Apple Patches a Record 260+ CVEs in One Update Cycle
Apple has mounted the largest vulnerability purge in its entire history: a single September cycle brought more than 260 unique CVEs and sent nearly the whole of the company’s ecosystem scrambling to update.
On September 14, Apple released iOS 27 and iPadOS 27, iOS 26.7 and iPadOS 26.7, macOS Golden Gate 27, macOS Tahoe 26.7, macOS Sequoia 15.8, along with new versions of tvOS, watchOS, visionOS, Safari, and Xcode. The full list of updates spans smartphones, tablets, computers, watches, headsets, media boxes, the browser, and developer tools.
The Most Imposing Numbers
The most striking figures fell to the new operating systems. iOS 27 and iPadOS 27 tallied 122 closed vulnerabilities, while macOS Golden Gate 27 counted a full 204. This spring, Apple had already weathered a major wave of fixes, yet the September release proved considerably larger in scale.
One cannot simply add 122 and 204. Many problems affect shared components and recur across several systems at once. The 260+ record therefore refers to unique CVEs across the entire cycle. For the same reason, the figure does not contradict the July reports of hundreds of fixes, which counted records separately for different platforms.
Serious Flaws on iPhone and iPad
Among the iPhone and iPad problems are errors far from cosmetic. CVE-2026-43689 allowed a malicious application to gain root privileges, while CVE-2026-84607 gave an isolated application the ability to execute arbitrary code with kernel privileges. Another vulnerability, CVE-2026-65414, could lead to code execution via Bluetooth. The scale looks especially sensitive against the backdrop of recent trouble, when WebKit vulnerabilities allowed Apple’s protective mechanisms to be bypassed.
An Even Longer List on Mac
On Mac the list is longer still. The flaw CVE-2026-43692 in the CUPS printing system allowed a remote user to cause a crash or execute arbitrary code, while CVE-2026-43690 in SMB opened kernel memory to a local user. In August, attackers had already exploited another critical macOS vulnerability to gain root and install a miner, so potentially dangerous high-privilege errors cannot be regarded as a purely theoretical threat.
AI Joins the Hunt for Bugs
The September release reveals another trend. In ten closed vulnerabilities, Apple named artificial-intelligence tools among the participants in the bug hunt. The documentation mentions Claude and Anthropic Research, and several macOS problems were discovered with the participation of the Nvidia AI Red Team. For now, AI more conspicuously helps find weak points than automatically remedy the problems it uncovers.
No Active Exploitation, but Analyze Quickly
Apple has not yet marked any of the new vulnerabilities as actively exploited. A count conducted by The Register identified more than 260 unique CVEs and named the September release the largest patch cycle in the company’s history. The publication of detailed descriptions, however, gives specialists and attackers alike ample information to analyze the closed errors.
Owners of compatible devices would do well to install the current system versions without long delay. An update is especially urgent for devices that work with untrusted files, network resources, Bluetooth devices, or regularly open external web pages.
A Turbulent Year of Fixes
The previous large wave came at the end of July, when updates across various Apple platforms collectively closed more than 300 vulnerabilities. The September record differs in counting methodology: it concerns more than 260 unique CVEs in a single cycle.
A month before the current release, Meta specialists discovered an image-processing error in ImageIO that could lead to arbitrary code execution on iPhone, iPad, and Mac. Such components are especially dangerous because they process potentially hostile data almost imperceptibly to the user.
The start of 2026 also proved uneasy. In February, Apple had to urgently close a zero-day vulnerability already used in sophisticated targeted attacks, one that affected several types of the company’s devices at once.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.