Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 CVE-2026-43724

CVE-2026-43724_CVE-2026-43724

The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. An app may be ab...

Apple iOS and iPadOS CVE
HIGH 8.1 CVE-2026-43735

CVE-2026-43735_CVE-2026-43735

The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. A malicious w...

Apple Safari CVE
CRITICAL 9.1 CVE-2026-55276

Apache Tomcat: Logged effective web.xml is incomplete_CVE-2026-55276

Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not i...

Apache Software Foundation Apache Tomcat 11.0.0-M1 CVE
MEDIUM 5.5 CVE-2026-43722

CVE-2026-43722_CVE-2026-43722

The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. An app may be ab...

Apple iOS and iPadOS CVE
HIGH 7.5 CVE-2026-43721

CVE-2026-43721_CVE-2026-43721

This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2....

Apple Safari CVE
HIGH 8.3 CVE-2026-43701

CVE-2026-43701_CVE-2026-43701

The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. A malicious w...

Apple Safari CVE
CRITICAL 9.1 CVE-2026-39868

CVE-2026-39868_CVE-2026-39868

This issue was addressed with improved input validation. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. An app may be abl...

Apple iOS and iPadOS CVE
HIGH 7.3 CVE-2026-55957

Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind_CVE-2026-55957

Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed...

Apache Software Foundation Apache Tomcat 11.0.0-M1 CVE
MEDIUM 6.5 CVE-2026-55956

Apache Tomcat: Security constraints for default servlet ignored method_CVE-2026-55956

Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method...

Apache Software Foundation Apache Tomcat 11.0.0-M1 CVE
MEDIUM 6.5 CVE-2026-55955

Apache Tomcat: EncryptInterceptor not protected against replay attacks_CVE-2026-55955

Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This is...

Apache Software Foundation Apache Tomcat 11.0.0-M1 CVE