Known vulnerabilities in iPadOS 26.1 23B85 - page 15

Vendor: Apple Inc.
Software: iPadOS
Version: 26.1 23B85
Software CPE: cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
Total vulnerabilities: 418
Public exploits: 5
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting iPadOS version 26.1 23B85 iPadOS 26.1 23B85 is affected by 418 vulnerabilities: 2 critical, 18 high, 85 medium, 313 low Critical High Medium Low

Vulnerabilities (418)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU131100 - Exposure of sensitive information to an unauthorized actor
CVE-2026-28965
CWE-200 Low
No
No
26.5 23F77 12.05.2026 SB2026051215
#VU131099 - Exposure of sensitive information to an unauthorized actor
CVE-2026-28963
CWE-200 Low
No
No
26.5 23F77 12.05.2026 SB2026051215
#VU131098 - Multiple Interpretations of UI Input
CVE-2026-28964
CWE-450 Low
No
No
26.5 23F77 12.05.2026 SB2026051215
SB2026051218
#VU131088 - Use After Free
CVE-2026-28994
CWE-416 Medium
No
No
18.7.9 22H355, 26.5 23F77 12.05.2026 SB2026051205
SB2026051209
SB2026051210
and 4 more
#VU131048 - Use After Free
CVE-2026-43668
CWE-416 Medium
No
No
18.7.9 22H355, 26.5 23F77 12.05.2026 SB2026051205
SB2026051209
SB2026051210
and 5 more
#VU131047 - Improper input validation
CVE-2026-28985
CWE-20 Low
No
No
26.5 23F77 12.05.2026 SB2026051205
SB2026051215
SB2026051216
#VU131046 - Memory corruption
CVE-2026-43653
CWE-119 Medium
No
No
18.7.9 22H355, 26.5 23F77 12.05.2026 SB2026051205
SB2026051210
SB2026051214
and 3 more
#VU131043 - Improper input validation
CVE-2026-28987
CWE-20 Low
No
No
18.7.9 22H355, 26.5 23F77 12.05.2026 SB2026051205
SB2026051209
SB2026051210
and 4 more
#VU131044 - Improper Access Control
CVE-2026-28983
CWE-284 Low
No
No
18.7.9 22H355, 26.5 23F77 12.05.2026 SB2026051205
SB2026051214
SB2026051215
and 5 more
#VU131042 - Improper Access Control
CVE-2026-28986
CWE-284 Low
No
No
18.7.9 22H355, 26.5 23F77 12.05.2026 SB2026051205
SB2026051209
SB2026051210
and 4 more
#VU131041 - Out-of-bounds write
CVE-2026-28972
CWE-787 Low
No
No
18.7.9 22H355, 26.5 23F77 12.05.2026 SB2026051205
SB2026051209
SB2026051210
and 5 more
#VU131040 - State Issues
CVE-2026-28951
CWE-371 Low
No
No
18.7.9 22H355, 26.5 23F77 12.05.2026 SB2026051205
SB2026051209
SB2026051210
and 2 more
#VU131038 - Improper input validation
CVE-2026-28897
CWE-20 Low
No
No
18.7.9 22H355, 26.5 23F77 12.05.2026 SB2026051205
SB2026051209
SB2026051210
and 5 more
#VU131035 - Memory corruption
CVE-2026-43654
CWE-119 Low
No
No
18.7.9 22H355, 26.5 23F77 12.05.2026 SB2026051205
SB2026051209
SB2026051210
and 5 more
#VU131034 - Memory corruption
CVE-2026-43655
CWE-119 Low
No
No
26.5 23F77 12.05.2026 SB2026051205
SB2026051215
SB2026051216
and 1 more
#VU131032 - Improper input validation
CVE-2026-28943
CWE-20 Low
No
No
18.7.9 22H355, 26.5 23F77 12.05.2026 SB2026051205
SB2026051209
SB2026051210
and 4 more
#VU131033 - Use After Free
CVE-2026-28969
CWE-416 Low
No
No
18.7.9 22H355, 26.5 23F77, 27.0 24A437 12.05.2026 SB2026051205
SB2026051209
SB2026051210
and 9 more
#VU126887 - Exposure of sensitive information to an unauthorized actor
CVE-2026-28950
CWE-200 Low
No
No
26.4.2 23E261, 15.8.8 19H422, 16.7.16 20H392, 17.7.11, 18.7.8 22H352 23.04.2026 SB2026042332
SB2026042333
SB2026051211
and 2 more
#VU124405 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-28871
CWE-79 Medium
No
No
18.7.7 22H333, 26.4 23E246 25.03.2026 SB2026032503
SB2026032504
SB2026032505
and 18 more
#VU124375 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-20688
CWE-22 Low
No
No
26.4 23E246 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 2 more


Showing elements 281 - 300 out of 418