Security Box Score — September 14, 2026 — page 2
Edition of September 14, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-91079 | 6.3 | — | hcengineering | platform | CWE-918 | Huly Platform through 0.7.426 SSRF via Print Service |
| CVE-2026-19543 | 6.2 | — | IBM | Common Licensing | CWE-20 | Multiple vulnerabilities affect IBM License Key Server Administration and Rep… |
| CVE-2026-55073 | 6.2 | — | Kozea | WeasyPrint | CWE-918 | WeasyPrint restrictive URL fetcher bypass allows local file read and SSRF |
| CVE-2026-55846 | 6.2 | — | allure-framework | allure2 | CWE-22 | Allure: Path Traversal in Allure Report HTTP Server Allows Arbitrary File Read |
| CVE-2026-55093 | 6.1 | — | sonos | tract | CWE-125 | tract-nnef: integer overflow in NNEF `.dat` tensor parser yields an out-of-bo… |
| CVE-2026-55832 | 6.1 | — | sonos | tract | CWE-22 | Tract: Arbitrary file read via unsanitized ONNX external_data `location` (pat… |
| CVE-2026-55847 | 6.1 | — | allure-framework | allure2 | CWE-79 | Allure: Stored XSS via unescaped ANSI helper in Allure report status message/… |
| CVE-2026-73191 | 6.1 | — | Apache Software Foundation | Apache Syncope | CWE-601 | Apache Syncope: CAS service URL injection via Forwarded HTTP headers |
| CVE-2026-78318 | 6.1 | — | Apache Software Foundation | Apache Syncope | CWE-79 | Apache Syncope: Unauthenticated reflected XSS in Console and Enduser |
| CVE-2026-7208 | 6.0 | — | Yealink | SIP-T33G | CWE-362 | Yealink SIP-T33G < 124.87.0.0 Race Condition via Diagnostic File Deletion |
| CVE-2026-18069 | 6.0 | — | IBM | i | CWE-367 | IBM i is Affected By A Race Condition Vulnerability in SQL Query Engine [] |
| CVE-2026-15924 | 5.9 | — | zephyrproject | zephyr | CWE-416 | Use-after-free / double-free from unsynchronized concurrent access to the TLS… |
| CVE-2026-16435 | 5.9 | — | IBM | WebSphere Application Server | CWE-650 | IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected … |
| CVE-2026-55235 | 5.9 | — | langchain-ai | langgraph-api | CWE-287 | langgraph-api: Relative webhook targets in LangGraph Server can reach in-proc… |
| CVE-2026-55236 | 5.9 | — | langchain-ai | langgraph-api | CWE-285 | langgraph-api: Incomplete assistant authorization in LangGraph Server run cre… |
| CVE-2026-73449 | 5.9 | — | Arista Networks | EOS | CWE-290 | On affected platforms running Arista EOS with both 802.1X port authentication… |
| CVE-2026-55102 | 5.8 | — | kyndryl-open-source | hashi-vault-js | CWE-209 | hashi-vault-js: Vault token and secret values exposed in thrown errors |
| CVE-2026-54246 | 5.7 | — | zalando | skipper | CWE-306 | Skipper routesrv-no-auth: All routesrv API Endpoints Lack Authentication |
| CVE-2026-19542 | 5.6 | — | The GNU C Library | glibc | CWE-121 | Stack-based out-of-bounds write in tdelete during tree rebalancing |
| CVE-2026-75944 | 5.6 | — | Arista Networks | EOS | CWE-459 | A race condition during supplicant re-authentication may leave a stale ACL en… |
| CVE-2026-76081 | 5.5 | — | zitadel | zitadel | CWE-193 | ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role De… |
| CVE-2026-82920 | 5.5 | — | Mattermost | Mattermost | CWE-863 | Mattermost ABAC parent policy bypass via policy update endpoint |
| CVE-2026-90701 | 5.5 | — | subhajitkhan | online-clinic-management-system | CWE-74 | subhajitkhan online-clinic-management-system listdoctor.php sql injection |
| CVE-2026-90708 | 5.5 | — | Yot | CMS | CWE-74 | Yot CMS Cookie global.php login sql injection |
| CVE-2026-90710 | 5.5 | — | taisan | tarzan-cms | CWE-918 | taisan tarzan-cms Theme Download Function ThemeService.java openConnection se… |
| CVE-2026-90715 | 5.5 | — | marcobambini | Gravity | CWE-189 | marcobambini Gravity udp json-parser gravity_json.c integer overflow |
| CVE-2026-90784 | 5.5 | — | Dvidelabs | flatcc | CWE-401 | Dvidelabs flatcc semantics.c fb_clear_parser memory leak |
| CVE-2026-90785 | 5.5 | — | Dvidelabs | flatcc | CWE-617 | Dvidelabs flatcc Struct Analysis semantics.c analyze_struct assertion |
| CVE-2026-90786 | 5.5 | — | Dvidelabs | flatcc | CWE-617 | Dvidelabs flatcc Duplicate Symbol semantics.c align_order_members assertion |
| CVE-2026-90787 | 5.5 | — | Soarkey | StudentManagement | CWE-266 | Soarkey StudentManagement Registration Workflow register.html RegisterServlet… |
| CVE-2026-90789 | 5.5 | — | itsourcecode | Leave Management System | CWE-74 | itsourcecode Leave Management System login.php sql injection |
| CVE-2026-90805 | 5.5 | — | subhajitkhan | online-clinic-management-system | CWE-74 | subhajitkhan online-clinic-management-system doctorlogin.php sql injection |
| CVE-2026-90995 | 5.5 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-476 | Sssd: sssd: local denial of service due to null pointer dereference in pam re… |
| CVE-2026-7884 | 5.4 | — | IBM | Cognos Analytics | CWE-79 | IBM Cognos Analytics versions 12.0.4 and 12.1.3 is affected by security vulne… |
| CVE-2026-12758 | 5.4 | — | IBM | Cloud Pak for Business Automation | CWE-862 | Multiple security vulnerabilities are addressed with IBM Cloud Pak for Busine… |
| CVE-2026-12766 | 5.4 | — | IBM | Langflow OSS | CWE-918 | Langflow is vulnerable to Server-Side Request Forgery due to missing or bypas… |
| CVE-2026-15887 | 5.4 | — | IBM | WebSphere Application Server | CWE-918 | IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected … |
| CVE-2026-16186 | 5.4 | — | IBM | WebSphere Application Server | CWE-79 | IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected … |
| CVE-2026-17047 | 5.4 | — | IBM | Db2 Mirror for i | CWE-352 | IBM Db2 Mirror for i is vulnerable to Cross-Site Request Forgery [] |
| CVE-2026-17628 | 5.4 | — | IBM | Langflow OSS | CWE-287 | Langflow is affected by improper authentication due to missing password verif… |
| CVE-2026-19273 | 5.4 | — | IBM | Sterling B2B Integrator | CWE-287 | The Dashboard of IBM Sterling B2B Integrator and IBM Sterling File Gateway ar… |
| CVE-2026-54181 | 5.4 | — | Laravel-Backpack | CRUD | CWE-79 | backpack/crud: Stored XSS in the color column — the `@if($column['escaped'])`… |
| CVE-2026-78415 | 5.4 | — | IBM | Sterling Secure Proxy | CWE-79 | IBM Sterling Secure Proxy is vulnerable to multiple issues |
| CVE-2026-91021 | 5.4 | — | Trilium | Trillium Notes | CWE-79 | CVE-2026-91021 |
| CVE-2026-10556 | 5.3 | — | Mattermost | Mattermost | CWE-754 | Unauthenticated webhook request with null notification entry could crash the … |
| CVE-2026-16188 | 5.3 | — | IBM | WebSphere Application Server | CWE-117 | IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected … |
| CVE-2026-18065 | 5.3 | — | IBM | i | CWE-290 | IBM i is Affected By Multiple Vulnerabilities in Navigator for i and Digital … |
| CVE-2026-47256 | 5.3 | — | open-telemetry | opentelemetry-collector-contrib | CWE-22 | OpenTelemetry: Path traversal in Sentry exporter via attacker-controlled serv… |
| CVE-2026-53496 | 5.3 | — | mattiasw | ExifReader | CWE-248 | ExifReader HEIC/AVIF ISO-BMFF parser throws uncaught RangeError on truncated … |
| CVE-2026-53715 | 5.3 | — | envoyproxy | gateway | CWE-362 | Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock |
| CVE-2026-54529 | 5.3 | — | smithyhq | sqladmin | CWE-20 | SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortab… |
| CVE-2026-57497 | 5.3 | — | quic-go | webtransport-go | CWE-770 | webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules |
| CVE-2026-57581 | 5.3 | — | riganti | dotvvm | CWE-434 | DotVVM: Unrestricted file upload |
| CVE-2026-89020 | 5.3 | — | MikroTik | RouterOS | CWE-121 | MikroTik RouterOS Stack Buffer Overflow via TFTP URL Path |
| CVE-2026-90790 | 5.3 | — | a2aproject | a2a-python | CWE-918 | a2aproject a2a-python Push Notification Sender base_push_notification_sender.… |
| CVE-2026-90806 | 5.3 | — | DjangoCRM | django-crm | CWE-862 | DjangoCRM django-crm Bulk Case Update bulk_views.py BulkUpdateCasesView autho… |
| CVE-2026-90808 | 5.3 | — | HKUDS | nanobot | CWE-183 | HKUDS nanobot ExecTool shell.py ExecTool._spawn incomplete blacklist |
| CVE-2026-90816 | 5.3 | — | n/a | FFmpeg | CWE-404 | FFmpeg Duration hlsproto.c parse_playlist denial of service |
| CVE-2026-90820 | 5.3 | — | a2aproject | a2a-java | CWE-862 | a2aproject a2a-java AuthorizationRequestHandlerDecorator.java AuthorizationRe… |
| CVE-2026-90935 | 5.3 | — | froxlor | froxlor | CWE-285 | Froxlor before 2.3.7 Authorization Bypass via Mysqls.add API |
| CVE-2026-90936 | 5.3 | — | froxlor | froxlor | CWE-200 | Froxlor before 2.3.7 Information Disclosure via customer_email.php |
| CVE-2026-90941 | 5.3 | — | 201206030 | novel-plus | CWE-862 | novel-plus through 5.3.3 Missing Authorization on the Admin Book Download End… |
| CVE-2026-91146 | 5.3 | — | jointakahe | takahe | CWE-79 | Takahe through 0.11.0 Cross-Site Scripting via javascript: URL Scheme |
| CVE-2026-91199 | 5.3 | — | refly-ai | refly | CWE-918 | Refly through 1.1.0 Server-Side Request Forgery via scrape endpoint |
| CVE-2026-91201 | 5.3 | — | arc53 | DocsGPT | CWE-346 | DocsGPT through 0.20.0 OAuth Token Disclosure via Wildcard postMessage |
| CVE-2026-19280 | 5.2 | — | IBM | i | CWE-787 | IBM i is Affected By Multiple Vulnerabilities in PASE [, ] |
| CVE-2026-86876 | 5.2 | — | Apple | iOS and iPadOS | CWE-787 | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-81566 | 5.1 | — | joomshaper.com | SP Page Builder (Free and Pro) extension for Joomla | CWE-284 | Joomla Extension - joomshaper.com - Missing Access Control in Menu Item Creat… |
| CVE-2026-90893 | 5.1 | — | MISP | MISP | CWE-352 | MISP UserSettingsController CSRF Protection Bypass on setTheme, setHomePage, … |
| CVE-2026-90931 | 5.1 | — | laradashboard | laradashboard | CWE-79 | LaraDashboard 0.9.0 through 1.2.2 Stored XSS via SVG Upload |
| CVE-2026-90957 | 5.1 | — | MISP | MISP | CWE-79 | MISP: Stored XSS via Inline-Served SVG Organisation Logos and Report Pictures |
| CVE-2026-10542 | 5.0 | — | Mattermost | Mattermost | CWE-639 | Playbooks channel action update validation issue |
| CVE-2026-55244 | 5.0 | — | lmfit | asteval | CWE-248 | ASTEVAL: Sandbox Escape via BaseException Subclasses |
| CVE-2026-75015 | 4.9 | — | Apache Software Foundation | Apache Syncope | CWE-522 | Apache Syncope: Nested secrets leak cleartext into audit records readable |
| CVE-2026-77883 | 4.9 | — | Apache Software Foundation | Apache Syncope | CWE-202 | Apache Syncope: Information disclosure via one-hop JEXL navigation past the J… |
| CVE-2026-16189 | 4.8 | — | IBM | WebSphere Application Server | CWE-117 | IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected … |
| CVE-2026-15923 | 4.6 | — | zephyrproject | zephyr | CWE-835 | Infinite loop denial of service in Zephyr SDIO byte-I/O from a card-supplied … |
| CVE-2026-16148 | 4.6 | — | zephyrproject | zephyr | CWE-666 | Kernel panic in the it82xx2 USB device controller driver via re-initializatio… |
| CVE-2026-90955 | 4.6 | — | MISP | MISP | CWE-223 | MISP CLI Shell Audit Logs Lose User Identity and CLI Marker After First Lazy … |
| CVE-2026-11993 | 4.3 | — | Mattermost | Mattermost | CWE-770 | Fix authenticated members disabling file content indexing server-wide via ext… |
| CVE-2026-12882 | 4.3 | — | Mattermost | Mattermost | CWE-407 | Mattermost Markdown autolink parsing denial of service |
| CVE-2026-13417 | 4.3 | — | Mattermost | Mattermost | CWE-754 | Boards plugin denial of service via unvalidated block fields.properties |
| CVE-2026-14259 | 4.3 | — | Mattermost | Mattermost | CWE-862 | Board archive import bypasses team board creation permissions |
| CVE-2026-14344 | 4.3 | — | Mattermost | Mattermost | CWE-862 | Inconsistent authorization checks in Mattermost Boards endpoints |
| CVE-2026-18251 | 4.3 | — | IBM | i | CWE-1385 | IBM i is Affected By Multiple Vulnerabilities in Navigator for i and Digital … |
| CVE-2026-18515 | 4.3 | — | IBM | i | CWE-22 | IBM i is Affected By Multiple Vulnerabilities in Navigator for i and Digital … |
| CVE-2026-54247 | 4.3 | — | zalando | skipper | CWE-770 | Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhau… |
| CVE-2026-57128 | 4.3 | — | MervinPraison | PraisonAI | CWE-306 | PraisonAI: Unauthenticated Event Injection via SSE `/publish` Endpoint |
| CVE-2026-65352 | 4.3 | — | Apple | iOS and iPadOS | CWE-642 | An information disclosure issue was addressed with improved state management.… |
| CVE-2026-65355 | 4.3 | — | Apple | iOS and iPadOS | CWE-642 | An information disclosure issue was addressed with improved state management.… |
| CVE-2026-75792 | 4.3 | — | IBM | Sterling Secure Proxy | CWE-285 | IBM Sterling Secure Proxy is vulnerable to multiple issues |
| CVE-2026-82437 | 4.3 | — | Apache Software Foundation | Apache Storm Logviewer | CWE-862 | Apache Storm Logviewer: Log Access Controls Not Enforced by Logviewer |
| CVE-2026-84518 | 4.3 | — | Apple | Safari | CWE-642 | This issue was addressed through improved state management. This issue is fix… |
| CVE-2026-86348 | 4.3 | — | Mattermost | Mattermost | CWE-704 | MS Calendar plugin: unrecovered handler panics from malformed post-action req… |
| CVE-2026-86349 | 4.3 | — | Mattermost | Mattermost | CWE-407 | Mattermost Server Algorithmic DoS via Unbounded Markdown Block Nesting |
| CVE-2026-12763 | 4.2 | — | IBM | Langflow OSS | CWE-306 | Langflow is vulnerable to authentication bypass and insufficient session expi… |
| CVE-2026-18151 | 4.2 | — | IBM | i | CWE-362 | IBM i is Affected By Multiple Vulnerabilities in Navigator for i and Digital … |
| CVE-2026-90463 | 4.0 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Sssd: local oob read in nss service request parsers (`sss_nss_protocol_parse_… |
| CVE-2026-90994 | 4.0 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Sssd: sssd: denial of service via malformed pam v1 requests |
| CVE-2026-90996 | 4.0 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-191 | Sssd: sssd: denial of service in nss responder via crafted zero-length requests |
| CVE-2026-54541 | 3.7 | — | nimiq | core-rs-albatross | CWE-248 | Nimiq: Panic in TrieProof::verify via child_index unwrap on equal-length keys |
| CVE-2026-54542 | 3.7 | — | nimiq | core-rs-albatross | CWE-125 | Nimiq: Out-of-bounds panic in KeyNibbles::Add from oversized child suffix in … |
| CVE-2026-55866 | 3.7 | — | authzed | spicedb | CWE-863 | SpiceDBChecks involving relations with caveats can result in unconditional pe… |
| CVE-2026-19086 | 3.3 | — | IBM | i | CWE-125 | IBM i is Affected By Multiple Vulnerabilities in PASE [, ] |
| CVE-2026-46696 | 3.3 | — | octobercms | system | CWE-269 | October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder… |
| CVE-2026-49400 | 3.3 | — | octobercms | october | CWE-502 | October CMS: PHP Object Injection via Backend Widget Session Storage |
| CVE-2026-57583 | 3.3 | — | OpenZeppelin | contracts-wizard | CWE-94 | OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / inf… |
| CVE-2026-16190 | 3.1 | — | IBM | WebSphere Application Server | CWE-862 | IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected … |
| CVE-2026-44162 | 2.7 | — | fluent | fluent-plugin-s3 | CWE-409 | fluent-plugin-s3: Denial of Service (DoS) via Decompression Bomb in `in_s3` |
| CVE-2026-82019 | 2.3 | — | TripleLift | video-bundle.js | CWE-79 | TripleLift video-bundle.js DOM-based XSS via postMessage |
| CVE-2026-82519 | 2.3 | — | reallysimpleplugins | Really Simple Security | CWE-862 | Really Simple Security < 9.8.2 Authorization Bypass via profile-page update h… |
| CVE-2026-75943 | 2.1 | — | Arista Networks | EOS | CWE-459 | A brief (milliseconds to seconds) traffic leak may occur when an authenticate… |
| CVE-2026-75945 | 2.1 | — | Arista Networks | EOS | CWE-459 | A race condition may cause a supplicant to remain in an authorized state afte… |
| CVE-2026-77191 | 2.1 | — | Arista Networks | EOS | CWE-862 | All of the CVEs covered in this advisory apply to affected platforms running … |
| CVE-2026-90712 | 2.1 | — | Gitlawb | openclaude | CWE-404 | Gitlawb openclaude xAI OAuth Callback xaiOAuthCallback.ts waitForCallback den… |
| CVE-2026-90714 | 2.1 | — | marcobambini | Gravity | CWE-119 | marcobambini Gravity JSON parser gravity_json.c memory corruption |
| CVE-2026-90791 | 2.1 | — | n/a | GPAC | CWE-119 | GPAC MP4Box base_scenegraph.c gf_node_unregister use after free |
| CVE-2026-90792 | 2.1 | — | n/a | GPAC | CWE-404 | GPAC MP4Box base_scenegraph.c gf_node_list_get_child null pointer dereference |
| CVE-2026-90793 | 2.1 | — | n/a | GPAC | CWE-119 | GPAC MP4Box base_scenegraph.c gf_node_get_name use after free |
| CVE-2026-90794 | 2.1 | — | n/a | GPAC | CWE-119 | GPAC MP4Box vrml_tools.c gf_sg_script_load use after free |
| CVE-2026-90795 | 2.1 | — | itsourcecode | Loan Management System | CWE-79 | itsourcecode Loan Management System navbar.php cross site scripting |
| CVE-2026-90796 | 2.1 | — | itsourcecode | Leave Management System | CWE-74 | itsourcecode Leave Management System index.php sql injection |
| CVE-2026-90807 | 2.1 | — | nanocoai | NanoClaw | CWE-59 | nanocoai NanoClaw Attachment agent-route.ts forwardAttachedFiles link following |
| CVE-2026-90810 | 2.1 | — | cosmicstack-labs | mercury-agent | CWE-266 | cosmicstack-labs mercury-agent Shell Command Permission Check permissions.ts … |
| CVE-2026-90812 | 2.1 | — | cosmicstack-labs | mercury-agent | CWE-266 | cosmicstack-labs mercury-agent Shell Command Permission permissions.ts checkS… |
| CVE-2026-90813 | 2.1 | — | cosmicstack-labs | mercury-agent | CWE-179 | cosmicstack-labs mercury-agent Shell Command Execution permissions.ts checkSh… |
| CVE-2026-90814 | 2.1 | — | cosmicstack-labs | mercury-agent | CWE-918 | cosmicstack-labs mercury-agent GitHub API github.ts githubRequest server-side… |
| CVE-2026-90815 | 2.1 | — | n/a | FFmpeg | CWE-119 | FFmpeg Convolution Filter vf_convolution.c setup_3x3 out-of-bounds |
| CVE-2026-90818 | 2.1 | — | netease-youdao | LobsterAI | CWE-918 | netease-youdao LobsterAI Browser Network Configuration openclawConfigSync.ts … |
| CVE-2026-90704 | 2.0 | — | D-Link | DWR-M921 | CWE-74 | D-Link DWR-M921 formDiskPartition system command injection |
| CVE-2026-90705 | 2.0 | — | D-Link | DWR-M921 | CWE-77 | D-Link DWR-M921 Boa Dispatch Table formsysCmd os command injection |
| CVE-2026-90706 | 2.0 | — | D-Link | DWR-M921 | CWE-77 | D-Link DWR-M921 formWsc os command injection |
| CVE-2026-90709 | 2.0 | — | Yot | CMS | CWE-74 | Yot CMS Admin Console admin.php eval code injection |
| CVE-2026-90716 | 2.0 | — | marcobambini | Gravity | CWE-119 | marcobambini Gravity Number gravity_parser.c parse_number_expression out-of-b… |
| CVE-2026-90788 | 2.0 | — | magicblack | MacCMS10 | CWE-77 | magicblack MacCMS10 Template .%40template%40default%40html%40label.html os co… |
| CVE-2026-90835 | 2.0 | — | michaelliao | itranswarp | CWE-79 | michaelliao itranswarp Page Content Rendering Markdown.java Markdown.toHtml c… |
| CVE-2026-90713 | 1.9 | — | vllm-project | vLLM | CWE-404 | vllm-project vLLM tiktoken vocab File mod.rs new denial of service |
| CVE-2026-90801 | 1.9 | — | GNU | Binutils | CWE-119 | GNU Binutils ld cache.c cache_bwrite buffer overflow |
| CVE-2026-90802 | 1.9 | — | GNU | Binutils | CWE-404 | GNU Binutils ld libbfd.c bfd_putl64 null pointer dereference |
| CVE-2026-90803 | 1.9 | — | GNU | Binutils | CWE-119 | GNU Binutils ld elf64-x86-64.c elf_x86_64_relocate_section buffer overflow |
| CVE-2026-90811 | 1.9 | — | cosmicstack-labs | mercury-agent | CWE-200 | cosmicstack-labs mercury-agent Shell Permission Manifest permissions.ts Permi… |
| CVE-2026-90824 | 1.9 | — | n/a | GPAC | CWE-119 | GPAC MP4Box dom_events.c gf_sg_dom_event_bubble stack-based overflow |
| CVE-2026-90825 | 1.9 | — | n/a | GPAC | CWE-119 | GPAC MP4Box base_scenegraph.c gf_node_unregister use after free |
| CVE-2026-90827 | 1.9 | — | n/a | GPAC | CWE-119 | GPAC MP4Box base_scenegraph.c gf_node_deactivate_ex use after free |
| CVE-2026-90828 | 1.9 | — | GNU | Binutils | CWE-404 | GNU Binutils ELF Orphan Section ldelf.c elf_orphan_compatible null pointer de… |
| CVE-2026-90829 | 1.9 | — | GNU | Binutils | CWE-404 | GNU Binutils SHT_GROUP Section elf.c bfd_elf_set_group_contents null pointer … |
| CVE-2026-90830 | 1.9 | — | GNU | Binutils | CWE-404 | GNU Binutils Section Merge merge.c _bfd_write_merged_section null pointer der… |
| CVE-2026-90831 | 1.9 | — | GNU | Binutils | CWE-119 | GNU Binutils ELF String Table elf-strtab.c _bfd_elf_strtab_delref memory corr… |
| CVE-2026-90804 | 0.9 | — | GNU | Binutils | CWE-119 | GNU Binutils Eh Frame Section elf-eh-frame.c _bfd_elf_write_section_eh_frame … |
| CVE-2026-90826 | 0.9 | — | n/a | GPAC | CWE-119 | GPAC MP4Box base_scenegraph.c gf_node_del out-of-bounds |
| CVE-2026-13260 | await | — | IBM | Verify Identity Access | CWE-770 | Security vulnerabilities have been addressed in IBM Verify Identity Access an… |
| CVE-2026-13272 | await | — | IBM | Verify Identity Access | CWE-1385 | Security vulnerabilities have been addressed in IBM Verify Identity Access an… |
| CVE-2026-13276 | await | — | IBM | Verify Identity Access | CWE-79 | Security vulnerabilities have been addressed in IBM Verify Identity Access an… |
| CVE-2026-13277 | await | — | IBM | Verify Identity Access | CWE-601 | Security vulnerabilities have been addressed in IBM Verify Identity Access an… |
| CVE-2026-20683 | await | — | Apple | iOS and iPadOS | — | An authentication issue was addressed with improved state management. This is… |
| CVE-2026-28836 | await | — | Apple | macOS | — | A correctness issue was addressed with improved checks. This issue is fixed i… |
| CVE-2026-28899 | await | — | Apple | macOS | — | A logic issue was addressed with improved checks. This issue is fixed in macO… |
| CVE-2026-28933 | await | — | Apple | macOS | — | A use-after-free issue was addressed with improved memory management. This is… |
| CVE-2026-28934 | await | — | Apple | macOS | — | A buffer overflow was addressed with improved bounds checking. This issue is … |
| CVE-2026-28935 | await | — | Apple | iOS and iPadOS | — | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-28937 | await | — | Apple | macOS | — | This issue was addressed through improved state management. This issue is fix… |
| CVE-2026-28938 | await | — | Apple | iOS and iPadOS | — | A privacy issue was addressed by moving sensitive data. This issue is fixed i… |
| CVE-2026-28966 | await | — | Apple | iOS and iPadOS | — | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-28968 | await | — | Apple | iOS and iPadOS | — | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-43664 | await | — | Apple | iOS and iPadOS | — | This issue was addressed with improved data protection. This issue is fixed i… |
| CVE-2026-43674 | await | — | Apple | iOS and iPadOS | — | An authentication issue was addressed with improved state management. This is… |
| CVE-2026-43677 | await | — | Apple | macOS | — | An out-of-bounds write issue was addressed by removing the vulnerable code. T… |
| CVE-2026-43683 | await | — | Apple | macOS | — | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-43684 | await | — | Apple | iOS and iPadOS | — | A use-after-free issue was addressed with improved memory management. This is… |
| CVE-2026-43686 | await | — | Apple | iOS and iPadOS | — | A use-after-free issue was addressed with improved memory management. This is… |
| CVE-2026-43687 | await | — | Apple | iOS and iPadOS | — | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-43688 | await | — | Apple | iOS and iPadOS | — | A memory corruption issue was addressed with improved input validation. This … |
| CVE-2026-43690 | await | — | Apple | macOS | — | A race condition was addressed with improved locking. This issue is fixed in … |
| CVE-2026-43695 | await | — | Apple | iOS and iPadOS | — | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-43696 | await | — | Apple | macOS | — | An authorization issue was addressed with improved entitlement checks. This i… |
| CVE-2026-43697 | await | — | Apple | macOS | — | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-43702 | await | — | Apple | iOS and iPadOS | — | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-43719 | await | — | Apple | macOS | — | A use-after-free issue was addressed with improved memory management. This is… |
| CVE-2026-43737 | await | — | Apple | iOS and iPadOS | — | An authorization issue was addressed with improved validation. This issue is … |
| CVE-2026-43741 | await | — | Apple | macOS | — | A logic issue was addressed with improved state management. This issue is fix… |
| CVE-2026-43761 | await | — | Apple | macOS | — | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-43762 | await | — | Apple | iOS and iPadOS | — | The issue was addressed with improved checks. This issue is fixed in iOS 26.6… |
