What Apple published on 27 July
Apple's security pages filled up in a single block on 27 July. macOS Tahoe 26.6 arrived as build 25G72 carrying 155 unique CVE identifiers, with Safari 26.6 alongside it. iOS 26.6 and iPadOS 26.6 listed 78 separate vulnerability entries tied to 87 unique CVEs. The updates for watchOS, tvOS and visionOS 26.6 accounted for a further 194 once the overlap between platforms was removed.
The named components read like an inventory of the whole system rather than one weak corner. On the phone the fixes touch the kernel, WebKit, Wi-Fi, Siri, the App Store, MediaRemote, ImageIO, SceneKit, libc, CloudAttestation, Game Center, Accessibility and Contacts. On the Mac the descriptions are blunter: flaws that could let an application gain root, escape its sandbox, bypass Gatekeeper, step around privacy preferences, or reach protected data.
Apple does not say that any of them were being exploited before the updates shipped, and no outlet has produced evidence to the contrary. Counting them is oddly hard: specialist publications working from the same Apple document have arrived at figures between roughly 130 and 155, depending on whether they count entries or identifiers. That spread is a small thing, but it tells you the inventory is written for humans to read rather than for a tool to parse.
Seven attempts is the part worth reading
The detail that matters is not in the CVE count. macOS Sequoia 15.7.8 and macOS Sonoma 14.8.8 shipped on the same day, and they reached release only after Apple issued seven release candidates. A fifth candidate on 13 July was unusual enough to be reported as rare on its own. Two more followed.
Read that as an engineering signal, not trivia. A release candidate is the build a vendor believes is finished. Issuing seven of them means Apple repeatedly believed the backport was done and repeatedly found it was not. The current branch, Tahoe, needed no such churn: it was authored once against the code the fixes were written for.
Between them, Sequoia 15.7.8 and Sonoma 14.8.8 address more than 138 distinct vulnerabilities. The volume is comparable to Tahoe's. What differs is the difficulty of getting it there, and Apple's release notes for the two older branches say almost nothing about it, offering only that these are important security fixes recommended for all users still running them.
The stability argument runs backwards
Most fleets that sit a version behind do it deliberately. The reasoning is familiar and usually sound: let other people find the regressions, keep the estate on a build that has been in the world long enough to be boring, upgrade when the business has a quiet week. Applied to features, that logic holds.
Applied to security patches, 27 July inverts it. The older branch is not the settled one. It is the one that required seven attempts to produce, because a backport is not the same work as a fix: the flaw is found and repaired in current code, then carried backwards into a codebase that has since moved on. Every version of separation between your estate and Apple's head of line is engineering distance that someone has to close under time pressure, and this month it took them seven goes.
The second-order point is about evidence rather than risk appetite. NIS2 asks in-scope organisations to handle vulnerabilities as a documented process, not as an instinct, and an auditor's question is rarely whether you patched. It is when you knew, what you decided, and why. "We stay one version back for stability" is a defensible answer only until the record shows the older branch is the slower and more fragile one to receive fixes. In Germany that record is read by the BSI, and the equivalent question lands with the NCSC for organisations operating in the UK.
The order to work in this week
Start with the machines that are already exposed, not the ones that are easiest to reach. Anything running Safari or WebKit against untrusted pages, any Mac where a standard user could plausibly be tricked into opening a crafted file, and any device outside the office network belongs in the first wave. The Gatekeeper and privacy-preference bypasses matter most on laptops that leave the building.
Then deal with the older estate honestly. If a set of Macs is on Sonoma or Sequoia because the hardware cannot take Tahoe, that is a fact to plan around and eventually budget for, not a posture to defend. If they are on an older release by choice, this is the month to ask whether the choice is still buying what it was meant to buy.
One thing to write down. Note the date the notes were published and the date each group of devices was updated, because the gap between those two numbers is the only part of this an auditor can check later, and it is the only part you control.
Read next: The nginx Patch Is Out, the Exploit Lands in August | Two Cursor Flaws Rated 9.8 Hand a Developer's Machine to Attackers



