Apple Products Multiple Vulnerabilities
CSIRTS triage
- What
- Multiple vulnerabilities exist in Apple products.
- Who is affected
- All users of affected Apple products are potentially impacted.
- Urgency
- Remediation is necessary as vulnerabilities could lead to various security issues, though exploitation status is currently unknown.
- Action
- Users should apply available updates for their Apple products.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.hkcert.org/security-bulletin/apple-products-multiple-vulnerabilities_20260728
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2025-433250.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all scored CVEs.
- Low exploitation riskCVE-2026-37830.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all scored CVEs.
- Low exploitation riskCVE-2026-37840.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all scored CVEs.
- Low exploitation riskCVE-2026-44240.88% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 56% of all scored CVEs.
- Low exploitation riskCVE-2026-206720.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all scored CVEs.
- Elevated exploitation riskCVE-2026-2391849.7% 30-day exploitation probability — well above the norm. Schedule remediation this cycle. Riskier than 99% of all scored CVEs.
- Low exploitation riskCVE-2026-288490.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all scored CVEs.
- Low exploitation riskCVE-2026-288960.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all scored CVEs.
- Low exploitation riskCVE-2026-289000.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all scored CVEs.
- Low exploitation riskCVE-2026-289110.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] WebKitGTK: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] IBM QRadar SIEM: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Apple macOS (Tahoe, Sonoma, and Sequoia): Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] Apple iOS and iPadOS: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] Apache HTTP Server: Multiple vulnerabilitiescert-bund
- unknownNCSC-2026-0267 [1.00] [M/H] Vulnerabilities fixed in Apple MacOSncsc-nl
- unknownNCSC-2026-0266 [1.00] [M/H] Vulnerabilities fixed in Apple iOS and iPadOSncsc-nl
- high[NEW] [high] Oracle Communications: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Apple products (July 28, 2026)cert-fr-avis
- mediumCVE-2026-43714: The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and …nvd
- highCVE-2026-43711: A memory corruption issue was addressed with improved memory handling. This issue is fixed in …nvd
- criticalCVE-2026-43710: The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15…nvd
More from HKCERT Security Bulletins
- unknownGoogle Chrome Multiple Vulnerabilities2026-07-30
- unknownCisco Secure Firewall Management Center Software Information Disclosure Vulnerability2026-07-30
- unknownIBM WebSphere Products Multiple Vulnerabilities2026-07-30
- unknownNode.js Multiple Vulnerabilities2026-07-30
- unknownXen Multiple Vulnerabilities2026-07-30