Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-28972

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination or write kernel memory.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
iOS and iPadOS, watchOS, tvOS, visionOS, macOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-28971

The issue was addressed with improved UI handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. A malicious iframe may use another website’s download settings.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple
Product
iOS and iPadOS, Safari, visionOS, macOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-2897

A security vulnerability has been detected in funadmin up to 7.1.0-rc4. This vulnerability affects unknown code of the file app/backend/view/index/index.html of the component Backend Interface. The manipulation of the argument Value leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
n/a
Product
funadmin
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-28969

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
macOS, tvOS, watchOS, visionOS, iOS and iPadOS
Provider severity
HIGH
Conflicts
2

CVE-2026-28967

A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4. An attacker in a privileged network position may be able to cause a denial-of-service.

PUBLISHED
Vendor
Apple
Product
iOS and iPadOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-28965

A privacy issue was addressed with improved checks. This issue is fixed in iOS 26.5 and iPadOS 26.5. A user may be able to view restricted content from the lock screen.

PUBLISHED
Vendor
Apple
Product
iOS and iPadOS
Provider severity
HIGH
Conflicts
1

CVE-2026-28964

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 26.5 and iPadOS 26.5, visionOS 26.5. An app may be able to access sensitive user data.

PUBLISHED
Vendor
Apple, Apple
Product
visionOS, iOS and iPadOS
Provider severity
HIGH
Conflicts
2

CVE-2026-28963

A privacy issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26.5 and iPadOS 26.5. An attacker with physical access may be able to use Visual Intelligence to access sensitive user data during iPhone Mirroring.

PUBLISHED
Vendor
Apple
Product
iOS and iPadOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-28962

This issue was addressed with improved access restrictions. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. Processing maliciously crafted web content may disclose sensitive user information.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple
Product
visionOS, Safari, macOS, iOS and iPadOS
Provider severity
HIGH
Conflicts
2

CVE-2026-28961

This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. An attacker with physical access to a locked device may be able to view sensitive user information.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-2896

A weakness has been identified in funadmin up to 7.1.0-rc4. This affects the function setConfig of the file app/backend/controller/Ajax.php of the component Configuration Handler. Executing a manipulation can lead to improper authorization. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
n/a
Product
funadmin
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-28959

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
watchOS, iOS and iPadOS, macOS, tvOS, visionOS
Provider severity
HIGH
Conflicts
2

CVE-2026-28958

This issue was addressed with improved data protection. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. An app may be able to access sensitive user data.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple
Product
Safari, macOS, visionOS, iOS and iPadOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-28957

An issue with app access to camera metadata was addressed with improved logic. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, visionOS 26.5. An app may be able to capture a user's screen.

PUBLISHED
Vendor
Apple, Apple
Product
visionOS, iOS and iPadOS
Provider severity
LOW
Conflicts
2

CVE-2026-28956

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
iOS and iPadOS, watchOS, visionOS, macOS, tvOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-28955

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.

PUBLISHED
Vendor
Red Hat, Red Hat, Apple, Red Hat, Red Hat, Apple, Apple, Apple, Red Hat, Red Hat, Red Hat, Red Hat, Apple, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Apple
Product
Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, visionOS, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, watchOS, Safari, iOS and iPadOS, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, tvOS, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 7 Extended Lifecycle Support, macOS
Provider severity
HIGH
Conflicts
2

CVE-2026-28954

A file quarantine bypass was addressed with additional checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A maliciously crafted disk image may bypass Gatekeeper checks.

PUBLISHED
Vendor
Apple, Apple
Product
iOS and iPadOS, macOS
Provider severity
HIGH
Conflicts
2

CVE-2026-28953

A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper memory handling.

PUBLISHED
Vendor
Red Hat, Apple, Red Hat, Red Hat, Red Hat, Apple, Red Hat, Apple, Red Hat, Red Hat, Red Hat, Apple, Red Hat, Apple, Red Hat, Apple, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, visionOS, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 6, macOS, Red Hat Enterprise Linux 8, iOS and iPadOS, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 7 Extended Lifecycle Support, tvOS, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, watchOS, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Safari, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
Provider severity
HIGH
Conflicts
3

CVE-2026-28952

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to cause unexpected system termination.

PUBLISHED
Vendor
Apple, Apple
Product
iOS and iPadOS, macOS
Provider severity
HIGH
Conflicts
2

CVE-2026-28951

An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to gain root privileges.

PUBLISHED
Vendor
Apple, Apple
Product
macOS, iOS and iPadOS
Provider severity
HIGH
Conflicts
2

CVE-2026-28950

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 15.8.8 and iPadOS 15.8.8, iOS 16.7.16 and iPadOS 16.7.16, iOS 18.7.8 and iPadOS 18.7.8, iOS 26.4.2 and iPadOS 26.4.2, iPadOS 17.7.11. Notifications marked for deletion could be unexpectedly retained on the device.

PUBLISHED
Vendor
Apple, Apple
Product
iOS and iPadOS, iPadOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-2895

A security flaw has been discovered in funadmin up to 7.1.0-rc4. Affected by this issue is the function repass of the file app/frontend/controller/Member.php. Performing a manipulation of the argument forget_code/vercode results in weak password recovery. Remote exploitation of the attack is possible. The attack's complexity is rated as high. The exploitation is known to be difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about th

PUBLISHED
Vendor
n/a
Product
funadmin
Provider severity
LOW, MEDIUM
Conflicts
1

CVE-2026-28947

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.

