Vendor

Apple

As of , 95 Apple vulnerabilities are on CISA's list of exploited vulnerabilities; 9 were added in 2026. Patch first: CVE-2026-65400.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2026-65400Improper AuthenticationApple macOSPatch nowForensic triage required by CISA0.02
2CVE-2026-86950Out-of-Bounds WriteApple Multiple ProductsPatch nowForensic triage required by CISA; listed in the last 14 days0.01
3CVE-2016-4657Webkit Memory CorruptionApple iOSPatch this weekMetasploit module; EPSS 0.67; verified Exploit-DB entry0.67
4CVE-2016-4655Information DisclosureApple iOSPatch this weekMetasploit module; verified Exploit-DB entry0.33
5CVE-2014-4404Heap-Based Buffer OverflowApple OS XPatch this weekMetasploit module; verified Exploit-DB entry0.49
6CVE-2016-4656Memory CorruptionApple iOSPatch this weekMetasploit module; verified Exploit-DB entry0.24
7CVE-2015-1130Authentication BypassApple OS XPatch this weekMetasploit module; verified Exploit-DB entry0.10
8CVE-2021-30657UnspecifiedApple macOSPatch this weekMetasploit module; EPSS 0.690.69
9CVE-2020-9934Input ValidationApple iOS, iPadOS, and macOSPatch this weekMetasploit module0.03
10CVE-2021-30860Integer OverflowApple Multiple ProductsPatch this weekEPSS 0.760.76
11CVE-2023-41064ImageIO Buffer OverflowApple iOS, iPadOS, and macOSPatch this weekEPSS 0.530.53
12CVE-2023-32434Integer OverflowApple Multiple ProductsPatch this weekEPSS 0.520.52
13CVE-2019-8605Use-After-FreeApple Multiple ProductsPatch soonVerified Exploit-DB entry0.18
14CVE-2020-3837Memory CorruptionApple Multiple ProductsPatch soonVerified Exploit-DB entry0.15
15CVE-2019-8506Type ConfusionApple Multiple ProductsPatch soonVerified Exploit-DB entry0.16
16CVE-2025-43300Out-of-Bounds WriteApple iOS, iPadOS, and macOSPatch soon0.32
17CVE-2023-28205WebKit Use-After-FreeApple Multiple ProductsPatch soon0.27
18CVE-2021-30807Memory CorruptionApple Multiple ProductsPatch soon0.29
19CVE-2025-31200Memory CorruptionApple Multiple ProductsPatch soon0.19
20CVE-2025-24085Use-After-FreeApple Multiple ProductsPatch soon0.18
21CVE-2024-44309Cross-Site Scripting (XSS)Apple Multiple ProductsPatch soon0.23
22CVE-2023-42916WebKit Out-of-Bounds ReadApple Multiple ProductsPatch soon0.18
23CVE-2023-41993WebKit Code ExecutionApple Multiple ProductsPatch soon0.24
24CVE-2023-37450WebKit Code ExecutionApple Multiple ProductsPatch soon0.19
25CVE-2023-32435WebKit Memory CorruptionApple Multiple ProductsPatch soon0.23

The next 70, from number 26

Products

Added each year

1020302021: 232320212022: 262620222023: 212120232024: 7720242025: 9920252026: 992026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
202123
202226
202321
20247
20259
20269

Used in ransomware

Changes CISA made to these entries

  1. CVE-2025-43520 Apple Multiple ProductsEdited: description.

Every change we recorded