CVE-2026-28950: exploitation status and patch state
CVE-2026-28950 · EPSS 3%
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.8 and iPadOS 18.7.8, iOS 26.4.2 and iPadOS 26.4.2. Notifications marked for deletion could be unexpectedly retained on the device.
Is CVE-2026-28950 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 3%.
Public exploit code: none found in monitored sources.