Edition of July 27, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-43747 | 7.1 | 2.3 | Apple | macOS | CWE-125 | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-64711 | 5.5 | 2.4 | Apple | iOS and iPadOS | CWE-285 | This issue was addressed with additional entitlement checks. This issue is fi… |
| CVE-2026-64723 | 5.5 | 2.4 | Apple | iOS and iPadOS | CWE-284 | A logic issue was addressed with improved checks. This issue is fixed in iOS … |
| CVE-2026-64776 | 5.5 | 2.3 | Apple | macOS | CWE-125 | The issue was addressed with improved bounds checks. This issue is fixed in m… |
| CVE-2026-17534 | 5.5 | 2.3 | MoonshotAI | Kimi Code | CWE-918 | Kimi Code FetchURL SSRF protection bypass via DNS-resolving hostnames and red… |
| CVE-2026-20672 | 5.5 | 2.3 | Apple | macOS | CWE-200 | An information disclosure issue was addressed with improved privacy controls.… |
| CVE-2026-43775 | 5.5 | 2.3 | Apple | macOS | CWE-285 | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-43782 | 5.5 | 2.3 | Apple | macOS | CWE-200 | This issue was addressed with improved checks. This issue is fixed in macOS S… |
| CVE-2026-17523 | 7.8 | 2.2 | Red Hat | Red Hat Enterprise Linux 8 | CWE-825 | Kernel: can:bcm: arbitrary kernel code execution leading to escalate privileges |
| CVE-2026-64707 | 5.5 | 2.1 | Apple | iOS and iPadOS | CWE-732 | A permissions issue was addressed with improved validation. This issue is fix… |
| CVE-2026-17572 | 5.5 | 2.1 | The HDF Group | HDF5 | CWE-125 | HDF5 SOHM List Index Heap Buffer Overflow |
| CVE-2026-66437 | 4.9 | 2.1 | Themeisle | Feedzy | CWE-918 | WordPress Feedzy plugin <= 5.2.4 - Server Side Request Forgery (SSRF) vulnera… |
| CVE-2026-64754 | 5.5 | 2.0 | Apple | iOS and iPadOS | CWE-787 | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-43767 | 5.0 | 2.0 | Apple | macOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-17574 | 5.2 | 2.0 | The HDF Group | HDF5 | CWE-476 | NULL Pointer Dereference in HDF5 via Invalid Variable-Length Datatype Type Tag |
| CVE-2026-17573 | 4.0 | 2.0 | The HDF Group | HDF5 | CWE-415 | Double Free in H5D__chunk_copy() in HDF5 via a Crafted Chunk-Index Size Field |
| CVE-2026-43672 | 7.1 | 1.9 | Apple | macOS | CWE-863 | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-64737 | 8.2 | 1.8 | Apple | macOS | CWE-284 | An authorization issue was addressed with improved state management. This iss… |
| CVE-2026-43756 | 5.5 | 1.8 | Apple | macOS | CWE-200 | A logic issue was addressed with improved validation. This issue is fixed in … |
| CVE-2026-10682 | 7.8 | 1.8 | zephyrproject | zephyr | CWE-787 | Out-of-bounds write in Zephyr `log_filter_set` syscall verifier reachable fro… |
| CVE-2026-17512 | 1.9 | 1.6 | ggml-org | whisper.cpp | CWE-119 | ggml-org whisper.cpp log_mel_spectrogram out-of-bounds |
| CVE-2026-17513 | 1.9 | 1.6 | ggml-org | whisper.cpp | CWE-617 | ggml-org whisper.cpp ggml.c ggml_ftype_to_ggml_type assertion |
| CVE-2025-59180 | 5.1 | 1.5 | Ericsson | Packet Core Controller (PCC) | CWE-798 | Use of Hard-coded Credentials Vulnerability |
| CVE-2026-39874 | 7.8 | 1.5 | Apple | macOS | CWE-276 | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2026-43806 | 5.5 | 1.4 | Apple | macOS | CWE-400 | A denial of service issue was addressed by removing the vulnerable code. This… |
| CVE-2026-64718 | 5.5 | 1.3 | Apple | Safari | CWE-416 | A use-after-free issue was addressed with improved memory management. This is… |
| CVE-2026-15003 | 5.6 | 1.3 | Red Hat | Red Hat Hardened Images | CWE-125 | Binutils: gnu binutils: heap-buffer-overflow in linker leads to information d… |
| CVE-2026-28849 | 5.5 | 1.3 | Apple | macOS | CWE-290 | The issue was addressed with improved checks. This issue is fixed in macOS Se… |
| CVE-2026-28900 | 5.5 | 1.3 | Apple | macOS | CWE-290 | A file quarantine bypass was addressed with additional checks. This issue is … |
| CVE-2026-43665 | 5.5 | 0.9 | Apple | macOS | CWE-862 | This issue was addressed with additional entitlement checks. This issue is fi… |
| CVE-2026-66428 | 4.3 | 0.9 | jgwhite33 | WP Google Review Slider | CWE-352 | WordPress WP Google Review Slider plugin <= 18.4 - Cross Site Request Forgery… |
| CVE-2026-66474 | 4.3 | 0.9 | HT Plugins | Insert Headers and Footers Code – HT Script | CWE-352 | WordPress Insert Headers and Footers Code – HT Script plugin <= 1.1.8 - Cross… |
| CVE-2026-43693 | 7.0 | 0.8 | Apple | macOS | CWE-362 | A race condition was addressed with improved state handling. This issue is fi… |
| CVE-2026-43781 | 4.7 | 0.8 | Apple | macOS | CWE-362 | A race condition was addressed with improved state handling. This issue is fi… |
| CVE-2026-43770 | 4.7 | 0.7 | Apple | macOS | CWE-362 | A race condition was addressed with additional validation. This issue is fixe… |
| CVE-2026-28926 | 7.0 | 0.5 | Apple | macOS | CWE-362 | A race condition was addressed with improved state handling. This issue is fi… |
| CVE-2026-43755 | 7.0 | 0.4 | Apple | macOS | CWE-362 | A race condition was addressed with improved state management. This issue is … |
| CVE-2026-43811 | 4.7 | 0.4 | Apple | iOS and iPadOS | CWE-362 | A race condition was addressed with improved checks. This issue is fixed in i… |
| CVE-2026-57916 | 4.6 | 0.4 | Asseco | proCertum SmartSign | CWE-73 | Arbitrary Path Execution via CPS URI in proCertum SmartSign |
| CVE-2026-14837 | 8.5 | 0.3 | Lenze | c430 | CWE-347 | SSH Enablement Signature Verification Bypass |