HIGHVulnerability
Verified
Global

CISA KEV: Apple Multiple Products — Apple Multiple Products Classic Buffer Overflow Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel memory.

Analysis

Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel memory. Added to CISA Known Exploited Vulnerabilities catalog on 2026-03-20. Remediation due: 2026-04-03.

Indicators of Compromise (1)

CVE (1)
CVE-2025-43520
Source Attribution

Originally published by CISA KEV on Mar 20, 2026. Verified by: CISA.

Related Threats

CRITICALVulnerability

NVD CRITICAL: CVE-2026-102240 — A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the ...

A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file /www/cgi-bin/network_tools of the component Network Tools CGI. The manipulation of the argument sid results in os command injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not res

CVE-2026-102240
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-101354 — A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affecte...

A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affected element is the function _tWlanTask of the component MmtAtePrase Parser. Performing a manipulation results in stack-based buffer overflow. The attacker must have access to the local network to execute the attack. The exploit has been released to the public and may be used for attacks. The vendor was contacted early ab

CVE-2026-101354
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-102361 — mall4j through 4.0 contains a missing authentication vulnerability in the PUT /u...

mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can supply a target username in the request body to overwrite passwords without verification, enabling account takeover and access to orders and personal data.

CVE-2026-102361
NIST NVD