PUBLISHED
Vendor
Red Hat, Red Hat, Apple, Red Hat, Apple, Red Hat, Red Hat, Red Hat, Red Hat, Apple, Red Hat, Red Hat, Apple, Red Hat, Red Hat, Apple, Apple, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, iOS and iPadOS, Red Hat Enterprise Linux 8, Safari, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat Enterprise Linux 9, tvOS, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 6, visionOS, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, macOS, watchOS, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Provider severity
HIGH
Conflicts
2

CVE-2026-28946

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Apple, Red Hat, Red Hat, Red Hat, Apple, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Safari, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, macOS, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-28945

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to bypass network restrictions.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
HIGH
Conflicts
1

CVE-2026-28944

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple
Product
visionOS, Safari, iOS and iPadOS, macOS
Provider severity
HIGH
Conflicts
2

CVE-2026-28943

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to determine kernel memory layout.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple
Product
tvOS, macOS, watchOS, iOS and iPadOS
Provider severity
HIGH
Conflicts
2

CVE-2026-28942

A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory management and result in an unexpected process crash.

PUBLISHED
Vendor
Red Hat, Apple, Red Hat, Red Hat, Red Hat, Apple, Red Hat, Red Hat, Red Hat, Apple, Red Hat, Apple, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Apple, Red Hat, Apple
Product
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, tvOS, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, iOS and iPadOS, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9, visionOS, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, watchOS, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 7 Extended Lifecycle Support, macOS, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Safari
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-28941

The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Tahoe 26.5. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.

PUBLISHED
Vendor
Apple, Apple
Product
iOS and iPadOS, macOS
Provider severity
HIGH
Conflicts
2

CVE-2026-28940

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5. Processing a maliciously crafted image may corrupt process memory.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple
Product
macOS, tvOS, iOS and iPadOS, visionOS
Provider severity
HIGH
Conflicts
2

CVE-2026-2894

A vulnerability was identified in funadmin up to 7.1.0-rc4. Affected by this vulnerability is the function getMember of the file app/frontend/view/login/forget.html. Such manipulation leads to information disclosure. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
n/a
Product
funadmin
Provider severity
MEDIUM
Conflicts
2

CVE-2026-28936

The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.8, macOS Sonoma 14.8.7, macOS Sonoma 14.8.8, macOS Tahoe 26.5, visionOS 26.5. Processing a maliciously crafted file may lead to unexpected app termination.

PUBLISHED
Vendor
Apple, Apple, Apple
Product
macOS, visionOS, iOS and iPadOS
Provider severity
HIGH
Conflicts
2

CVE-2026-28932

A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause a denial of service.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-28931

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. Connecting to a malicious NFS server may lead to kernel memory corruption.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple
Product
tvOS, iOS and iPadOS, macOS, watchOS
Provider severity
HIGH
Conflicts
2

CVE-2026-28930

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.5. An app may be able to access protected user data.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
HIGH
Conflicts
1

CVE-2026-2893

The Page and Post Clone plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' parameter in the content_clone() function in all versions up to, and including, 6.3. This is due to insufficient escaping on the user-supplied meta_key value and insufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensiti

PUBLISHED
Vendor
carlosfazenda
Product
Fast Page & Post Duplicator
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28929

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. Replying to an email could display remote images in Mail in Lockdown Mode.

PUBLISHED
Vendor
Apple, Apple
Product
iOS and iPadOS, macOS
Provider severity
HIGH
Conflicts
2

CVE-2026-28928

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple
Product
macOS, watchOS, tvOS, iOS and iPadOS
Provider severity
CRITICAL
Conflicts
2

CVE-2026-28926

A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to elevate privileges.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
HIGH
Conflicts
1

CVE-2026-28925

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to cause unexpected system termination or write kernel memory.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
HIGH
Conflicts
1

CVE-2026-28924

A race condition was addressed with improved handling of symbolic links. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to access Contacts without user consent.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
HIGH
Conflicts
1

CVE-2026-28923

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A malicious app may be able to break out of its sandbox.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
HIGH
Conflicts
1

CVE-2026-28922

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to access private information.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-28920

An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Visiting a maliciously crafted website may leak sensitive data.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
iOS and iPadOS, watchOS, macOS, visionOS, tvOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-2892

The Otter Blocks plugin for WordPress is vulnerable to Purchase Verification Bypass in all versions up to, and including, 3.1.4. This is due to the 'get_customer_data' method relying on an unsigned 'o_stripe_data' cookie to determine Stripe product ownership for unauthenticated users. The 'check_purchase' method trusts this cookie data without performing server-side verification against the Stripe API for one-time 'payment' mode purchases. This makes it possible for unauthenticated attackers to

PUBLISHED
Vendor
themeisle
Product
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
Provider severity
HIGH
Conflicts
0

CVE-2026-28919

A consistency issue was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to gain root privileges.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
HIGH
Conflicts
1

CVE-2026-28918

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Parsing a maliciously crafted file may lead to an unexpected app termination.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
iOS and iPadOS, tvOS, macOS, visionOS, watchOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-28917

The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple, Apple
Product
macOS, Safari, iOS and iPadOS, tvOS, watchOS, visionOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-28915

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to gain root privileges.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
HIGH
Conflicts
1

CVE-2026-28914

A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. A maliciously crafted ZIP archive may bypass Gatekeeper checks.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
MEDIUM
Conflicts
1