Vendor
Apple
As of , 95 Apple vulnerabilities are on CISA's list of exploited vulnerabilities; 9 were added in 2026. Patch first: CVE-2026-65400.
Patch first
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1 | CVE-2026-65400Improper Authentication | Apple macOS | Patch nowForensic triage required by CISA | 0.02 | ||
| 2 | CVE-2026-86950Out-of-Bounds Write | Apple Multiple Products | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.01 | ||
| 3 | CVE-2016-4657Webkit Memory Corruption | Apple iOS | Patch this weekMetasploit module; EPSS 0.67; verified Exploit-DB entry | 0.67 | ||
| 4 | CVE-2016-4655Information Disclosure | Apple iOS | Patch this weekMetasploit module; verified Exploit-DB entry | 0.33 | ||
| 5 | CVE-2014-4404Heap-Based Buffer Overflow | Apple OS X | Patch this weekMetasploit module; verified Exploit-DB entry | 0.49 | ||
| 6 | CVE-2016-4656Memory Corruption | Apple iOS | Patch this weekMetasploit module; verified Exploit-DB entry | 0.24 | ||
| 7 | CVE-2015-1130Authentication Bypass | Apple OS X | Patch this weekMetasploit module; verified Exploit-DB entry | 0.10 | ||
| 8 | CVE-2021-30657Unspecified | Apple macOS | Patch this weekMetasploit module; EPSS 0.69 | 0.69 | ||
| 9 | CVE-2020-9934Input Validation | Apple iOS, iPadOS, and macOS | Patch this weekMetasploit module | 0.03 | ||
| 10 | CVE-2021-30860Integer Overflow | Apple Multiple Products | Patch this weekEPSS 0.76 | 0.76 | ||
| 11 | CVE-2023-41064ImageIO Buffer Overflow | Apple iOS, iPadOS, and macOS | Patch this weekEPSS 0.53 | 0.53 | ||
| 12 | CVE-2023-32434Integer Overflow | Apple Multiple Products | Patch this weekEPSS 0.52 | 0.52 | ||
| 13 | CVE-2019-8605Use-After-Free | Apple Multiple Products | Patch soonVerified Exploit-DB entry | 0.18 | ||
| 14 | CVE-2020-3837Memory Corruption | Apple Multiple Products | Patch soonVerified Exploit-DB entry | 0.15 | ||
| 15 | CVE-2019-8506Type Confusion | Apple Multiple Products | Patch soonVerified Exploit-DB entry | 0.16 | ||
| 16 | CVE-2025-43300Out-of-Bounds Write | Apple iOS, iPadOS, and macOS | Patch soon | 0.32 | ||
| 17 | CVE-2023-28205WebKit Use-After-Free | Apple Multiple Products | Patch soon | 0.27 | ||
| 18 | CVE-2021-30807Memory Corruption | Apple Multiple Products | Patch soon | 0.29 | ||
| 19 | CVE-2025-31200Memory Corruption | Apple Multiple Products | Patch soon | 0.19 | ||
| 20 | CVE-2025-24085Use-After-Free | Apple Multiple Products | Patch soon | 0.18 | ||
| 21 | CVE-2024-44309Cross-Site Scripting (XSS) | Apple Multiple Products | Patch soon | 0.23 | ||
| 22 | CVE-2023-42916WebKit Out-of-Bounds Read | Apple Multiple Products | Patch soon | 0.18 | ||
| 23 | CVE-2023-41993WebKit Code Execution | Apple Multiple Products | Patch soon | 0.24 | ||
| 24 | CVE-2023-37450WebKit Code Execution | Apple Multiple Products | Patch soon | 0.19 | ||
| 25 | CVE-2023-32435WebKit Memory Corruption | Apple Multiple Products | Patch soon | 0.23 |
Products
- Multiple Products54 entries
- iOS, iPadOS, and macOS11 entries
- iOS8 entries
- macOS6 entries
- iOS and iPadOS5 entries
- iOS and macOS4 entries
- iOS, iPadOS, and watchOS4 entries
- OS X2 entries
- iOS, macOS, watchOS1 entry
Added each year
Show the numbers
| Period | entries added |
|---|---|
| 2021 | 23 |
| 2022 | 26 |
| 2023 | 21 |
| 2024 | 7 |
| 2025 | 9 |
| 2026 | 9 |