Known vulnerabilities in macOS 26.3.2 (a) 25D771400a - page 25

Vendor: Apple Inc.
Software: macOS
Version: 26.3.2 (a) 25D771400a
Software CPE: cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Total vulnerabilities: 524
Public exploits: 5
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting macOS version 26.3.2 (a) 25D771400a macOS 26.3.2 (a) 25D771400a is affected by 524 vulnerabilities: 17 high, 83 medium, 424 low Critical High Medium Low

Vulnerabilities (524)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU124380 - Improper Access Control
CVE-2026-28837
CWE-284 Low
No
No
26.4 25E246 25.03.2026 SB2026032504
#VU124379 - Improper Access Control
CVE-2026-28820
CWE-284 Low
No
No
26.4 25E246 25.03.2026 SB2026032504
#VU124365 - Permissions, Privileges, and Access Controls
CVE-2026-20607
CWE-264 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
#VU124364 - State Issues
CVE-2026-28845
CWE-371 Low
No
No
26.4 25E246 25.03.2026 SB2026032504
#VU124354 - Memory corruption
CVE-2026-28822
CWE-119 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 4 more
#VU124352 - Improper input validation
CVE-2026-28886
CWE-20 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 5 more
#VU124350 - Improper input validation
CVE-2026-28821
CWE-20 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
#VU124349 - Memory corruption
CVE-2026-20690
CWE-119 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 5 more
#VU124348 - Improper Link Resolution Before File Access ('Link Following')
CVE-2026-28866
CWE-59 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 2 more
#VU124347 - Improper input validation
CVE-2026-28894
CWE-20 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 2 more
#VU124346 - Use After Free
CVE-2026-28879
CWE-416 Medium
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 5 more
#VU124345 - Permissions, Privileges, and Access Controls
CVE-2026-20684
CWE-264 Low
No
No
26.4 25E246 25.03.2026 SB2026032504
#VU124344 - Cryptographic Issues
CVE-2026-20699
CWE-310 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624, 26.3 25D125 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 1 more
#VU124343 - State Issues
CVE-2026-28824
CWE-371 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
#VU124341 - Improper Link Resolution Before File Access ('Link Following')
CVE-2026-20633
CWE-59 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
#VU124335 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2026-28865
CWE-300 Medium
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 5 more
#VU119149 - Improper Neutralization of Server-Side Includes (SSI) Within a Web Page
CVE-2025-58098
CWE-97 Low
Public exploit available
No
14.8.5 23J423, 15.7.5 24G624, 26.4 25E246 04.12.2025 SB2025120441
SB2025121923
SB2025121940
and 47 more
#VU119148 - Server-Side Request Forgery (SSRF)
CVE-2025-59775
CWE-918 Medium
No
No
14.8.5 23J423, 15.7.5 24G624, 26.4 25E246 04.12.2025 SB2025120441
SB2026010820
SB20260114117
and 11 more
#VU119147 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2025-65082
CWE-74 Low
No
No
14.8.5 23J423, 15.7.5 24G624, 26.4 25E246 04.12.2025 SB2025120441
SB2025121923
SB2025122202
and 33 more
#VU119146 - Improper input validation
CVE-2025-66200
CWE-20 Low
No
No
14.8.5 23J423, 15.7.5 24G624, 26.4 25E246 04.12.2025 SB2025120441
SB2025121923
SB2025122202
and 31 more


Showing elements 481 - 500 out of 524