Apple discloses first actively exploited zero-day of 2026
ID: 8efcec80-b3de-554f-a153-b873072d7ff1
STIX ID: report--8efcec80-b3de-554f-a153-b873072d7ff1
Feed Name: CyberScoop
Apple disclosed a zero-day memory-corruption vulnerability (CVE-2026-20700) affecting dyld on iPhones and iPads, which was actively exploited in "extremely sophisticated" targeted attacks against specific individuals; the flaw can enable arbitrary code execution and was discovered by Google Threat Intelligence Group. CISA added the defect to its known exploited vulnerabilities catalog, and Apple addressed the issue in iOS/iPadOS 26.3 alongside fixes for two related WebKit vulnerabilities (CVE-2025-14174 and CVE-2025-43529).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
