Security

Apple Patched 273 Vulnerabilities in a Day. Closing One Enterprise-Wide Still Takes Months.

Apple's September 14 update fixed 273 unique vulnerabilities in a single coordinated release. A month earlier, one macOS flaw Apple had already fixed was still being used to plant cryptocurrency miners, and Qualys's own 2026 benchmark says that gap is entirely normal.

September 17, 2026 · Security
A silver laptop on a wooden desk displaying an UPDATING progress screen, next to a red alarm clock and a wooden artist's mannequin

Key Takeaways

  • Apple's September 14, 2026 release fixed 273 unique vulnerabilities across macOS, iOS, iPadOS, watchOS, tvOS, visionOS, Safari and Xcode, collapsed down from 1,038 product-level CVE listings before deduplication.
  • CISA had already added a separate macOS Screen Sharing flaw, CVE-2026-65400, to its Known Exploited Vulnerabilities catalog a month earlier, after attackers used it to plant SSH backdoors and cryptocurrency miners, and gave federal agencies three days to patch.
  • Qualys's 2026 benchmark puts the average enterprise time to remediate a complex application at five months and ten days, versus 54.81 days for a high or critical application or API flaw.
  • Only 10 of the 273 September vulnerabilities were credited to AI-assisted discovery, 8 of them in macOS.

Two hundred and seventy-three is the kind of number that is supposed to feel reassuring. It is Apple closing the door on nearly three-quarters of a thousand product-level bug reports in a single, coordinated release, a scale of patching that would have been unthinkable a decade ago. It is also, on its own, close to meaningless, because a fix that exists is not the same thing as a fix that has been applied.

One Release, 273 Fixes, and a Bluetooth Bug That Reaches Every Platform

On September 14, 2026, Apple shipped iOS 27, iPadOS 27, macOS Golden Gate 27, watchOS 27, tvOS 27, visionOS 27, Safari 27 and Xcode 27, alongside maintenance updates for older supported versions. Across ten security advisories, the release addressed 273 unique CVE identifiers, a number that only emerges after deduplicating 1,038 product-level listings that repeat across overlapping bulletins.

Of those 273, Zero Day Initiative's review counted just two rated critical, but one of them reaches nearly everything Apple makes. CVE-2026-65414, an out-of-bounds write in Bluetooth, scored 9.8 and spans all eight operating systems in the release. ZDI flagged it as "automatable" with "total" technical impact, meaning a working exploit does not require a human operator once it exists. A separate high-severity bug in ImageIO, CVE-2026-65346, was called "the most dangerous remote content bug" in the batch because malicious images render automatically inside Messages, no click required. Apple's own advisories list none of the 273 as under active exploitation at the time of release.

The Bug Apple Had Already Fixed Shows What "Patched" Actually Buys

The more instructive story is not in the September batch at all. In August, Apple fixed CVE-2026-65400, an authentication weakness in the macOS Screen Sharing daemon that let a network attacker reach a fully authenticated remote-access session without valid credentials, gaining root. CISA rescored it to 9.8 and added it to its Known Exploited Vulnerabilities catalog on August 18, giving federal civilian agencies until August 21 to remediate under Binding Operational Directive 26-04.

That three-day window existed because the exploitation was already happening. Attackers who reached root through the Screen Sharing flaw were transferring SSH public keys onto the device, establishing persistent remote access, clearing logs and command history, altering packet-filter rules, and deploying the XMRig cryptocurrency miner. None of this required a zero-day. The fix already existed in macOS Sequoia 15.7.9, Sonoma 14.8.9 and Tahoe 26.6.1. The vulnerability that mattered was not in Apple's code anymore, it was in the interval between a patch shipping and a fleet actually installing it.

The Real Number Is Not 273, It Is Five Months and Ten Days

Qualys's 2026 Enterprise Patch and Remediation Benchmark puts the average mean time to remediation for a complex application at five months and ten days, and 54.81 days even for a high or critical application or API flaw. Set against a three-day federal deadline for a vulnerability already being used to mine cryptocurrency on compromised Macs, the gap is not a rounding error, it is close to two orders of magnitude. Qualys CEO Sumedh Thakar frames the fix as structural rather than procedural: "With about 40 million of the 150 million patches deployed by Qualys in the last 12 months being autonomously deployed already, with no human in the loop, it's clear that autonomous remediation is not the future, it's already here."

The September release adds one more wrinkle to the timeline problem. ZDI credited only 10 of the 273 vulnerabilities, 8 of them in macOS, to AI-assisted discovery, and noted that "Apple is not immune to the new normal of AI-assisted vulnerability discovery." That is a small share of this particular batch, but discovery tooling improves in one direction. A defender's patch cycle that already averages months was not built for a disclosure pipeline that gets faster on both the finding and the exploiting side at the same time.

Apple's part of this transaction gets faster every year. Ten advisories, 273 fixes, one release date. The part that has not moved at the same pace is everything that happens after the download finishes, and CVE-2026-65400 is the plainest possible evidence that the gap in between is where the actual damage still gets done.

Share

More in Security

All Resources →