CVE Tools

Apple Patches Everything (July 2026) - SANS ISC

SANS Internet Storm CenterBy SANS Internet Storm Center18 min read

PatchmacOSiOS

Our summary

Apple has issued a comprehensive set of security updates for all its major operating systems—macOS, iOS, iPadOS, tvOS, watchOS, visionOS, and Safari. The latest releases fix a total of 187 vulnerabilities, many affecting multiple platforms simultaneously. Notably, none of the issues were reported to be actively exploited in the wild.

Among the critical fixes are several related to ZIP archive handling, kernel memory corruption, and sandbox escape risks. These include CVE-2026-28849, CVE-2026-28900, and CVE-2026-28914, which may relate to a recently disclosed potential exploit method. The update also includes adjustments aimed at preparing users for upcoming major OS releases later this year.

Read at SANS Internet Storm Center

Below is the opening; the full story is at SANS Internet Storm Center.

From SANS Internet Storm Center

I am a bit late with this summary, but this week Apple released updates to all its operating systems and Safari. The Safari update, as usual, targets macOS prior to macOS 26. macOS updates covered the two older versions (14 and 15), while other operating system patches only covered the current 26 versions.…

Continue at SANS Internet Storm Center

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store