affected Apple products are at risk from these vulnerabilities.
- Urgency
- This is an urgent situation as exploitation could lead to severe security issues.
- Action
- Users should update their Apple products to the latest versions to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0938/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-437300.51% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 42% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-647340.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289820.49% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-437660.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-438040.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-437380.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-436940.60% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 47% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-438110.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-437990.65% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-437550.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0371 [1.00] [M/H] Kwetsbaarheden verholpen in Apple macOS en Samba door Apple en Sambancsc-nl
- unknownNCSC-2026-0370 [1.00] [M/H] Kwetsbaarheden verholpen in Apple iOS en iPadOSncsc-nl
- high[NEU] [hoch] Apple iOS, iPadOS, macOS Tahoe, macOS Golden Gate, macOS Sequoia und Safari: Mehrere Schwachstell…cert-bund
- high[UPDATE] [hoch] Apple Safari, macOS, iOS und iPadOS: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Apple macOS (Tahoe, Sonoma und Sequoia): Mehrere Schwachstellencert-bund
- medium[UPDATE] [mittel] Apple iOS und iPadOS: Mehrere Schwachstellencert-bund
- unknownApple Products Multiple Vulnerabilitieshkcert
- unknownexploitedMultiples vulnérabilités dans les produits Apple (15 septembre 2026)cert-fr-avis
- medium[UPDATE] [mittel] cURL: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] WebKitGTK: Mehrere Schwachstellencert-bund
- unknownMultiples vulnérabilités dans les produits VMware (07 septembre 2026)cert-fr-avis
- medium[NEW] [medium] WebKitGTK: Multiple vulnerabilitiescert-bund
Recent advisories for Apple products
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownApple Products Multiple Vulnerabilitieshkcert · 2026-09-15
- unknownApple Products Multiple Vulnerabilitieshkcert · 2026-08-18
- unknownMultiple vulnerabilities in Apple products (August 18, 2026)cert-fr-avis · 2026-08-18
- unknownApple Products Multiple Vulnerabilitieshkcert · 2026-07-28
- unknownApple Products Multiple Vulnerabilitieshkcert · 2026-07-06
- unknownMultiple vulnerabilities in Apple products (June 30, 2026)cert-fr-avis · 2026-06-30
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans Microsoft Edge (15 septembre 2026)2026-09-15
- unknownVulnérabilité dans Microsoft Windows (15 septembre 2026)2026-09-15
- unknownMultiples vulnérabilités dans les produits Cisco (15 septembre 2026)2026-09-15
- unknownMultiples vulnérabilités dans les produits Apple (15 septembre 2026)2026-09-15
- unknownMultiples vulnérabilités dans MISP (14 septembre 2026)2026-09-14