3d ago
2026-07-27 21:17Z
CRIT

CVE-2026-64731 — A path handling issue was addressed with improved validation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64731

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox. CVSSv3.1 9.8 (CRITICAL)

CWECWE 22TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 21:17Z
CRIT

CVE-2026-64729 — A use after free issue was addressed with improved memory management.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64729

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination. CVSSv3.1 9.8 (CRITICAL)

CWECWE 416TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 21:17Z
CRIT

CVE-2026-64727 — A type confusion issue was addressed with improved memory handling.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64727

A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26.6, tvOS 26.6. An app may be able to cause unexpected system termination. CVSSv3.1 9.8 (CRITICAL)

CWECWE 843TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 21:17Z
CRIT

CVE-2026-64726 — The issue was addressed with improved memory handling.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64726

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker in physical proximity may be able to corrupt process memory. CVSSv3.1 9.8 (CRITICAL)

CWECWE 119TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 21:17Z
CRIT

CVE-2026-64720 — A race condition was addressed with improved state handling.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64720

A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination. CVSSv3.1 9.8 (CRITICAL)

CWECWE 362TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 21:17Z
HIGH

CVE-2026-64719 — An out-of-bounds access issue was addressed with improved bounds checking.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64719

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash. CVSSv3.1 8.1 (HIGH)

CWECWE 125TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3d ago
2026-07-27 21:17Z
HIGH

CVE-2026-64713 — This issue was addressed with improved checks.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64713

This issue was addressed with improved checks. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Websites may know if the user has visited a given link. CVSSv3.1 8.1 (HIGH)

CWECWE 203TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
3d ago
2026-07-27 21:17Z
CRIT

CVE-2026-64704 — A type confusion issue was addressed with improved memory handling.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64704

A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination. CVSSv3.1 9.8 (CRITICAL)

CWECWE 843TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 21:17Z
CRIT

CVE-2026-64703 — A use after free issue was addressed with improved memory management.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64703

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause a denial-of-service. CVSSv3.1 9.8 (CRITICAL)

CWECWE 416TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 21:17Z
CRIT

CVE-2026-64702 — An access issue was addressed with additional sandbox restrictions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64702

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to break out of its sandbox. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 21:17Z
CRIT

CVE-2026-64700 — A use after free issue was addressed with improved memory management.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64700

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination. CVSSv3.1 9.8 (CRITICAL)

CWECWE 416TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 21:17Z
CRIT

CVE-2026-64698 — The issue was addressed with improved memory handling.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64698

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or read kernel memory. CVSSv3.1 9.8 (CRITICAL)

CWECWE 119TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 21:17Z
CRIT

CVE-2026-64697 — The issue was addressed with improved memory handling.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64697

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory. CVSSv3.1 9.8 (CRITICAL)

CWECWE 119TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 21:17Z
CRIT

CVE-2026-64696 — The issue was addressed with improved memory handling.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64696

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory. CVSSv3.1 9.8 (CRITICAL)

CWECWE 119TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 21:17Z
CRIT

CVE-2026-64695 — The issue was addressed with improved memory handling.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64695

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory. CVSSv3.1 9.8 (CRITICAL)

CWECWE 119TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 21:17Z
CRIT

CVE-2026-64694 — An integer overflow was addressed with improved input validation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64694

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination. CVSSv3.1 9.8 (CRITICAL)

CWECWE 190TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 21:17Z
CRIT

CVE-2026-64691 — A buffer overflow was addressed with improved size validation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64691

A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Tahoe 26.6. An app may be able to cause unexpected system termination. CVSSv3.1 9.8 (CRITICAL)

CWECWE 120TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 21:17Z
HIGH

CVE-2026-64555 — Linux: In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Fix

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64555

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops() kvm_hyp_handle_mops() resets the single-step state machine as part of rewinding state for a MOPS exception by modifying vcpu_cpsr() and writing the result directly into hardware. In the case of nested virtualization, vcpu_cpsr() is a synthetic value such that the rest of KVM can deal with vEL2 cleanly. That means the value requires translation b CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-07-27 21:17Z
HIGH

CVE-2026-64554 — Linux: It is later dereferenced in ip6_frag_next(), causing a use-after-free write.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64554

