[NEW] [medium] Apple iOS and iPadOS: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Apple iOS and Apple iPadOS to execute arbitrary code, escalate privileges, carry out a Denial of Service attack, disclose information, manipulate files, and bypass security measures.
CSIRTS triage
- What
- Multiple vulnerabilities in Apple iOS and iPadOS can be exploited to execute arbitrary code, escalate privileges, carry out a Denial of Service attack, disclose information, manipulate files, and bypass security measures.
- Who is affected
- Users of Apple iOS and iPadOS are affected by these vulnerabilities.
- Urgency
- Remediation is medium urgency as the vulnerabilities are exploitable but not confirmed to be actively exploited.
- Action
- Update to the latest version of iOS and iPadOS to address these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch iOS and iPadOS
Get an email when a new iOS and iPadOS advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2537
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-289280.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all scored CVEs.
- Low exploitation riskCVE-2026-289310.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all scored CVEs.
- Low exploitation riskCVE-2026-289730.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all scored CVEs.
- Low exploitation riskCVE-2026-37830.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all scored CVEs.
- Low exploitation riskCVE-2026-37840.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all scored CVEs.
- Low exploitation riskCVE-2026-436730.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all scored CVEs.
- Low exploitation riskCVE-2026-437110.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all scored CVEs.
- Low exploitation riskCVE-2026-437140.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all scored CVEs.
- Low exploitation riskCVE-2026-437230.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all scored CVEs.
- Low exploitation riskCVE-2026-437290.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] WebKitGTK: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] IBM QRadar SIEM: Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] Apple Safari: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Apple macOS (Tahoe, Sonoma, and Sequoia): Multiple vulnerabilitiescert-bund
- unknownNCSC-2026-0267 [1.00] [M/H] Vulnerabilities fixed in Apple MacOSncsc-nl
- unknownNCSC-2026-0266 [1.00] [M/H] Vulnerabilities fixed in Apple iOS and iPadOSncsc-nl
- high[NEW] [high] Oracle Communications: Multiple vulnerabilitiescert-bund
- unknownApple Products Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Apple products (July 28, 2026)cert-fr-avis
- criticalCVE-2026-64733: This issue was addressed with improved data protection. This issue is fixed in iOS 26.6 and iP…nvd
- mediumCVE-2026-64732: This issue was addressed through improved state management. This issue is fixed in iOS 26.6 an…nvd
- mediumCVE-2026-64730: The issue was addressed with improved UI. This issue is fixed in Safari 26.6, iOS 26.6 and iPa…nvd
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow unspecified attack2026-07-31