Published Wednesday, September 16, 2026 at 05:36 PM PT

BLUF: Apple released 273 CVEs in September 2026 across all major platforms (macOS 27/Sequoia/Tahoe, iOS/iPadOS 27, visionOS, watchOS). At least one vulnerability is marked automatable with “technical impact: total” and spans eight OS platforms. Full scope still being mapped; immediate patch availability confirmed.
DETAILS:
- Volume: 273 unique CVEs in single monthly release; sourced from Zero Day Initiative security advisory
- Platform scope: Confirmed across macOS 27 (Golden Gate), macOS Sequoia 15.8, macOS Tahoe 26.7, iOS/iPadOS 27, visionOS 27, watchOS 27, and two additional platforms (tvOS/bridgeOS inferred but not explicitly confirmed in available text)
- Critical marker: At least one CVE tagged by CISA as “automatable: yes, technical impact: total” — indicates remote exploit potential with full system compromise possible; affects all eight major Apple OS platforms
- AI-assisted discovery noted: ZDI observes this release reflects “new normal of AI-assisted vulnerability discovery,” suggesting volume and complexity may exceed prior monthly releases
- Details truncated: Specific CVE IDs, severity scores, and per-platform vulnerability breakdown incomplete in available material
IMPACT:
- Scope: All macOS users (three active versions), all iOS/iPadOS users, Vision Pro, Apple Watch, and Apple TV ecosystem
- Severity range: Unknown — at least one automatable/total-impact CVE confirmed; remainder unvetted
- Estimated devices: Billions of installed Apple devices across platforms
RECOMMENDED ACTIONS:
- Immediate: Inventory macOS, iOS, visionOS, watchOS devices in your environment; confirm patch availability from Apple’s official security advisories (not yet fully summarized here)
- Triage: Once full advisory is published, identify which CVEs affect your footprint — automatable vulnerabilities take priority
- Staging: Begin patching macOS/iOS endpoints on a 48–72 hour timeline pending final severity assessment
- Monitor: Watch for exploitation indicators; automatable status suggests rapid weaponization risk
SOURCES:
- Zero Day Initiative — The Apple Security Update Review for September 2026 (source text truncated; full advisory recommended)
- CISA CVE metadata (automation/technical-impact tags confirmed)
STATUS: Developing — full CVE manifest and per-vulnerability details pending. This alert will be updated when complete ZDI and Apple advisories are available.
Recent high-severity events at publish time:

