Total CVEs

111,140

Critical Severity

796

High Severity

2,523

Last 7 Days

1,238
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 1 - 20 of 84 CVEs

Intego Personal Backup, a macOS backup utility that allows users to create scheduled backups and bootable system clones, contains a local privilege escalation vulnerability. Backup task definitions are stored in a location writable by non-privileged users while being processed with elevated privileg...

Vendor: Intego
Product: Personal Backup
Published: Feb 12, 2026
Source: NVD

Intego Log Reporter, a macOS diagnostic utility bundled with Intego security products that collects system and application logs for support analysis, contains a local privilege escalation vulnerability. A root-executed diagnostic script creates and writes files in /tmp without enforcing secure direc...

Vendor: Intego
Product: Log Reporter
Published: Feb 12, 2026
Source: NVD
CVE-2026-20700 HIGH - 7.8

A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 26.3, tvOS 26.3, macOS Tahoe 26.3, visionOS 26.3, iOS 26.3 and iPadOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issu...

Vendor: Apple
Product: macOS, watchOS, visionOS, iOS and iPadOS, tvOS
Published: Feb 11, 2026
Source: NVD

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Tahoe 26.3. An app may be able to access information about a user's contacts.

Vendor: Apple
Product: macOS
Published: Feb 11, 2026
Source: NVD
CVE-2026-20680 MEDIUM - 6.5

The issue was addressed with additional restrictions on the observability of app states. This issue is fixed in macOS Tahoe 26.3, macOS Sonoma 14.8.4, macOS Sequoia 15.7.4, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. A sandboxed app may be able to access sensitive user data.

Vendor: Apple
Product: macOS, iOS and iPadOS
Published: Feb 11, 2026
Source: NVD
CVE-2026-20677 CRITICAL - 9.0

A race condition was addressed with improved handling of symbolic links. This issue is fixed in macOS Tahoe 26.3, macOS Sonoma 14.8.4, iOS 18.7.5 and iPadOS 18.7.5, visionOS 26.3, iOS 26.3 and iPadOS 26.3. A shortcut may be able to bypass sandbox restrictions.

Vendor: Apple
Product: macOS, visionOS, iOS and iPadOS
Published: Feb 11, 2026
Source: NVD
CVE-2026-20676 MEDIUM - 5.3

This issue was addressed through improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, Safari 26.3, macOS Tahoe 26.3, visionOS 26.3. A website may be able to track users through Safari web extensions.

Vendor: Apple
Product: Safari, macOS, visionOS, iOS and iPadOS
Published: Feb 11, 2026
Source: NVD
CVE-2026-20675 MEDIUM - 5.5

The issue was addressed with improved bounds checks. This issue is fixed in watchOS 26.3, tvOS 26.3, macOS Tahoe 26.3, macOS Sonoma 14.8.4, macOS Sequoia 15.7.4, iOS 18.7.5 and iPadOS 18.7.5, visionOS 26.3, iOS 26.3 and iPadOS 26.3. Processing a maliciously crafted image may lead to disclosure of us...

Vendor: Apple
Product: macOS, watchOS, visionOS, iOS and iPadOS, tvOS
Published: Feb 11, 2026
Source: NVD
CVE-2026-20673 MEDIUM - 5.3

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, iOS 18.7.5 and iPadOS 18.7.5, macOS Tahoe 26.3, macOS Sonoma 14.8.4. Turning off "Load remote content in messages” may not apply to all mail previews.

Vendor: Apple
Product: macOS, iOS and iPadOS
Published: Feb 11, 2026
Source: NVD

A logic issue was addressed with improved checks. This issue is fixed in watchOS 26.3, tvOS 26.3, macOS Tahoe 26.3, macOS Sonoma 14.8.4, macOS Sequoia 15.7.4, iOS 18.7.5 and iPadOS 18.7.5, visionOS 26.3, iOS 26.3 and iPadOS 26.3. An attacker in a privileged network position may be able to intercept ...

Vendor: Apple
Product: macOS, watchOS, visionOS, iOS and iPadOS, tvOS
Published: Feb 11, 2026
Source: NVD
CVE-2026-20669 MEDIUM - 5.5

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Tahoe 26.3. An app may be able to access sensitive user data.

Vendor: Apple
Product: macOS
Published: Feb 11, 2026
Source: NVD
CVE-2026-20667 HIGH - 8.8

A logic issue was addressed with improved checks. This issue is fixed in watchOS 26.3, macOS Tahoe 26.3, macOS Sonoma 14.8.4, macOS Sequoia 15.7.4, iOS 26.3 and iPadOS 26.3. An app may be able to break out of its sandbox.

Vendor: Apple
Product: macOS, watchOS, iOS and iPadOS
Published: Feb 11, 2026
Source: NVD
CVE-2026-20666 MEDIUM - 5.5

An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.3. An app may be able to access sensitive user data.

Vendor: Apple
Product: macOS
Published: Feb 11, 2026
Source: NVD
CVE-2026-20662 MEDIUM - 4.6

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.

Vendor: Apple
Product: macOS
Published: Feb 11, 2026
Source: NVD
CVE-2026-20660 HIGH - 7.5

A path handling issue was addressed with improved logic. This issue is fixed in macOS Tahoe 26.3, macOS Sonoma 14.8.4, iOS 18.7.5 and iPadOS 18.7.5, visionOS 26.3, iOS 26.3 and iPadOS 26.3, Safari 26.3. A remote user may be able to write arbitrary files.

Vendor: Apple
Product: Safari, macOS, visionOS, iOS and iPadOS
Published: Feb 11, 2026
Source: NVD
CVE-2026-20658 HIGH - 7.8

A package validation issue was addressed by blocking the vulnerable package. This issue is fixed in macOS Tahoe 26.3. An app may be able to gain root privileges.

Vendor: Apple
Product: macOS
Published: Feb 11, 2026
Source: NVD

A logic issue was addressed with improved validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, Safari 26.3, macOS Tahoe 26.3. An app may be able to access a user's Safari history.

Vendor: Apple
Product: Safari, macOS, iOS and iPadOS
Published: Feb 11, 2026
Source: NVD
CVE-2026-20654 MEDIUM - 5.5

The issue was addressed with improved memory handling. This issue is fixed in watchOS 26.3, tvOS 26.3, macOS Tahoe 26.3, visionOS 26.3, iOS 26.3 and iPadOS 26.3. An app may be able to cause unexpected system termination.

Vendor: Apple
Product: macOS, watchOS, visionOS, iOS and iPadOS, tvOS
Published: Feb 11, 2026
Source: NVD
CVE-2026-20653 MEDIUM - 5.5

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Tahoe 26.3, macOS Sonoma 14.8.4, macOS Sequoia 15.7.4, iOS 18.7.5 and iPadOS 18.7.5, visionOS 26.3, iOS 26.3 and iPadOS 26.3. An app may be able to access sensitive user data.

Vendor: Apple
Product: macOS, visionOS, iOS and iPadOS
Published: Feb 11, 2026
Source: NVD
CVE-2026-20652 HIGH - 7.5

The issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26.3, iOS 18.7.5 and iPadOS 18.7.5, visionOS 26.3, iOS 26.3 and iPadOS 26.3, Safari 26.3. A remote attacker may be able to cause a denial-of-service.

Vendor: Apple
Product: Safari, macOS, visionOS, iOS and iPadOS
Published: Feb 11, 2026
Source: NVD