| CVE-2026-43785 | await | — | Apple | iOS and iPadOS | — | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2026-43787 | await | — | Apple | macOS | — | A logic issue was addressed with improved checks. This issue is fixed in macO… |
| CVE-2026-43788 | await | — | Apple | macOS | — | An integer overflow was addressed with improved input validation. This issue … |
| CVE-2026-43789 | await | — | Apple | macOS | — | An access issue was addressed with additional sandbox restrictions. This issu… |
| CVE-2026-43790 | await | — | Apple | macOS | — | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-43791 | await | — | Apple | macOS | — | A validation issue was addressed with improved input sanitization. This issue… |
| CVE-2026-43808 | await | — | Apple | iOS and iPadOS | — | A use-after-free issue was addressed with improved memory management. This is… |
| CVE-2026-43815 | await | — | Apple | macOS | — | A buffer overflow was addressed with improved bounds checking. This issue is … |
| CVE-2026-64714 | await | — | Apple | iOS and iPadOS | — | A memory corruption issue was addressed with improved bounds checking. This i… |
| CVE-2026-64717 | await | — | Apple | iOS and iPadOS | — | A race condition was addressed with improved state handling. This issue is fi… |
| CVE-2026-64736 | await | — | Apple | iOS and iPadOS | — | An out-of-bounds access issue was addressed with improved bounds checking. Th… |
| CVE-2026-64752 | await | — | Apple | iOS and iPadOS | — | A memory corruption issue was addressed by removing the vulnerable code. This… |
| CVE-2026-64753 | await | — | Apple | Safari | — | A permissions issue was addressed by removing the vulnerable code. This issue… |
| CVE-2026-64756 | await | — | Apple | iOS and iPadOS | — | A path handling issue was addressed with improved validation. This issue is f… |
| CVE-2026-64761 | await | — | Apple | iOS and iPadOS | — | A privacy issue was addressed with improved handling of user preferences. Thi… |
| CVE-2026-64790 | await | — | Apple | macOS | — | A path handling issue was addressed with improved validation. This issue is f… |
| CVE-2026-65342 | await | — | Apple | macOS | — | A permissions issue was addressed with improved validation. This issue is fix… |
| CVE-2026-65344 | await | — | Apple | iOS and iPadOS | — | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-65345 | await | — | Apple | iOS and iPadOS | — | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2026-65348 | await | — | Apple | iOS and iPadOS | — | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2026-65353 | await | — | Apple | iOS and iPadOS | — | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-65354 | await | — | Apple | iOS and iPadOS | — | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2026-65357 | await | — | Apple | iOS and iPadOS | — | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-65358 | await | — | Apple | iOS and iPadOS | — | A race condition was addressed with improved state handling. This issue is fi… |
| CVE-2026-65359 | await | — | Apple | iOS and iPadOS | — | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-65360 | await | — | Apple | iOS and iPadOS | — | A race condition was addressed with improved state handling. This issue is fi… |
| CVE-2026-65361 | await | — | Apple | macOS | — | This issue was addressed with improved checks. This issue is fixed in macOS G… |
| CVE-2026-65365 | await | — | Apple | macOS | — | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-65369 | await | — | Apple | macOS | — | A logic issue was addressed with improved state management. This issue is fix… |
| CVE-2026-65371 | await | — | Apple | iOS and iPadOS | — | This issue was addressed with improved redaction of sensitive information. Th… |
| CVE-2026-65374 | await | — | Apple | macOS | — | A memory corruption issue was addressed with improved validation. This issue … |
| CVE-2026-65375 | await | — | Apple | macOS | — | The issue was addressed with improved authentication. This issue is fixed in … |
| CVE-2026-65376 | await | — | Apple | macOS | — | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-65377 | await | — | Apple | iOS and iPadOS | — | A memory corruption issue was addressed with improved memory handling. This i… |
| CVE-2026-65378 | await | — | Apple | macOS | — | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-65380 | await | — | Apple | macOS | — | An issue existed in the handling of snapshots. The issue was resolved with im… |
| CVE-2026-65381 | await | — | Apple | macOS | — | A validation issue existed in the entitlement verification. This issue was ad… |
| CVE-2026-65382 | await | — | Apple | macOS | — | A parsing issue in the handling of directory paths was addressed with improve… |
| CVE-2026-65383 | await | — | Apple | macOS | — | This issue was addressed with improved checks. This issue is fixed in macOS G… |
| CVE-2026-65390 | await | — | Apple | Safari | — | An integer overflow was addressed with improved input validation. This issue … |
| CVE-2026-65391 | await | — | Apple | Safari | — | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-65393 | await | — | Apple | Xcode | — | A permissions issue was addressed with improved validation. This issue is fix… |
| CVE-2026-65395 | await | — | Apple | iOS and iPadOS | — | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-65398 | await | — | Apple | iOS and iPadOS | — | An out-of-bounds access issue was addressed with improved bounds checking. Th… |
| CVE-2026-65399 | await | — | Apple | iOS and iPadOS | — | A file quarantine bypass was addressed with additional checks. This issue is … |
| CVE-2026-65401 | await | — | Apple | macOS | — | A race condition was addressed with improved state handling. This issue is fi… |
| CVE-2026-65402 | await | — | Apple | iOS and iPadOS | — | A use after free issue was addressed with improved memory management. This is… |
| CVE-2026-65403 | await | — | Apple | iOS and iPadOS | — | This issue was addressed with improved checks. This issue is fixed in iOS 26.… |
