Known vulnerabilities in macOS 26.1 25B78 - page 27

Vendor: Apple Inc.
Software: macOS
Version: 26.1 25B78
Software CPE: cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Total vulnerabilities: 645
Public exploits: 8
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting macOS version 26.1 25B78 macOS 26.1 25B78 is affected by 645 vulnerabilities: 2 critical, 22 high, 94 medium, 527 low Critical High Medium Low

Vulnerabilities (645)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU124362 - Exposure of sensitive information to an unauthorized actor
CVE-2026-28893
CWE-200 Low
No
No
26.4 25E246 25.03.2026 SB2026032504
#VU124355 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-28876
CWE-22 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 3 more
#VU124085 - Protection Mechanism Failure
CVE-2026-20643
CWE-693 Medium
No
No
26.3.1 (a) 25D771280a, 26.3.2 (a) 25D771400a, 26.4 25E246 17.03.2026 SB2026031771
SB2026031772
SB2026031773
and 22 more
#VU122717 - Protection Mechanism Failure
CVE-2026-20606
CWE-693 Low
No
No
26.3 25D125, 14.8.4 23J319, 15.7.4 24G517 11.02.2026 SB2026021188
SB2026021189
SB2026021190
and 2 more
#VU122716 - Exposure of sensitive information to an unauthorized actor
CVE-2026-20641
CWE-200 Low
No
No
26.3 25D125, 14.8.4 23J319, 15.7.4 24G517 11.02.2026 SB2026021188
SB2026021189
SB2026021190
and 5 more
#VU122715 - Exposure of sensitive information to an unauthorized actor
CVE-2026-20680
CWE-200 Low
No
No
26.3 25D125, 14.8.4 23J319, 15.7.4 24G517 11.02.2026 SB2026021188
SB2026021189
SB2026021190
and 2 more
#VU122714 - Permissions, Privileges, and Access Controls
CVE-2026-20648
CWE-264 Low
No
No
26.3 25D125 11.02.2026 SB2026021188
#VU122713 - Improper input validation
CVE-2026-20658
CWE-20 Low
No
No
26.3 25D125 11.02.2026 SB2026021188
#VU122701 - Memory corruption
CVE-2026-20605
CWE-119 Low
No
No
26.3 25D125, 14.8.4 23J319, 15.7.4 24G517 11.02.2026 SB2026021188
SB2026021189
SB2026021190
and 1 more
#VU122700 - Improper input validation
CVE-2026-20618
CWE-20 Low
No
No
26.3 25D125 11.02.2026 SB2026021188
#VU122699 - Information Exposure Through Log Files
CVE-2026-20619
CWE-532 Low
No
No
26.3 25D125, 15.7.4 24G517 11.02.2026 SB2026021188
SB2026021189
#VU122698 - Improper Access Control
CVE-2026-20612
CWE-284 Low
No
No
26.3 25D125, 14.8.4 23J319, 15.7.4 24G517 11.02.2026 SB2026021188
SB2026021189
SB2026021190
#VU122697 - Exposure of sensitive information to an unauthorized actor
CVE-2026-20647
CWE-200 Low
No
No
26.3 25D125 11.02.2026 SB2026021188
#VU122696 - State Issues
CVE-2026-20662
CWE-371 Low
No
No
26.3 25D125, 15.7.4 24G517 11.02.2026 SB2026021188
SB2026021189
#VU122695 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-20653
CWE-22 Low
No
No
26.3 25D125, 14.8.4 23J319, 15.7.4 24G517 11.02.2026 SB2026021188
SB2026021189
SB2026021190
and 3 more
#VU122694 - Improper Link Resolution Before File Access ('Link Following')
CVE-2026-20610
CWE-59 Low
No
No
26.3 25D125 11.02.2026 SB2026021188
#VU122693 - Permissions, Privileges, and Access Controls
CVE-2026-20628
CWE-264 Low
No
No
26.3 25D125, 14.8.4 23J319, 15.7.4 24G517 11.02.2026 SB2026021188
SB2026021189
SB2026021190
and 5 more
#VU122692 - Improper input validation
CVE-2026-20656
CWE-20 Low
No
No
26.3 25D125 11.02.2026 SB2026021188
SB2026021195
SB2026021254
#VU122690 - State Issues
CVE-2026-20666
CWE-371 Low
No
No
26.3 25D125 11.02.2026 SB2026021188
#VU121026 - Insufficiently Protected Credentials
CVE-2025-14524
CWE-522 Low
No
No
14.8.5 23J423, 15.7.5 24G624, 26.4 25E246 07.01.2026 SB2026010741
SB2026010781
SB2026010782
and 23 more


Showing elements 521 - 540 out of 645