CVE-2021-30666
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 20, 2026
11 articles
EPSS Score
Source: FIRST.org · 2026-05-24
1.18%
probability
This CVE has a 1.18% probability
of being exploited in the next 30 days.
0%
Top 79.0th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Attack Intelligence
Apple fixes zero-day in iOS and iPadOS 15.0.2 emergency release: Detect and Prioritize Vulnerabilities using VMDR for Mobile Devices
Qualys
Oct 18, 2021
Emergency Apple iOS 15.0.2 update fixes zero-day used in attacks
BleepingComputer
Oct 11, 2021
Apple fixes iOS zero-day used to deploy NSO iPhone spyware
BleepingComputer
Sep 13, 2021
Apple fixes zero-day affecting iPhones and Macs, exploited in the wild
BleepingComputer
Jul 26, 2021
Apple patches new zero-day bug used to hack iPhones and Macs
BleepingComputer
Sep 23, 2021
Apple fixes ninth zero-day bug exploited in the wild this year
BleepingComputer
Jun 15, 2021
Apple fixes bug that breaks iPhone WiFi when joining rogue hotspots
BleepingComputer
Jul 23, 2021
Qualys Response to CISA Alert: Binding Operational Directive 22-01
Qualys
Nov 09, 2021
Signal Intelligence
Confidence
92%
EPSS
1.18%
Mentions
11
Last Seen
Nov 09, 2021
CNA Information
Analyst Note
Multiple authoritative sources (Qualys, BleepingComputer) explicitly identify CVE-2021-30666 as a zero-day exploited in the wild, with Apple issuing an emergency patch (iOS 15.0.2) to address active attacks. The exploitation preceded or coincided with patch availability, meeting zero-day criteria.
Triage Info
Decided atMar 20, 2026