Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-43726

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple, Apple
Product
iOS and iPadOS, watchOS, tvOS, macOS, visionOS, Safari
Provider severity
MEDIUM
Conflicts
2

CVE-2026-43725

The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to process restricted web content outside the sandbox.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple, Apple
Product
macOS, visionOS, Safari, tvOS, iOS and iPadOS, watchOS
Provider severity
HIGH
Conflicts
2

CVE-2026-43724

The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
iOS and iPadOS, visionOS, tvOS, macOS, watchOS
Provider severity
HIGH
Conflicts
2

CVE-2026-43723

A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to gain root privileges.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
visionOS, tvOS, macOS, watchOS, iOS and iPadOS
Provider severity
HIGH
Conflicts
2

CVE-2026-43722

The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2. An app may be able to leak sensitive kernel state.

PUBLISHED
Vendor
Apple, Apple
Product
iOS and iPadOS, macOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-43721

This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to silently hijack clipboard data.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple, Apple
Product
watchOS, Safari, tvOS, visionOS, macOS, iOS and iPadOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-43720

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple, Apple
Product
macOS, visionOS, tvOS, Safari, watchOS, iOS and iPadOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-4372

A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.json` file containing the `_attn_implementation_internal` field set to an attacker-controlled HuggingFace Hub repository ID. When a victim loads this model using the standard `AutoModelForCausalLM.from_pretrained()` API, the library downloads and executes arbitrary Python code from the attacker's re

PUBLISHED
Vendor
huggingface
Product
huggingface/transformers
Provider severity
HIGH
Conflicts
0

CVE-2026-43718

A stack overflow was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple, Apple
Product
iOS and iPadOS, tvOS, Safari, watchOS, macOS, visionOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-43717

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
tvOS, Safari, watchOS, macOS, iOS and iPadOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-43716

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.

PUBLISHED
Vendor
Apple, Apple, Apple
Product
macOS, Safari, iOS and iPadOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-43715

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple, Apple
Product
watchOS, macOS, Safari, iOS and iPadOS, visionOS, tvOS
Provider severity
HIGH
Conflicts
2

CVE-2026-43714

The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. A malicious app may be able to access protected user data.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple
Product
watchOS, iOS and iPadOS, visionOS, macOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-43713

A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Visiting a website may leak sensitive data.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple, Apple
Product
watchOS, tvOS, iOS and iPadOS, Safari, visionOS, macOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-43712

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple, Apple
Product
visionOS, iOS and iPadOS, watchOS, macOS, tvOS, Safari
Provider severity
MEDIUM
Conflicts
2

CVE-2026-43711

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted video file may lead to unexpected app termination.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
tvOS, iOS and iPadOS, visionOS, watchOS, macOS
Provider severity
HIGH
Conflicts
2

CVE-2026-43710

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An attacker may be able to cause unexpected system termination or corrupt kernel memory.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
CRITICAL
Conflicts
1

CVE-2026-4371

A flaw was found in Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue: A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Mozilla, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 10.0 Extended Update Support, Thunderbird, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 9.6 Extended Update Support
Provider severity
HIGH
Conflicts
3

CVE-2026-43709

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple, Apple
Product
tvOS, Safari, iOS and iPadOS, visionOS, watchOS, macOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-43708

The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may exfiltrate data cross-origin.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple, Apple
Product
watchOS, visionOS, macOS, iOS and iPadOS, Safari, tvOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-43707

A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple, Apple
Product
Safari, macOS, watchOS, visionOS, iOS and iPadOS, tvOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-43706

A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
visionOS, macOS, watchOS, tvOS, iOS and iPadOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-43705

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple, Apple
Product
tvOS, watchOS, iOS and iPadOS, macOS, Safari, visionOS
Provider severity
HIGH
Conflicts
2

CVE-2026-43704

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious web extension may be able to cause an unexpected process crash.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple, Apple
Product
Safari, macOS, watchOS, tvOS, visionOS, iOS and iPadOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-43703

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
visionOS, tvOS, iOS and iPadOS, watchOS, macOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-43701

The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to process restricted web content outside the sandbox.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple, Apple
Product
iOS and iPadOS, Safari, tvOS, visionOS, macOS, watchOS
Provider severity
HIGH
Conflicts
2

CVE-2026-43700

A cross-origin issue was addressed with improved tracking of security origins. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may disclose sensitive user information.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple, Apple
Product
watchOS, Safari, macOS, visionOS, tvOS, iOS and iPadOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-4370