| CVE-2026-65404 | await | — | Apple | iOS and iPadOS | — | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-65405 | await | — | Apple | iOS and iPadOS | — | A memory initialization issue was addressed with improved memory handling. Th… |
| CVE-2026-65406 | await | — | Apple | iOS and iPadOS | — | A logic issue was addressed with improved validation. This issue is fixed in … |
| CVE-2026-65407 | await | — | Apple | iOS and iPadOS | — | A use after free issue was addressed with improved memory management. This is… |
| CVE-2026-65408 | await | — | Apple | iOS and iPadOS | — | An integer overflow was addressed with improved input validation. This issue … |
| CVE-2026-65409 | await | — | Apple | iOS and iPadOS | — | A type confusion issue was addressed with improved memory handling. This issu… |
| CVE-2026-65410 | await | — | Apple | iOS and iPadOS | — | The issue was addressed with improved checks. This issue is fixed in iOS 26.7… |
| CVE-2026-65411 | await | — | Apple | iOS and iPadOS | — | A path handling issue was addressed with improved validation. This issue is f… |
| CVE-2026-65412 | await | — | Apple | iOS and iPadOS | — | A null pointer dereference was addressed with improved input validation. This… |
| CVE-2026-65413 | await | — | Apple | macOS | — | An integer overflow was addressed with improved input validation. This issue … |
| CVE-2026-65415 | await | — | Apple | iOS and iPadOS | — | A race condition was addressed with additional validation. This issue is fixe… |
| CVE-2026-84487 | await | — | Apple | iOS and iPadOS | — | An integer overflow was addressed with improved input validation. This issue … |
| CVE-2026-84489 | await | — | Apple | iOS and iPadOS | — | A buffer overflow was addressed with improved bounds checking. This issue is … |
| CVE-2026-84491 | await | — | Apple | iOS and iPadOS | — | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2026-84492 | await | — | Apple | iOS and iPadOS | — | A race condition was addressed with improved state handling. This issue is fi… |
| CVE-2026-84497 | await | — | Apple | iOS and iPadOS | — | A buffer overflow was addressed with improved size validation. This issue is … |
| CVE-2026-84506 | await | — | Apple | macOS | — | A use after free issue was addressed with improved memory management. This is… |
| CVE-2026-84507 | await | — | Apple | iOS and iPadOS | — | A race condition was addressed with improved state handling. This issue is fi… |
| CVE-2026-84509 | await | — | Apple | macOS | — | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-84510 | await | — | Apple | iOS and iPadOS | — | A heap buffer overflow was addressed with improved bounds checking. This issu… |
| CVE-2026-84511 | await | — | Apple | iOS and iPadOS | — | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-84512 | await | — | Apple | macOS | — | A buffer overflow was addressed with improved bounds checking. This issue is … |
| CVE-2026-84513 | await | — | Apple | iOS and iPadOS | — | A privacy issue was addressed with improved private data redaction for log en… |
| CVE-2026-84514 | await | — | Apple | macOS | — | This issue was addressed with additional entitlement checks. This issue is fi… |
| CVE-2026-84515 | await | — | Apple | macOS | — | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-84516 | await | — | Apple | macOS | — | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-84517 | await | — | Apple | macOS | — | An integer overflow was addressed with improved input validation. This issue … |
| CVE-2026-84519 | await | — | Apple | iOS and iPadOS | — | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-84520 | await | — | Apple | macOS | — | A buffer overflow was addressed with improved size validation. This issue is … |
| CVE-2026-84521 | await | — | Apple | iOS and iPadOS | — | A use after free issue was addressed with improved memory management. This is… |
| CVE-2026-84522 | await | — | Apple | macOS | — | A race condition was addressed with improved state management. This issue is … |
| CVE-2026-84523 | await | — | Apple | iOS and iPadOS | — | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-84524 | await | — | Apple | iOS and iPadOS | — | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-84525 | await | — | Apple | macOS | — | A logging issue was addressed with improved data redaction. This issue is fix… |
| CVE-2026-84526 | await | — | Apple | iOS and iPadOS | — | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-84527 | await | — | Apple | iOS and iPadOS | — | A logging issue was addressed with improved data redaction. This issue is fix… |
| CVE-2026-84530 | await | — | Apple | iOS and iPadOS | — | An information disclosure issue was addressed with improved memory management… |
| CVE-2026-84531 | await | — | Apple | iOS and iPadOS | — | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-84532 | await | — | Apple | iOS and iPadOS | — | An out-of-bounds read issue was addressed with improved input validation. Thi… |
| CVE-2026-84533 | await | — | Apple | iOS and iPadOS | — | A cryptographic issue was addressed with improved integrity checks. This issu… |
| CVE-2026-84534 | await | — | Apple | iOS and iPadOS | — | A path handling issue was addressed with improved validation. This issue is f… |
| CVE-2026-84535 | await | — | Apple | macOS | — | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-84536 | await | — | Apple | macOS | — | An integer underflow was addressed with improved input validation. This issue… |
| CVE-2026-84537 | await | — | Apple | macOS | — | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-84540 | await | — | Apple | macOS | — | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-84541 | await | — | Apple | macOS | — | An input validation issue was addressed with improved input validation. This … |
| CVE-2026-84543 | await | — | Apple | macOS | — | An out-of-bounds access issue was addressed with improved bounds checking. Th… |
| CVE-2026-84544 | await | — | Apple | macOS | — | An integer overflow was addressed with improved input validation. This issue … |
