CVE-2026-65329Medium· 5.9▾ SunlitAn authentication issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, iOS 27 and iPadOS 27. An attacker in a privileged network position may be able to bypass IPSec authentication and …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
0.2% → 0.2%
An authentication issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, iOS 27 and iPadOS 27. An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic.
ipados < 26.6.1iphone_os < 26.6.1Upgrade past the affected range:
ipados 26.6.1iphone_os 26.6.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-86890Medium· 4.6A logic issue was addressed with improved checks
CVE-2026-20683High· 7.1An authentication issue was addressed with improved state management
CVE-2026-43674Medium· 4.6An authentication issue was addressed with improved state management
CVE-2026-84606High· 7.5A privacy issue was addressed with improved handling of identifiers
CVE-2026-84521Medium· 5.5A use after free issue was addressed with improved memory management
CVE-2026-65349Medium· 6.6An out-of-bounds read was addressed with improved input validation