Apple Products Multiple Vulnerabilities
Details
Original advisory: https://www.hkcert.org/security-bulletin/apple-products-multiple-vulnerabilities_20260915
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2022-34373.7% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 89% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-206830.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-288990.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289300.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289340.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289350.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289370.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289660.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289680.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-289690.53% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0371 [1.00] [M/H] Kwetsbaarheden verholpen in Apple macOS en Samba door Apple en Sambancsc-nl
- unknownNCSC-2026-0370 [1.00] [M/H] Kwetsbaarheden verholpen in Apple iOS en iPadOSncsc-nl
- high[NEU] [hoch] Apple iOS, iPadOS, macOS Tahoe, macOS Golden Gate, macOS Sequoia und Safari: Mehrere Schwachstell…cert-bund
- high[UPDATE] [hoch] Apple Safari, macOS, iOS und iPadOS: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Apple macOS (Tahoe, Sonoma und Sequoia): Mehrere Schwachstellencert-bund
- medium[UPDATE] [mittel] Apple iOS und iPadOS: Mehrere Schwachstellencert-bund
- unknownexploitedMultiples vulnérabilités dans les produits Apple (15 septembre 2026)cert-fr-avis
- unknownCVE-2026-64790: A path handling issue was addressed with improved validation. This issue is fixed in macOS Gol…nvd
- unknownCVE-2026-64761: A privacy issue was addressed with improved handling of user preferences. This issue is fixed …nvd
- unknownCVE-2026-64756: A path handling issue was addressed with improved validation. This issue is fixed in iOS 27 an…nvd
- mediumCVE-2026-64753: A permissions issue was addressed by removing the vulnerable code. This issue is fixed in Safa…nvd
- highCVE-2026-64752: A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed i…nvd
More from HKCERT Security Bulletins
- unknownCisco Products Multiple Vulnerabilities2026-09-15
- unknownGitLab Multiple Vulnerabilities2026-09-14
- unknownPhishing Alert - Beware of Phishing Activities Leading to Unauthorised Credit Card Transactions2026-09-14
- unknownPalo Alto Products Multiple Vulnerabilities2026-09-10
- unknownMongoDB Multiple Vulnerabilities2026-09-10