CVE-2026-65329

Summary

An authentication issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, iOS 27 and iPadOS 27. An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic.

Affected Software

VendorProductVersion RangeStatus
AppleiOS and iPadOS0 < 26.6.1affected
AppleiOS and iPadOS0 < 27affected

Weaknesses

  • An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References