Apple's September 14 update fixed 273 unique vulnerabilities in a single coordinated release. A month earlier, one macOS flaw Apple had already fixed was still being used to plant cryptocurrency miners, and Qualys's own 2026 benchmark says that gap is entirely normal.
Key Takeaways
Two hundred and seventy-three is the kind of number that is supposed to feel reassuring. It is Apple closing the door on nearly three-quarters of a thousand product-level bug reports in a single, coordinated release, a scale of patching that would have been unthinkable a decade ago. It is also, on its own, close to meaningless, because a fix that exists is not the same thing as a fix that has been applied.
On September 14, 2026, Apple shipped iOS 27, iPadOS 27, macOS Golden Gate 27, watchOS 27, tvOS 27, visionOS 27, Safari 27 and Xcode 27, alongside maintenance updates for older supported versions. Across ten security advisories, the release addressed 273 unique CVE identifiers, a number that only emerges after deduplicating 1,038 product-level listings that repeat across overlapping bulletins.
Of those 273, Zero Day Initiative's review counted just two rated critical, but one of them reaches nearly everything Apple makes. CVE-2026-65414, an out-of-bounds write in Bluetooth, scored 9.8 and spans all eight operating systems in the release. ZDI flagged it as "automatable" with "total" technical impact, meaning a working exploit does not require a human operator once it exists. A separate high-severity bug in ImageIO, CVE-2026-65346, was called "the most dangerous remote content bug" in the batch because malicious images render automatically inside Messages, no click required. Apple's own advisories list none of the 273 as under active exploitation at the time of release.
The more instructive story is not in the September batch at all. In August, Apple fixed CVE-2026-65400, an authentication weakness in the macOS Screen Sharing daemon that let a network attacker reach a fully authenticated remote-access session without valid credentials, gaining root. CISA rescored it to 9.8 and added it to its Known Exploited Vulnerabilities catalog on August 18, giving federal civilian agencies until August 21 to remediate under Binding Operational Directive 26-04.
That three-day window existed because the exploitation was already happening. Attackers who reached root through the Screen Sharing flaw were transferring SSH public keys onto the device, establishing persistent remote access, clearing logs and command history, altering packet-filter rules, and deploying the XMRig cryptocurrency miner. None of this required a zero-day. The fix already existed in macOS Sequoia 15.7.9, Sonoma 14.8.9 and Tahoe 26.6.1. The vulnerability that mattered was not in Apple's code anymore, it was in the interval between a patch shipping and a fleet actually installing it.
Qualys's 2026 Enterprise Patch and Remediation Benchmark puts the average mean time to remediation for a complex application at five months and ten days, and 54.81 days even for a high or critical application or API flaw. Set against a three-day federal deadline for a vulnerability already being used to mine cryptocurrency on compromised Macs, the gap is not a rounding error, it is close to two orders of magnitude. Qualys CEO Sumedh Thakar frames the fix as structural rather than procedural: "With about 40 million of the 150 million patches deployed by Qualys in the last 12 months being autonomously deployed already, with no human in the loop, it's clear that autonomous remediation is not the future, it's already here."
The September release adds one more wrinkle to the timeline problem. ZDI credited only 10 of the 273 vulnerabilities, 8 of them in macOS, to AI-assisted discovery, and noted that "Apple is not immune to the new normal of AI-assisted vulnerability discovery." That is a small share of this particular batch, but discovery tooling improves in one direction. A defender's patch cycle that already averages months was not built for a disclosure pipeline that gets faster on both the finding and the exploiting side at the same time.
Apple's part of this transaction gets faster every year. Ten advisories, 273 fixes, one release date. The part that has not moved at the same pace is everything that happens after the download finishes, and CVE-2026-65400 is the plainest possible evidence that the gap in between is where the actual damage still gets done.
Guide
A three-day federal patch deadline only works if enrolled Macs are already configured to comply. This is the audit-ready checklist for proving that they are.
Download
Guide
Qualys already runs 40 million patches a year with no human in the loop. This is the framework for closing the remaining manual gap without slowing release velocity.
Download
Whitepaper
Not every Mac in a distributed fleet updates the day a fix ships. This covers the endpoint and access controls that carry the risk until it does.
Download
Moonlock Lab found unique malicious macOS samples up roughly 40% year over year, and that two stealer families now dominate detections.
Cisco Talos found phishing back on top for initial access, and CrowdStrike found most of what follows is now malware-free.
A sweeping analysis of incident data across 500 enterprises asks whether zero trust has delivered on its promise.