CVE-2026-28894: Input Validation
802.1X. An authentication issue was addressed with improved state management.
Other sources
A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. A remote attacker may be able to cause a denial-of-service.
— NVD
Accounts. An authorization issue was addressed with improved state management.
— Apple
Admin Framework. A path handling issue was addressed with improved validation.
— Apple
apache. This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.
— Apple
APFS. A buffer overflow was addressed with improved bounds checking.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-28877
- CVE-2026-28959
- CVE-2026-28995
- CVE-2026-39869
- CVE-2026-28872
- CVE-2026-28894
- CVE-2026-28936
- CVE-2026-43659
- CVE-2026-28870
- CVE-2026-28977
- CVE-2026-28992
- CVE-2026-28943
- CVE-2026-28969
- CVE-2026-43654
- CVE-2026-28954
- CVE-2026-28897
- CVE-2026-28952
- CVE-2026-28951
- CVE-2026-28972
- CVE-2026-28986
- CVE-2026-28987
- CVE-2026-28983
- CVE-2026-28882
- CVE-2026-28929
- CVE-2026-43653
- CVE-2026-43668
- CVE-2026-43666
- CVE-2026-28940
- CVE-2026-28941
- CVE-2026-28906
- CVE-2026-28873
- CVE-2026-43656
- CVE-2026-28846
- CVE-2026-28993
- CVE-2026-28957
- CVE-2026-28907
- CVE-2026-43660
- CVE-2026-28847
- CVE-2026-28904
- CVE-2026-28903
- CVE-2026-28955
- CVE-2026-28953
- CVE-2026-28962
- CVE-2026-28917
- CVE-2026-28819
- CVE-2026-28994
- CVE-2026-28920
- CVE-2026-28865
- CVE-2026-28895
- CVE-2026-28879
- CVE-2026-28822
- CVE-2026-28874
- CVE-2026-28875
- CVE-2026-28866
- CVE-2026-20690
- CVE-2026-28886
- CVE-2026-28878
- CVE-2025-14524
- CVE-2026-28876
- CVE-2026-28880
- CVE-2026-28833
- CVE-2025-64505
- CVE-2026-28868
- CVE-2026-28867
- CVE-2026-20698
- CVE-2026-20687
- CVE-2026-20692
- CVE-2026-20688
- CVE-2026-28863
- CVE-2026-28864
- CVE-2026-28860
- CVE-2026-28856
- CVE-2026-28858
- CVE-2026-28967
- CVE-2026-28852
- CVE-2026-20657
- CVE-2026-20665
- CVE-2026-20643
- CVE-2026-28871
- CVE-2026-20664
- CVE-2026-28857
- CVE-2026-28861
- CVE-2026-28859
- CVE-2026-20691
- CVE-2025-55753
- CVE-2025-58098
- CVE-2025-59775
- CVE-2025-65082
- CVE-2025-66200
- CVE-2026-20637
- CVE-2026-28824
- CVE-2026-20699
- CVE-2026-20660
- CVE-2026-20639
- CVE-2026-28821
- CVE-2026-28838
- CVE-2026-28888
- CVE-2026-20633
- CVE-2026-28892
- CVE-2026-28832
- CVE-2026-20668
- CVE-2026-28834
- CVE-2026-20695
- CVE-2026-28829
- CVE-2026-20607
- CVE-2026-20651
- CVE-2026-20694
- CVE-2026-28891
- CVE-2026-20701
- CVE-2026-28839
- CVE-2026-28827
- CVE-2026-28816
- CVE-2026-28826
- CVE-2026-20693
- CVE-2026-28862
- CVE-2026-28831
- CVE-2026-28817
- CVE-2026-28835
- CVE-2026-28825
- CVE-2026-28818
- CVE-2026-20697
- CVE-2026-28828
- CVE-2026-28823
- CVE-2026-20696
- CVE-2026-20684
- CVE-2026-28910
- CVE-2026-28893
- CVE-2026-28881
- CVE-2026-28842
- CVE-2026-28841
- CVE-2026-28845
- CVE-2026-20632
- CVE-2026-20631
- CVE-2026-28840
- CVE-2026-28830
- CVE-2026-28820
- CVE-2026-28837
- CVE-2026-28844
Frequently Asked Questions
What is the severity of CVE-2026-28894?
CVE-2026-28894 has been classified as a high severity vulnerability that can lead to denial-of-service conditions.
How do I fix CVE-2026-28894?
To mitigate CVE-2026-28894, upgrade to iOS 26.4, iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, or macOS Tahoe 26.4.
Which versions of Apple products are affected by CVE-2026-28894?
CVE-2026-28894 affects iOS versions up to 26.4, iPadOS versions up to 26.4, macOS Tahoe versions up to 26.4, macOS Sequoia versions up to 15.7.5, and macOS Sonoma versions up to 14.8.5.
Can CVE-2026-28894 be exploited remotely?
Yes, a remote attacker may exploit CVE-2026-28894 to cause denial-of-service through inadequate input validation.
What types of issues does CVE-2026-28894 address?
CVE-2026-28894 addresses an authentication issue with improved state management and a denial-of-service issue with enhanced input validation.