Patch SLA Tracker

CVE-2026-20700

Exploited before a patch existed (Apple: “may have been exploited”).

Export this CVE's branch rows: CSV · JSON · Permalink: /cve/CVE-2026-20700

First fix
(iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3)
CISA KEV added
(1 day after the first fix)
NVD published
(same day)

First fix: The release date of the earliest Apple update (including Rapid Security Responses and Background Security Improvements) whose advisory lists the CVE.

KEV date added (proxy): CISA KEV “date added” is when CISA catalogued evidence of exploitation. It is a lagging proxy: exploitation started on or before that date, usually well before.

Fix per branch

Backport gap: For one CVE and one branch: the branch's first fix date minus the earliest fix date across all branches of the same platform.

No fix listed: The branch is still maintained (it shipped a security update after the earliest fix, or its last security update is under 180 days old), but no Apple advisory lists this CVE for it as of the data date. The branch may be unaffected; Apple does not publish “not affected” statements.

Branch ended: The branch shipped no security update after the earliest fix and none in the 180 days before the data date, so it is treated as ended and not counted as missing a backport. Updates without published CVE entries do not keep a branch alive.

Fixed at branch release: The branch was first released after the earliest fix, so it is not a backport and is not counted. “Listed”: its advisory names the CVE. “Inherited”: it does not, and the fix is assumed to be in the branch from its first release.

CVE-2026-20700 timeline across branchesiOS 27 fixed on 2026-09-14 (215 days after first fix, branch released later); iOS 26 fixed on 2026-02-11 (0 days after first fix); iPadOS 27 fixed on 2026-09-14 (215 days after first fix, branch released later); iPadOS 26 fixed on 2026-02-11 (0 days after first fix); macOS 27 Golden Gate fixed on 2026-09-14 (215 days after first fix, branch released later); macOS 26 Tahoe fixed on 2026-02-11 (0 days after first fix); KEV added on 2026-02-12; NVD published on 2026-02-11KEV added 2026-02-12NVD published 2026-02-11iOS 27iOS 26iPadOS 27iPadOS 26macOS 27 Golden GatemacOS 26 Tahoe2026-02-112026-09-14
Filled circle: first fix on that branch. Hollow circle: branch first released after the earliest fix, so it shipped with the fix (not a backport).
iOS: earliest fix
BranchStatusFirst fix on branchGap
iOS 27fixed at branch release (inherited) first iOS 27 release–
iOS 26fixed with the earliest fix iOS 26.3 and iPadOS 26.30 d
iOS 18no fix listed––
iOS 17branch ended––
iOS 16no fix listed––
iOS 15no fix listed––
iOS 14branch ended––
iOS 13branch ended––
iOS 12branch ended––
iPadOS: earliest fix
BranchStatusFirst fix on branchGap
iPadOS 27fixed at branch release (inherited) first iPadOS 27 release–
iPadOS 26fixed with the earliest fix iOS 26.3 and iPadOS 26.30 d
iPadOS 18no fix listed––
iPadOS 17no fix listed––
iPadOS 16no fix listed––
iPadOS 15no fix listed––
iPadOS 14branch ended––
iPadOS 13branch ended––
macOS: earliest fix
BranchStatusFirst fix on branchGap
macOS 27 Golden Gatefixed at branch release (inherited) first macOS 27 Golden Gate release–
macOS 26 Tahoefixed with the earliest fix macOS Tahoe 26.30 d
macOS 15 Sequoiano fix listed––
macOS 14 Sonomano fix listed––
macOS 13 Venturabranch ended––
macOS 12 Montereybranch ended––
macOS 11 Big Surbranch ended––
macOS 10 Catalinabranch ended––

Every Apple listing

Each release whose advisory lists CVE-2026-20700, with Apple's own notes.

Apple advisories listing CVE-2026-20700
ReleaseBranchReleasedEntry addedExploited note
iOS 26.3 and iPadOS 26.3iOS 26with releaseyes
iOS 26.3 and iPadOS 26.3iPadOS 26with releaseyes
macOS Tahoe 26.3macOS 26 Tahoewith releaseyes