A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the internal Dqlite database cluster fails to perform proper TLS client and server authentication. Specifically, the Juju controller's database endpoint does not validate client certificates when a new node attempts to join the cluster. An unauthenticated attacker with network reachability to the Juju controller's Dqlite port can exploit this flaw to join the database cluster. Once join

PUBLISHED
Vendor
Canonical
Product
Juju
Provider severity
CRITICAL
Conflicts
1

CVE-2026-43699

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple, Apple
Product
Safari, iOS and iPadOS, macOS, visionOS, watchOS, tvOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-43698

An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to gain root privileges.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
HIGH
Conflicts
1

CVE-2026-43694

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or write kernel memory.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
CRITICAL
Conflicts
1

CVE-2026-43693

A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
HIGH
Conflicts
1

CVE-2026-4369

A maliciously crafted HTML payload in an assembly variant name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process.

PUBLISHED
Vendor
Autodesk
Product
Fusion
Provider severity
HIGH
Conflicts
0

CVE-2026-43685

A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to inject arbitrary operating system commands through unsanitized input in the External ODBC Data Source connection test feature. This issue is fixed in FileMaker Cloud 2.22.0.5.

PUBLISHED
Vendor
Claris
Product
FileMaker Cloud
Provider severity
HIGH
Conflicts
1

CVE-2026-43682

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
CRITICAL
Conflicts
1

CVE-2026-43681

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A local user may be able to read kernel memory.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
HIGH
Conflicts
1

CVE-2026-43680

A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to bypass a front-end restriction on OS Script schedule types and execute arbitrary operating system commands on the underlying host. This issue is fixed in FileMaker Cloud 2.22.0.5.

PUBLISHED
Vendor
Claris
Product
FileMaker Cloud
Provider severity
HIGH
Conflicts
1

CVE-2026-4368

Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup

PUBLISHED
Vendor
NetScaler, NetScaler
Product
Gateway, ADC
Provider severity
HIGH
Conflicts
1

CVE-2026-43676

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
watchOS, iOS and iPadOS, Safari, visionOS, macOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-43673

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted audio file may corrupt process memory.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
tvOS, visionOS, iOS and iPadOS, watchOS, macOS
Provider severity
HIGH
Conflicts
2

CVE-2026-43672

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious application may be able to bypass Privacy preferences.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
HIGH
Conflicts
1

CVE-2026-4367

A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file's end, leading to application crashes and Denial of Service conditions.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Hardened Images, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 6
Provider severity
MEDIUM
Conflicts
1

CVE-2026-43668

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
macOS, iOS and iPadOS, visionOS, watchOS, tvOS
Provider severity
HIGH
Conflicts
2

CVE-2026-43666

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An attacker on the local network may be able to cause a denial-of-service.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
tvOS, watchOS, macOS, iOS and iPadOS, visionOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-43665

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A local attacker may be able to determine the legacy VNC password configured for Screen Sharing.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-43663

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple, Apple
Product
iOS and iPadOS, visionOS, macOS, tvOS, Safari, watchOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-43661

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. Processing a maliciously crafted image may corrupt process memory.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple
Product
tvOS, macOS, watchOS, iOS and iPadOS
Provider severity
HIGH
Conflicts
2

CVE-2026-43660

A validation issue was addressed with improved logic. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple, Apple
Product
visionOS, macOS, iOS and iPadOS, watchOS, Safari, tvOS
Provider severity
HIGH
Conflicts
2

CVE-2026-4366

A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirects when processing certain client configuration requests. This behavior allows an attacker to trick the server into making unintended requests to internal or restricted resources. As a result, sensitive internal services such as cloud metadata endpoints could be accessed. This issue may lead to information disclosure and enable attackers to map internal network infrastructure.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat build of Keycloak 26.4, Red Hat JBoss Enterprise Application Platform 8, Red Hat Single Sign-On 7, Red Hat Build of Keycloak, Red Hat build of Keycloak 26.4.12, Red Hat build of Keycloak 26.4, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Build of Keycloak, Red Hat build of Keycloak 26.4
Provider severity
MEDIUM
Conflicts
1

CVE-2026-43659

A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, visionOS 26.5. An app may be able to access sensitive user data.

PUBLISHED
Vendor
Apple, Apple, Apple
Product
visionOS, macOS, iOS and iPadOS
Provider severity
MEDIUM
Conflicts
2