VORANT. Threat Intelligence Sign in Get the full feed

Apple patches 140+ iOS/iPadOS vulnerabilities

elevated vulnerability

NCSC-NL flags an Apple security update fixing over 140 iOS/iPadOS vulnerabilities, including a critical CVE-2026-65414 (CVSS 9.8); no in-the-wild exploitation reported.

The Dutch National Cyber Security Centre (NCSC-NL) published an advisory summarizing Apple's latest security update for iOS and iPadOS, which addresses a very large batch of vulnerabilities (well over 140 CVEs) spanning path traversal, cross-site scripting, stack-based buffer overflow, out-of-bounds read/write, race conditions, use-after-free, improper resource shutdown, external control of critical state data, and missing authorization issues. These flaws sit across core OS components including file handling, memory management, authentication processes, and web content rendering.

According to the advisory, successful exploitation could let an attacker gain unauthorized access to user data, cause application or system crashes, read or corrupt kernel memory, escalate privileges, bypass sandbox restrictions, or manipulate network traffic. Some issues could expose sensitive information such as Wi-Fi passwords, device identifiers, and user location data. The most severe entry, CVE-2026-65414, carries a CVSS v3 score of 9.8, with several others (CVE-2026-43686, CVE-2026-43715, CVE-2026-65415) rated 8.1–8.8. NCSC-NL does not indicate any of these vulnerabilities are being actively exploited in the wild; this is a routine, if unusually large, vendor patch release. Apple has issued fixes via improved validation, stricter access controls, better memory/state management, and removal of vulnerable code paths. Defenders should prioritize deployment of the latest iOS/iPadOS updates across managed fleets, particularly for the highest-CVSS entries, and track for any subsequent in-the-wild exploitation reporting.

Mentioned in this report

Vulnerabilities CVE-2026-20683CVE-2026-28966CVE-2026-28968CVE-2026-28969CVE-2026-43661CVE-2026-43664CVE-2026-43674CVE-2026-43684CVE-2026-43686CVE-2026-43687CVE-2026-43688CVE-2026-43689CVE-2026-43715CVE-2026-43738CVE-2026-43743CVE-2026-64718CVE-2026-64752CVE-2026-64753CVE-2026-64758CVE-2026-64760CVE-2026-65329CVE-2026-65395CVE-2026-65414CVE-2026-65415CVE-2026-84489CVE-2026-84492CVE-2026-84518CVE-2026-84519CVE-2026-84523CVE-2026-84596CVE-2026-84597CVE-2026-84607CVE-2026-84611CVE-2026-84617CVE-2026-84630CVE-2026-86876CVE-2026-86879CVE-2026-86882CVE-2026-86885CVE-2026-86903

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0370.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free