Zero Day Initiative | Blog
Follow
The Apple Security Update Review for September 2026
Apple has released security patches for 273 CVEs across multiple operating systems in its September 2026 update. The update addresses vulnerabilities in macOS, iOS/iPadOS, visionOS, watchOS, tvOS, Safari, and Xcode. Many CVEs lack severity scores, but key ones have been identified.One critical vulnerability, CVE-2026-65400 in Screen Sharing Server, is actively exploited, allowing unauthenticated network access. Another critical bug, CVE-2026-65414 in Bluetooth, permits remote arbitrary code execution across all eight OS platforms.CVE-2026-65346 in ImageIO is a high-severity bug, enabling arbitrary code execution through malicious image processing. Other notable high-severity issues include CVE-2026-84607 in AVEVideoEncoder and CVE-2026-43790 in Kernel, both awaiting NVD scores.Additional high-severity vulnerabilities affecting CUPS (CVE-2026-43692) and autofs (CVE-2026-84568) are also highlighted. The release includes 134 scored CVEs: 2 critical, 46 high, 84 medium, and 2 low. 139 CVEs are still awaiting severity scores from NVD.The patches cover various components like WebKit, Kernel, SMB, and Screen Sharing. Users are advised to update their devices to mitigate these security risks.
https://www.thezdi.com/blog/2026/9/16/the-apple-security-update-review-for-september-2026 thezdi.com