logo

Apple discloses first actively exploited zero-day of 2026

ID: 8efcec80-b3de-554f-a153-b873072d7ff1

STIX ID: report--8efcec80-b3de-554f-a153-b873072d7ff1

Feed Name: CyberScoop

Threat Score
85/100

Date Published: 2026-02-12

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

Apple disclosed a zero-day memory-corruption vulnerability (CVE-2026-20700) affecting dyld on iPhones and iPads, which was actively exploited in "extremely sophisticated" targeted attacks against specific individuals; the flaw can enable arbitrary code execution and was discovered by Google Threat Intelligence Group. CISA added the defect to its known exploited vulnerabilities catalog, and Apple addressed the issue in iOS/iPadOS 26.3 alongside fixes for two related WebKit vulnerabilities (CVE-2025-14174 and CVE-2025-43529).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.