| CVE-2026-84546 | await | — | Apple | iOS and iPadOS | — | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-84548 | await | — | Apple | macOS | — | An integer overflow was addressed with improved input validation. This issue … |
| CVE-2026-84549 | await | — | Apple | macOS | — | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-84550 | await | — | Apple | macOS | — | A race condition was addressed with additional validation. This issue is fixe… |
| CVE-2026-84551 | await | — | Apple | iOS and iPadOS | — | A logic issue was addressed with improved validation. This issue is fixed in … |
| CVE-2026-84552 | await | — | Apple | iOS and iPadOS | — | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-84554 | await | — | Apple | macOS | — | An integer overflow was addressed with improved input validation. This issue … |
| CVE-2026-84555 | await | — | Apple | macOS | — | An authorization issue was addressed with improved access control. This issue… |
| CVE-2026-84556 | await | — | Apple | macOS | — | An authorization issue was addressed with improved access control. This issue… |
| CVE-2026-84558 | await | — | Apple | macOS | — | A double free issue was addressed with improved memory management. This issue… |
| CVE-2026-84559 | await | — | Apple | macOS | — | A permissions issue was addressed with improved validation. This issue is fix… |
| CVE-2026-84560 | await | — | Apple | iOS and iPadOS | — | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-84561 | await | — | Apple | iOS and iPadOS | — | A double free issue was addressed with improved memory management. This issue… |
| CVE-2026-84562 | await | — | Apple | macOS | — | A race condition was addressed with additional validation. This issue is fixe… |
| CVE-2026-84563 | await | — | Apple | macOS | — | A logic issue was addressed with improved checks. This issue is fixed in macO… |
| CVE-2026-84564 | await | — | Apple | iOS and iPadOS | — | An uninitialized memory issue was addressed with improved memory initializati… |
| CVE-2026-84565 | await | — | Apple | macOS | — | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-84566 | await | — | Apple | iOS and iPadOS | — | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-84567 | await | — | Apple | macOS | — | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-84569 | await | — | Apple | macOS | — | An access issue was addressed with additional sandbox restrictions on the sys… |
| CVE-2026-84570 | await | — | Apple | macOS | — | A logic issue was addressed with improved checks. This issue is fixed in macO… |
| CVE-2026-84571 | await | — | Apple | iOS and iPadOS | — | A buffer overflow was addressed with improved bounds checking. This issue is … |
| CVE-2026-84572 | await | — | Apple | macOS | — | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-84573 | await | — | Apple | macOS | — | This issue was addressed with improved checks. This issue is fixed in macOS G… |
| CVE-2026-84574 | await | — | Apple | macOS | — | A permissions issue was addressed with improved state management. This issue … |
| CVE-2026-84575 | await | — | Apple | iOS and iPadOS | — | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-84576 | await | — | Apple | macOS | — | This issue was addressed with improved checks. This issue is fixed in macOS G… |
| CVE-2026-84577 | await | — | Apple | macOS | — | An access issue was addressed with additional sandbox restrictions. This issu… |
| CVE-2026-84578 | await | — | Apple | macOS | — | A logic issue was addressed with improved checks. This issue is fixed in macO… |
| CVE-2026-84580 | await | — | Apple | macOS | — | The issue was addressed with improved checks. This issue is fixed in macOS Go… |
| CVE-2026-84581 | await | — | Apple | macOS | — | A buffer overflow was addressed with improved bounds checking. This issue is … |
| CVE-2026-84583 | await | — | Apple | iOS and iPadOS | — | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2026-84584 | await | — | Apple | macOS | — | This issue was addressed with improved handling of symlinks. This issue is fi… |
| CVE-2026-84585 | await | — | Apple | macOS | — | A permissions issue was addressed with improved state management. This issue … |
| CVE-2026-84586 | await | — | Apple | macOS | — | An information disclosure issue was addressed with improved state management.… |
| CVE-2026-84587 | await | — | Apple | macOS | — | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2026-84588 | await | — | Apple | macOS | — | A memory corruption issue was addressed by removing the vulnerable code. This… |
| CVE-2026-84589 | await | — | Apple | macOS | — | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2026-84593 | await | — | Apple | iOS and iPadOS | — | A use after free issue was addressed with improved memory management. This is… |
| CVE-2026-84596 | await | — | Apple | iOS and iPadOS | — | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-84597 | await | — | Apple | iOS and iPadOS | — | An out-of-bounds read issue was addressed with improved input validation. Thi… |
| CVE-2026-84598 | await | — | Apple | iOS and iPadOS | — | A path traversal issue was addressed with improved path validation. This issu… |
| CVE-2026-84600 | await | — | Apple | iOS and iPadOS | — | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-84601 | await | — | Apple | macOS | — | A permissions issue was addressed with improved state management. This issue … |
| CVE-2026-84602 | await | — | Apple | iOS and iPadOS | — | A type confusion issue was addressed with improved checks. This issue is fixe… |
| CVE-2026-84603 | await | — | Apple | iOS and iPadOS | — | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2026-84606 | await | — | Apple | iOS and iPadOS | — | A privacy issue was addressed with improved handling of identifiers. This iss… |
| CVE-2026-84607 | await | — | Apple | iOS and iPadOS | — | A race condition was addressed with improved state management. This issue is … |
| CVE-2026-84609 | await | — | Apple | iOS and iPadOS | — | A permissions issue was addressed with improved path validation. This issue i… |
| CVE-2026-84611 | await | — | Apple | iOS and iPadOS | — | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-84612 | await | — | Apple | iOS and iPadOS | — | An authorization issue was addressed with improved access control. This issue… |
