All Threat Alerts
criticalThreat Update
CVE-2026-28958CVE-2026-28973CVE-2026-28984CVE-2026-28990CVE-2026-28996CVE-2026-39868CVE-2026-39877CVE-2026-43661CVE-2026-43663CVE-2026-43667CVE-2026-43673CVE-2026-43676CVE-2026-43700CVE-2026-43701CVE-2026-43705CVE-2026-43708CVE-2026-43711CVE-2026-43714CVE-2026-43717CVE-2026-43720CVE-2026-43722CVE-2026-43723CVE-2026-43724CVE-2026-43725CVE-2026-43727CVE-2026-43729CVE-2026-43731CVE-2026-43735CVE-2026-43738CVE-2026-43742CVE-2026-43744CVE-2026-43745CVE-2026-43754CVE-2026-43757CVE-2026-43769CVE-2026-43776CVE-2026-43778CVE-2026-43794CVE-2026-43796CVE-2026-43797CVE-2026-43800CVE-2026-43801CVE-2026-43802CVE-2026-43803CVE-2026-43807CVE-2026-43810CVE-2026-43811CVE-2026-43812CVE-2026-43818CVE-2026-43821CVE-2026-64692CVE-2026-64693CVE-2026-64695CVE-2026-64700CVE-2026-64707CVE-2026-64709CVE-2026-64715CVE-2026-64719CVE-2026-64721CVE-2026-64722CVE-2026-64723CVE-2026-64724CVE-2026-64725CVE-2026-64726CVE-2026-64732CVE-2026-64734CVE-2026-64735CVE-2026-64738CVE-2026-64739CVE-2026-64740CVE-2026-64742CVE-2026-64743CVE-2026-64744CVE-2026-64746CVE-2026-64747CVE-2026-64749CVE-2026-64755CVE-2026-64757CVE-2026-64760CVE-2026-64762CVE-2026-64763CVE-2026-64764CVE-2026-64765CVE-2026-64768CVE-2026-64769CVE-2026-64771CVE-2026-64772CVE-2026-64774CVE-2026-64778CVE-2026-64779CVE-2026-64780CVE-2026-64781CVE-2026-64782CVE-2026-64784CVE-2026-64787CVE-2026-64788CVE-2026-65329CVE-2026-65330CVE-2026-65331CVE-2026-65334CVE-2026-65338CVE-2026-65339CVE-2026-65340CVE-2026-65341CVE-2026-65343CVE-2026-65346CVE-2026-65347CVE-2026-65349

SANS Internet Storm Center Advisory โ€” Aug 17, 2026

Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single screen-sharing vulnerability. This vulnerability did not affect iOS/iPadOS. ]]>

Tuesday, August 18, 2026AppleVulnios Threat Intelligence
Share:

Vulnerability Snapshot

CVE-2026-28958 is rated CRITICAL โ€” exploitation is trivial or already observed in the wild and impact is severe. Patch immediately, not on the next maintenance window.

Affected technology: Safari.

Executive Summary

Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single screen-sharing vulnerability. This vulnerability did not affect iOS/iPadOS. ]]>

Source

How Vulnios Detects This

Vulnios scans for this vulnerability using Trivy and Grype for SBOM-based CVE matching and Vulnios CVE feed continuous monitoring against your asset inventory. Run a scan against your environment to see whether you are exposed; findings are linked back to the original CVE record so triage starts with the patch path already known.

AI Security Advisor

Powered by Gemini

Get AI-powered security recommendations tailored to this specific threat โ€” including risk assessment, detection guidance, MITRE ATT&CK mapping, and actionable remediation steps.

Affected Products

Safari

Related Threat Alerts

Frequently Asked Questions

What is CVE-2026-28958?

CVE-2026-28958 is a critical-severity vulnerability tracked under the Common Vulnerabilities and Exposures program. Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single scre

Am I affected?

Check whether your environment runs Safari. If you operate any of those, treat yourself as in scope until you have evidence otherwise. A Vulnios scan will identify the exact assets carrying the affected version.

How urgent is the response?

Critical: do not wait for your normal patch cycle. Verify exposure today, apply the vendor patch immediately, and add detection rules for any post-exploit indicators.

How do I remediate?

Apply the vendor patch listed in the upstream advisory linked under Sources. If the patch is not yet available, follow the vendor-supplied workaround (often a config flag or feature disable) and add detections for the published exploit pattern in your SIEM. Re-scan after the patch lands to confirm the finding clears.

Where can I track exploitation activity?

Watch CISA's Known Exploited Vulnerabilities catalog for CVE-2026-28958. Cross-reference with public exploit databases and your own SIEM/IDS for indicator-of-compromise patterns. Vulnios tracks KEV status automatically and surfaces it on the asset findings view.

How does Vulnios help with this?

Vulnios continuously cross-references your asset inventory against the live CVE feed (NVD, vendor advisories, CISA KEV, and curated OSINT). When a new CVE matches your environment, you get a prioritized finding with the severity, KEV status, exploit-prediction (EPSS), and a direct path to the vendor patch. You can start a free scan from the homepage.

sansiscincidentdaily-summaryrceidentityics-otmalwareApple

Protect Your Organization

Monitor CVEs, scan for vulnerabilities, and get real-time threat alerts โ€” all in one platform.

Weekly threat digest

KEV-listed exploits and vendor advisories, every Monday.

One email a week. Unsubscribe any time.

Get instant alerts on Telegram

Join our public channel for real-time critical CVE alerts.

Follow @vulnios