NCSC-2026-0266 [1.00] [M/H] Vulnerabilities fixed in Apple iOS and iPadOS
Apple has fixed multiple vulnerabilities in various versions of iOS and iPadOS. Several memory management errors such as use-after-free, buffer overflows, out-of-bounds reads and writes, integer overflows, race conditions, and insufficient input validation have been resolved. These errors can lead to unexpected system or application terminations, memory corruption, privilege escalation, sandbox escape, unauthorized access to sensitive user data, and in some cases arbitrary code execution. Issues with state management, permissions, sandboxing, and UI spoofing in Safari and other Apple components have also been addressed. The vulnerabilities are present in core components of the operating systems and affect a wide range of Apple platforms. Exploitation can occur via specially crafted files, network traffic, web content, or applications. No specific proof-of-concept details are mentioned in the input.
CSIRTS triage
- What
- Multiple vulnerabilities in iOS and iPadOS can lead to memory corruption, privilege escalation, and arbitrary code execution.
- Who is affected
- Users of various versions of iOS and iPadOS are affected.
- Urgency
- Remediation is high urgency due to the potential for exploitation and severe impacts.
- Action
- Update to the latest version of iOS and iPadOS to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch iOS and iPadOS
Get an email when a new iOS and iPadOS advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0266
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-37830.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-37840.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-44241.2% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 67% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289280.58% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289310.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289730.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-436730.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-437110.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-437140.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-437230.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0371 [1.00] [M/H] Kwetsbaarheden verholpen in Apple macOS en Samba door Apple en Sambancsc-nl
- unknownNCSC-2026-0370 [1.00] [M/H] Kwetsbaarheden verholpen in Apple iOS en iPadOSncsc-nl
- high[NEU] [hoch] Apple iOS, iPadOS, macOS Tahoe, macOS Golden Gate, macOS Sequoia und Safari: Mehrere Schwachstell…cert-bund
- high[UPDATE] [hoch] Apple Safari, macOS, iOS und iPadOS: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Apple macOS (Tahoe, Sonoma und Sequoia): Mehrere Schwachstellencert-bund
- medium[UPDATE] [mittel] Apple iOS und iPadOS: Mehrere Schwachstellencert-bund
- unknownApple Products Multiple Vulnerabilitieshkcert
- medium[UPDATE] [mittel] cURL: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] WebKitGTK: Mehrere Schwachstellencert-bund
- unknownMultiples vulnérabilités dans les produits VMware (07 septembre 2026)cert-fr-avis
- medium[NEW] [medium] WebKitGTK: Multiple vulnerabilitiescert-bund
- unknownUSN-8703-1: WebKitGTK vulnerabilitiesubuntu
Recent advisories for Apple iOS and
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownNCSC-2026-0370 [1.00] [M/H] Kwetsbaarheden verholpen in Apple iOS en iPadOSncsc-nl · 2026-09-15
- high[NEU] [hoch] Apple iOS, iPadOS, macOS Tahoe, macOS Golden Gate, macOS Sequoia und Safari: Mehrere Schwachstell…cert-bund · 2026-09-15
- high[UPDATE] [hoch] Apple Safari, macOS, iOS und iPadOS: Mehrere Schwachstellencert-bund · 2026-09-15
- medium[UPDATE] [mittel] Apple iOS und iPadOS: Mehrere Schwachstellencert-bund · 2026-09-15
- high[UPDATE] [hoch] Apple iOS und iPadOS: Mehrere Schwachstellencert-bund · 2026-09-09
- high[UPDATE] [hoch] Apple iOS: Mehrere Schwachstellencert-bund · 2026-09-09
More from NCSC-NL Advisories
- unknownNCSC-2026-0371 [1.00] [M/H] Kwetsbaarheden verholpen in Apple macOS en Samba door Apple en Samba2026-09-15
- unknownNCSC-2026-0370 [1.00] [M/H] Kwetsbaarheden verholpen in Apple iOS en iPadOS2026-09-15
- unknownNCSC-2026-0369 [1.00] [M/H] Kwetsbaarheid verholpen in Palo Alto Networks PAN-OS2026-09-15
- unknownNCSC-2026-0368 [1.00] [H/H] Kwetsbaarheid verholpen in Cisco Secure Email Gateway2026-09-14
- unknownNCSC-2026-0347 [1.01] [M/H] Kwetsbaarheden verholpen in Microsoft Azure2026-09-14