| CVE-2026-84615 | await | — | Apple | iOS and iPadOS | — | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-84616 | await | — | Apple | iOS and iPadOS | — | A type confusion issue was addressed with improved memory handling. This issu… |
| CVE-2026-84617 | await | — | Apple | iOS and iPadOS | — | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-84618 | await | — | Apple | macOS | — | A permissions issue was addressed with improved validation. This issue is fix… |
| CVE-2026-84619 | await | — | Apple | macOS | — | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-84620 | await | — | Apple | iOS and iPadOS | — | An integer overflow was addressed with improved input validation. This issue … |
| CVE-2026-84621 | await | — | Apple | iOS and iPadOS | — | An authorization issue was addressed with improved access control. This issue… |
| CVE-2026-84622 | await | — | Apple | iOS and iPadOS | — | A memory initialization issue was addressed with improved memory handling. Th… |
| CVE-2026-84623 | await | — | Apple | iOS and iPadOS | — | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-84624 | await | — | Apple | iOS and iPadOS | — | A permissions issue was addressed with improved path validation. This issue i… |
| CVE-2026-84625 | await | — | Apple | iOS and iPadOS | — | A permissions issue was addressed with additional sandbox restrictions. This … |
| CVE-2026-84626 | await | — | Apple | iOS and iPadOS | — | An information disclosure issue was addressed with improved state management.… |
| CVE-2026-84628 | await | — | Apple | iOS and iPadOS | — | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-84629 | await | — | Apple | iOS and iPadOS | — | This issue was addressed with additional entitlement checks. This issue is fi… |
| CVE-2026-84630 | await | — | Apple | iOS and iPadOS | — | A race condition was addressed with improved state handling. This issue is fi… |
| CVE-2026-84632 | await | — | Apple | iOS and iPadOS | — | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-84635 | await | — | Apple | Safari | — | A logic issue was addressed with improved state management. This issue is fix… |
| CVE-2026-84636 | await | — | Apple | iOS and iPadOS | — | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-86869 | await | — | Apple | iOS and iPadOS | — | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-86870 | await | — | Apple | iOS and iPadOS | — | A heap buffer overflow was addressed with improved bounds checking. This issu… |
| CVE-2026-86878 | await | — | Apple | iOS and iPadOS | — | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2026-86881 | await | — | Apple | iOS and iPadOS | — | A certificate validation issue was addressed with improved certificate valida… |
| CVE-2026-86882 | await | — | Apple | iOS and iPadOS | — | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-86883 | await | — | Apple | iOS and iPadOS | — | A privacy issue was addressed with improved handling of files. This issue is … |
| CVE-2026-86884 | await | — | Apple | iOS and iPadOS | — | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2026-86885 | await | — | Apple | iOS and iPadOS | — | An input validation issue was addressed with improved input validation. This … |
| CVE-2026-86886 | await | — | Apple | iOS and iPadOS | — | A path traversal issue was addressed with improved input validation. This iss… |
| CVE-2026-86887 | await | — | Apple | iOS and iPadOS | — | A privacy issue was addressed by removing sensitive data. This issue is fixed… |
| CVE-2026-86888 | await | — | Apple | iOS and iPadOS | — | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2026-86889 | await | — | Apple | macOS | — | A certificate validation issue was addressed with improved certificate valida… |
| CVE-2026-86890 | await | — | Apple | iOS and iPadOS | — | A logic issue was addressed with improved checks. This issue is fixed in iOS … |
| CVE-2026-86891 | await | — | Apple | macOS | — | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-86892 | await | — | Apple | iOS and iPadOS | — | This issue was addressed with additional entitlement checks. This issue is fi… |
| CVE-2026-86893 | await | — | Apple | iOS and iPadOS | — | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2026-86894 | await | — | Apple | macOS | — | A logic issue was addressed with improved checks. This issue is fixed in macO… |
| CVE-2026-86895 | await | — | Apple | iOS and iPadOS | — | An information disclosure issue was addressed with improved state management.… |
| CVE-2026-86897 | await | — | Apple | Safari | — | This issue was addressed with additional entitlement checks. This issue is fi… |
| CVE-2026-86898 | await | — | Apple | Safari | — | A logic issue was addressed with improved state management. This issue is fix… |
| CVE-2026-86900 | await | — | Apple | macOS | — | An out-of-bounds read issue was addressed with improved input validation. Thi… |
| CVE-2026-86901 | await | — | Apple | macOS | — | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-86902 | await | — | Apple | macOS | — | A parsing issue in the handling of directory paths was addressed with improve… |
| CVE-2026-86903 | await | — | Apple | iOS and iPadOS | — | An out-of-bounds read was addressed with improved input validation. This issu… |
| CVE-2026-86904 | await | — | Apple | iOS and iPadOS | — | A privacy issue was addressed with improved state management. This issue is f… |
| CVE-2026-86905 | await | — | Apple | iOS and iPadOS | — | This issue was addressed by removing the vulnerable code. This issue is fixed… |
| CVE-2026-86909 | await | — | Apple | macOS | — | A logic issue was addressed with improved state management. This issue is fix… |
| CVE-2026-86910 | await | — | Apple | macOS | — | A permissions issue was addressed with improved path validation. This issue i… |
| CVE-2026-86911 | await | — | Apple | macOS | — | This issue was addressed with improved state management. This issue is fixed … |
| CVE-2026-86924 | await | — | Apple | iOS and iPadOS | — | A memory corruption issue was addressed with improved input validation. This … |