iOS 26.6.2 Carries Zero Published CVE Entries, Apple’s Index Shows

Apple iPhone 18 Pro 2up
Image: Apple

iOS 26.6.2 and iPadOS 26.6.2 shipped on September 8, 2026, and Apple’s own security releases index lists no CVE entries for either one. The row carries no link to a support article, because there is nothing underneath it to document.

Apple iPhone 18 Pro Photos app Apple Reference Image
Apple's iOS interface. iOS 26.6.2 predates iOS 27, the next release on Apple's software calendar. Image: Apple

That single line, on the page Apple maintains at support.apple.com/en-us/100100, is the entire public record of this release’s security content. Apple published a point update the day before its September 9 product event with zero disclosed vulnerabilities attached to it.

Key facts on iOS 26.6.2

ItemWhat Apple’s index shows
ReleaseiOS 26.6.2 and iPadOS 26.6.2
DateSeptember 8, 2026
Devices listediPhone 11 and later, iPad Pro 12.9-in 3rd gen and later, iPad Pro 11-in 1st gen and later, iPad Air 3rd gen and later, iPad 8th gen and later, iPad mini 5th gen and later
CVE entriesNone published
Linked support articleNone
Index it appears onsupport.apple.com/en-us/100100
Apple iPhone Duo colors
iPhone Duo. It ships with iOS 27, not the iOS 26.6.2 release covered here. Image: Apple

What the row on Apple’s index actually says

Apple’s security releases index lists one line per software release: a name, the devices it applies to, and a date. Most rows also carry a link through to a support article that itemizes CVE numbers with a short description of each fix. The iOS 26.6.2 row has the name, the devices and the date. It has no such link, and the index attaches no CVE identifiers to it at all.

Don’t miss the best of The Mac Observer

Set us as a preferred source and our Apple reporting ranks higher in your Google Search results and Discover feed — one tap, no account changes.

Or get it by email

This is a different situation from a release Apple marks as containing security fixes without full detail. There is simply no entry to expand.

Apple Watch Series 12 2up
Apple Watch, shown for illustration. This release is for iPhone and iPad, not watchOS. Image: Apple

How it compares with the release before it

iOS 26.6.2iOS 26.6.1
DateSep 8, 2026Aug 17, 2026
CVE entries published029
Linked support articleNonehttps://support.apple.com/en-us/148282
Actively exploited issue listedNot applicableNone listed

Twenty-two days separate the two releases. The last one Apple documented, iOS 26.6.1, carried 29 CVE entries including one in Telephony, CVE-2026-65329, which Apple’s own impact line describes as letting an attacker in a privileged network position bypass IPSec authentication and intercept network traffic. That document also states plainly that it lists no actively exploited issue. The one release after it carries no entries at all.

What no published CVE entries does and does not mean

  • It means Apple’s index lists no CVE identifiers against this specific release, and links to no support article for it.
  • It does not mean Apple has stated the release contains no changes at all; the index only speaks to security disclosures.
  • It is not the first time a release on this index has carried no CVE entries, and Apple’s page gives no standing explanation for when that happens.
  • It carries no comparison to any other platform’s release the same week; Apple’s index treats every row on its own.
  • It applies only to iOS 26.6.2 and iPadOS 26.6.2. Other rows on the same index, dated the same week or earlier, carry their own separate CVE counts.

The device list on the iOS 26.6.2 row is wide: iPhone 11 and later, plus a run of iPad Pro, iPad Air, iPad and iPad mini generations. That is the same shape of device list Apple used on the row above it, iOS 26.6.1, which is the release that did carry the 29 entries.

Timing, and what comes next on Apple’s calendar

iOS 26.6.2 landed one day before Apple’s September 9 event, where the company introduced the iPhone 18 Pro and iPhone Duo. Neither of those phones ships with iOS 26.6.2; both arrive with iOS 27, which reaches all eligible devices on Monday, September 14, and has not yet appeared as its own row on Apple’s security index.

What Apple has not said

Apple has not published a reason why iOS 26.6.2 carries no CVE entries, and it has not stated whether any security content was addressed in the release without a public disclosure. The index simply shows an empty column where 29 entries sat three weeks earlier.

As of Saturday, September 12, 2026, no follow-up entry has appeared on Apple’s index for iOS 26.6.2, and the next scheduled software milestone on Apple’s own calendar is iOS 27 on September 14.