Known vulnerabilities in macOS 26.3.2 25D2140 - page 7

Vendor: Apple Inc.
Software: macOS
Version: 26.3.2 25D2140
Software CPE: cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Total vulnerabilities: 193
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting macOS version 26.3.2 25D2140 macOS 26.3.2 25D2140 is affected by 193 vulnerabilities: 4 high, 43 medium, 146 low Critical High Medium Low

Vulnerabilities (193)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU124406 - Exposure of sensitive information to an unauthorized actor
CVE-2026-20691
CWE-200 Medium
No
No
26.4 25E246 25.03.2026 SB2026032503
SB2026032504
SB2026032505
and 20 more
#VU124402 - Memory corruption
CVE-2026-28859
CWE-119 High
No
No
26.4 25E246 25.03.2026 SB2026032503
SB2026032504
SB2026032505
and 21 more
#VU124401 - State Issues
CVE-2026-28861
CWE-371 Low
No
No
26.4 25E246 25.03.2026 SB2026032503
SB2026032504
SB2026032505
and 8 more
#VU124399 - Use After Free
CVE-2026-28835
CWE-416 Medium
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
#VU124396 - State Issues
CVE-2026-20693
CWE-371 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
#VU124395 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-28816
CWE-22 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
#VU124394 - Improper Privilege Management
CVE-2026-28891
CWE-269 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
#VU124393 - Improper Access Control
CVE-2026-20701
CWE-284 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
#VU124392 - Improper input validation
CVE-2026-20692
CWE-20 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 1 more
#VU124391 - Improper Access Control
CVE-2026-28882
CWE-284 Low
No
No
26.4 25E246 25.03.2026 SB2026032504
SB2026032514
SB2026032539
and 3 more
#VU124385 - Memory corruption
CVE-2026-20664
CWE-119 Low
No
No
26.4 25E246 25.03.2026 SB2026032503
SB2026032504
SB2026032505
and 19 more
#VU124377 - Information Exposure Through Log Files
CVE-2026-28818
CWE-532 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
#VU124376 - Out-of-bounds write
CVE-2026-28825
CWE-787 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
#VU124374 - State Issues
CVE-2026-28831
CWE-371 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
#VU124373 - Information Exposure Through Log Files
CVE-2026-28862
CWE-532 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
#VU124372 - Improper Access Control
CVE-2026-20631
CWE-284 Low
No
No
26.4 25E246 25.03.2026 SB2026032504
#VU124369 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-28827
CWE-22 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
#VU124368 - Improper Access Control
CVE-2026-28839
CWE-284 Low
No
No
26.4 25E246, 14.8.5 23J423, 15.7.5 24G624 25.03.2026 SB2026032504
SB2026032506
SB2026032507
#VU124367 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-20632
CWE-22 Low
No
No
26.4 25E246 25.03.2026 SB2026032504
#VU124366 - Improper Link Resolution Before File Access ('Link Following')
CVE-2026-20694
CWE-59 Low
No
No
26.4 25E246, 14.8.4 23J319, 14.8.5 23J423, 15.7.4 24G517, 15.7.5 24G624, 26.3 25D125 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 4 more


Showing elements 121 - 140 out of 193