DIRAS TAKE
Urgent: this is a pre-auth, network-exploitable memory corruption that can lead to remote code execution; apply Apple's available updates immediately to affected devices.
What is CVE-2026-64726?
An unauthenticated attacker can trigger memory corruption in Apple iOS and iPadOS and achieve remote code execution; this is tracked as CVE-2026-64726. The flaw affects iOS and iPadOS before 18.7.10 and before 26.6, and related Apple platforms listed below also have fixes. According to the CVSS vector the issue is exploitable over the network without privileges or user interaction, so an attacker only needs network access to a vulnerable device to attempt exploitation.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Apple iOS and iPadOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| iOS and iPadOS 18.x | before 18.7.10 | 18.7.10 |
| iOS and iPadOS 26.x | before 26.6 | 26.6 |
| macOS 26.x | before 26.6 | 26.6 |
| tvOS 26.x | before 26.6 | 26.6 |
| visionOS 26.x | before 26.6 | 26.6 |
| watchOS 26.x | before 26.6 | 26.6 |
Is CVE-2026-64726 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-64726
- Install vendor updates: update to iOS/iPadOS 18.7.10 or 26.6, and to macOS/tvOS/visionOS/watchOS 26.6 where applicable.
- If you cannot patch immediately, restrict network exposure of vulnerable devices from untrusted networks and services.
- Monitor device logs and network traffic for unusual connections or crashes and follow Apple security guidance.
Frequently asked questions
Is CVE-2026-64726 being actively exploited?
There are no public reports of exploitation as of 2026-09-29.
Which iOS and iPadOS versions are affected by CVE-2026-64726?
iOS and iPadOS releases before 18.7.10 and before 26.6 are listed as affected; related Apple platforms also have fixes in 26.6.
Is there a patch for CVE-2026-64726?
Yes. Apple released fixes in iOS and iPadOS 18.7.10 and 26.6, and in macOS/tvOS/visionOS/watchOS 26.6.
Does CVE-2026-64726 require authentication?
No. The vulnerability is exploitable without privileges or user interaction and can be reached over the network.
References
- nvd.nist.gov/vuln/detail/CVE-2026-64726
- cve.org/CVERecord?id=CVE-2026-64726
- support.apple.com/en-us/128066
- support.apple.com/en-us/128067
- support.apple.com/en-us/128068
- support.apple.com/en-us/128069
- support.apple.com/en-us/128070
- support.apple.com/en-us/148287
- All Apple CVEs on CVE Radar
- CVEs published in September 2026