Known vulnerabilities in macOS 26.3 25D125 - page 17

Vendor: Apple Inc.
Software: macOS
Version: 26.3 25D125
Software CPE: cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Total vulnerabilities: 376
Public exploits: 5
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting macOS version 26.3 25D125 macOS 26.3 25D125 is affected by 376 vulnerabilities: 11 high, 69 medium, 296 low Critical High Medium Low

Vulnerabilities (376)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU124406 - Exposure of sensitive information to an unauthorized actor
CVE-2026-20691
CWE-200 Medium
No
No
26.4 25E246 25.03.2026 SB2026032503
SB2026032504
SB2026032505
and 20 more
#VU124405 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-28871
CWE-79 Medium
No
No
26.4 25E246 25.03.2026 SB2026032503
SB2026032504
SB2026032505
and 18 more
#VU124402 - Memory corruption
CVE-2026-28859
CWE-119 High
No
No
26.4 25E246 25.03.2026 SB2026032503
SB2026032504
SB2026032505
and 21 more
#VU124401 - State Issues
CVE-2026-28861
CWE-371 Low
No
No
26.4 25E246 25.03.2026 SB2026032503
SB2026032504
SB2026032505
and 8 more
#VU124400 - State Issues
CVE-2026-20665
CWE-371 High
No
No
26.4 25E246 25.03.2026 SB2026032503
SB2026032504
SB2026032505
and 22 more
#VU124386 - Memory corruption
CVE-2026-28857
CWE-119 Low
No
No
26.4 25E246 25.03.2026 SB2026032503
SB2026032504
SB2026032505
and 19 more
#VU124384 - Permissions, Privileges, and Access Controls
CVE-2026-28829
CWE-264 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
#VU124383 - Improper input validation
CVE-2026-28852
CWE-20 Low
No
No
26.4 25E246, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032509
and 4 more
#VU124382 - Improper input validation
CVE-2026-28828
CWE-20 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
#VU124381 - Improper input validation
CVE-2026-28844
CWE-20 Low
No
No
26.4 25E246 25.03.2026 SB2026032504
#VU124380 - Improper Access Control
CVE-2026-28837
CWE-284 Low
No
No
26.4 25E246 25.03.2026 SB2026032504
#VU124379 - Improper Access Control
CVE-2026-28820
CWE-284 Low
No
No
26.4 25E246 25.03.2026 SB2026032504
#VU124378 - Permissions, Privileges, and Access Controls
CVE-2026-20697
CWE-264 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
#VU124365 - Permissions, Privileges, and Access Controls
CVE-2026-20607
CWE-264 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
#VU124364 - State Issues
CVE-2026-28845
CWE-371 Low
No
No
26.4 25E246 25.03.2026 SB2026032504
#VU124350 - Improper input validation
CVE-2026-28821
CWE-20 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
#VU124349 - Memory corruption
CVE-2026-20690
CWE-119 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 5 more
#VU124348 - Improper Link Resolution Before File Access ('Link Following')
CVE-2026-28866
CWE-59 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 2 more
#VU124345 - Permissions, Privileges, and Access Controls
CVE-2026-20684
CWE-264 Low
No
No
26.4 25E246 25.03.2026 SB2026032504
#VU124335 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2026-28865
CWE-300 Medium
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 5 more


Showing elements 321 - 340 out of 376