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() br_ip6_fragment() gets prevhdr, a pointer into the skb head, from ip6_find_1stfragopt(), then calls skb_checksum_help(). For a cloned skb skb_checksum_help() reallocates the head via pskb_expand_head(), leaving prevhdr dangling. It is later dereferenced in ip6_frag_next(), causing a use-after-free write. Save prevhdr's offset before skb_ch CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-07-27 21:17Z
HIGH

CVE-2026-64552 — Linux: That is still too loose: add_recvbuf_big() sets sg[1] to start at offset sizeof(struct padded_vnet_hdr)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64552

In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix len check in receive_big() receive_big() bounds the device-announced length by (big_packets_num_skbfrags + 1) * PAGE_SIZE. That is still too loose: add_recvbuf_big() sets sg[1] to start at offset sizeof(struct padded_vnet_hdr) into the first page, so the chain actually carries hdr_len + (PAGE_SIZE - sizeof(padded_vnet_hdr)) + big_packets_num_skbfrags * PAGE_SIZE bytes -- 20 bytes less than CVSSv3.1 8.4 (HIGH)

TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
3d ago
2026-07-27 21:17Z
CRIT

CVE-2026-64551 — Linux: In the Linux kernel, the following vulnerability has been resolved: sctp: validate STALE_COOKIE cause

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64551

In the Linux kernel, the following vulnerability has been resolved: sctp: validate STALE_COOKIE cause length before reading staleness When an ERROR chunk with a STALE_COOKIE cause is received in the COOKIE_ECHOED state, sctp_sf_do_5_2_6_stale() reads the 4-byte Measure of Staleness that follows the cause header: err = (struct sctp_errhdr *)(chunk->skb->data); stale = ntohl(*(__be32 *)((u8 *)err + sizeof(*err))); err is the first cause in the chunk, not the STALE_COOKI CVSSv3.1 9.1 (CRITICAL)

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3d ago
2026-07-27 21:17Z
HIGH

CVE-2026-64548 — Linux: Since len comes from BPF with arg3_type = ARG_ANYTHING and both are u32, a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64548

In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() When the scatterlist ring is full or nearly full, bpf_msg_push_data() enters a copy fallback path and computes copy + len for the page allocation size. Since len comes from BPF with arg3_type = ARG_ANYTHING and both are u32, a crafted len can wrap the sum to a small value, causing an undersized allocation followed by an out-of-bounds memcpy. CVSSv3.1 8.4 (HIGH)

TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
3d ago
2026-07-27 21:17Z
HIGH

CVE-2026-64547 — Linux: 0x4000), so the pad-byte read lands past the end of the skb: BUG: KASAN

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64547

In the Linux kernel, the following vulnerability has been resolved: net: usb: net1080: validate packet_len before pad-byte access in rx_fixup For an even packet_len, net1080_rx_fixup() reads the pad byte at skb->data[packet_len] before the skb->len != packet_len check further down, and packet_len is only bounded against NC_MAX_PACKET. A malicious NetChip 1080 device can send a short frame advertising a large even packet_len (e.g. 0x4000), so the pad-byte read lands past the CVSSv3.1 8.1 (HIGH)

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3d ago
2026-07-27 21:17Z
CRIT

CVE-2026-64541 — Linux: In the Linux kernel, the following vulnerability has been resolved: net/smc: fix UAF in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64541

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket smc_cdc_rx_handler() looks up the connection by token under the link group's conns_lock, drops the lock, and then dereferences conn and the smc_sock derived from it, ending in sock_hold(&smc->sk) inside smc_cdc_msg_recv(). No reference is held across the lock release. The only reference pinning the socket while the connection is discoverable in CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-07-27 21:17Z
HIGH

CVE-2026-64540 — Linux: In the Linux kernel, the following vulnerability has been resolved: usbnet: gl620a: fix out-of-bounds

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64540

In the Linux kernel, the following vulnerability has been resolved: usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() genelink_rx_fixup() splits an aggregated RX frame into its individual packets, using a per-packet length taken from device-supplied data. That length is only bounded by GL_MAX_PACKET_LEN (1514); it is never compared against how many bytes were actually received. A malicious GeneLink (GL620A) device can therefore send a short URB whose header cla CVSSv3.1 8.1 (HIGH)

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score