CVE-2026-65329
published 2026-08-17CVE-2026-65329: An authentication issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1. An attacker in a privileged network…
PriorityP432medium5.9CVSS 3.1
AVAACHPRNUINSUCHILAN
EPSS
0.17%
6.6th percentile
An authentication issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1. An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_and_ipados | < 26.6.1 | 26.6.1 |
| apple | ipados | < 26.6.1 | 26.6.1 |
| apple | iphone_os | < 26.6.1 | 26.6.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
An authentication issue was addressed with improved state management.
ghsa_unreviewed·2026-08-18
CVE-2026-65329 [MEDIUM] CWE-287 An authentication issue was addressed with improved state management.
An authentication issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1. An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic.
VulDB
Apple iOS/iPadOS up to 26.6.0 improper authentication
vuldb·2026-08-17
CVE-2026-65329 [CRITICAL] Apple iOS/iPadOS up to 26.6.0 improper authentication
A vulnerability described as critical has been identified in Apple iOS and iPadOS up to 26.6.0. This impacts an unknown function. Such manipulation leads to improper authentication.
This vulnerability is documented as CVE-2026-65329. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
2026-08-17
Published