Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
  • Home
  • Attack Feeds
  • Apple discloses first actively exploited zero-day of 2026  – CyberScoop
AttackFeed by Joe Wagner | Apple discloses first actively exploited zero-day of 2026  - CyberScoop

Apple discloses first actively exploited zero-day of 2026  – CyberScoop

Posted on February 12, 2026 By Matt Kapko
Attack Feeds

Apple disclosed a zero-day vulnerability Wednesday that the vendor warned was previously “exploited in an extremely sophisticated attack against specific targeted individuals,” the company said in a security update.

The memory-corruption vulnerability — CVE-2026-20700 — affects iPhones and iPads and was exploited on devices running versions of iOS before iOS 26. The Cybersecurity and Infrastructure Security Agency added the defect to its known exploited vulnerabilities catalog Thursday.

The disclosure marks the first zero-day reported by Apple since late 2025, and the first Apple defect flagged as actively exploited by CISA this year. 

“An attacker with memory write capability may be able to execute arbitrary code,” the company said.

Apple, which typically shares limited details about in-the-wild exploitation of zero-days, noted the latest zero-day, similar to others it disclosed last year, was exploited by sophisticated attackers targeting distinct people. 

The company did not immediately respond to a request for comment and did not describe the nature or objectives of the attacks.

Caitlin Condon, vice president of security research at VulnCheck, said the zero-day was likely exploited as part of a highly targeted spyware or surveillance attack on a very small number of individuals’ devices.

The zero-day vulnerability, which was discovered by Google Threat Intelligence Group, affects dyld, Apple’s open-source dynamic link editor that acts as a core system component to securely load applications on users’ devices. 

Apple said a pair of additional vulnerabilities affecting WebKit — CVE-2025-14174 and CVE-2025-43529 — were previously disclosed in response to attacks involving CVE-2026-20700. 

The company did not describe how the three vulnerabilities are related, but previously noted CVE-2025-43529 was “exploited in an extremely sophisticated attack against specific targeted individuals.”

All three of the memory-corruption defects affect mobile operating systems, “where sophisticated zero-day attacks are commonly employed to surveil individuals, whether those are political dissidents, journalists, public figures or other high-value targets,” Condon said.

“Memory-corruption exploits are also commonly seen in sophisticated attacks, as they’re tricky to exploit reliably but provide elevated access,” she added.

Apple’s security updates for iOS 26.3 and iPadOS 26.3 addresses 38 vulnerabilities total, but CVE-2026-20700 is the only defect it disclosed as actively exploited prior to public disclosure.

The post Apple discloses first actively exploited zero-day of 2026 appeared first on CyberScoop.

  –

Read More  – CyberScoop 

Post navigation

❮ Previous Post: Proofpoint acquires Acuvity to tackle the security risks of agentic AI  – CyberScoop
Next Post: Researchers Observe In-the-Wild Exploitation of BeyondTrust CVSS 9.9 Vulnerability  – The Hacker News ❯

You may also like

AttackFeed by Joe Wagner | NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE  - The Hacker News
Attack Feeds
NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE  – The Hacker News
May 17, 2026
AttackFeed by Joe Wagner | Operation Masquerade: FBI Disrupts Russian Router Hacking Campaign  - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
Operation Masquerade: FBI Disrupts Russian Router Hacking Campaign  – Hackread – Cybersecurity News, Data Breaches, AI and More
April 8, 2026
Attack Feeds
OVHcloud Founder Denies Massive 590TB Data Breach Claims  – Hackread – Cybersecurity News, Data Breaches, AI and More
March 24, 2026
AttackFeed by Joe Wagner | Patch Tuesday, February 2026 Edition  - Krebs on Security
Attack Feeds
Patch Tuesday, February 2026 Edition  – Krebs on Security
February 10, 2026
  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.