Macrumors Apple Releases iOS 26.6 to Patch 78 Security Vulnerabilities
Article Content
- •iOS 26.6 and iPadOS 26.6 fix 78 vulnerabilities, including critical kernel and WebKit issues.
- •Apple has not reported any active exploitation of these vulnerabilities but urges immediate updates.
- •The updates also address security flaws in Wi-Fi, Siri, and image processing on iPhones.
On July 27, 2026, Apple released iOS 26.6 and iPadOS 26.6, addressing over 75 security vulnerabilities, including 78 individual entries tied to 87 unique CVEs. Key fixes include multiple kernel vulnerabilities that could allow for memory corruption and disclosure, as well as significant WebKit vulnerabilities affecting Safari. A Wi-Fi vulnerability was also patched, which could enable nearby attackers to corrupt process memory. While Apple has not confirmed any active exploitation of these vulnerabilities, the public disclosure raises concerns about potential attacks on unpatched devices. Users are strongly advised to update their devices immediately to mitigate risks associated with these vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (36)
Following this threat?
Track CVE-2026-39875 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…