CVE-2026-20636
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visio
CVSS
6.5
Medium
EPSS
0.4%
p34
KEV
—
Exploit Today
10
0-100
Published: Feb 11, 2026 · Last modified: Jul 15, 2026 · CWE-119 · CWE-120
0.4%EPSS · 30 days0.4%
2026-08-242026-09-22
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciously crafted web content may lead to an unexpected process crash.
- support.apple.comhttps://support.apple.com/en-us/126346
- support.apple.comhttps://support.apple.com/en-us/126348
- support.apple.comhttps://support.apple.com/en-us/126353
- support.apple.comhttps://support.apple.com/en-us/126354
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:10702
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:11329
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:11814
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:13845
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:14659
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:16056
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:16695
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:19206
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:19535
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:22136
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:9692
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-20636
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2448791
- security.access.redhat.comhttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-20636.json
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-944248.8 HIG3.5%
——1A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function sub_140001000 in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The vendor was contacted early about this disclosure but did not respond in any way.4hCVE-2026-884098.8 HIG20.3%
——6FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a buffer overflow in the _Decode_GrB_Matrix function (/v19/decode_matrix.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.9hCVE-2026-941468.8 HIG2.5%
——1A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue affects the function sub_110BC of the file BSMEM64_W10.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress/Size results in write-what-where condition. Attacking locally is a requirement. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.7hCVE-2026-941428.8 HIG2.7%
——1A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200. Affected by this vulnerability is the function sub_1105C of the file BS_HWMIO64_W10.sys of the component IOCTL Handler. Such manipulation of the argument PhysicalAddress leads to write-what-where condition. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.1dCVE-2026-941298.8 HIG2.5%
——1A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800. This vulnerability affects the function sub_1105C of the file BS_RVSIO64.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress results in write-what-where condition. The attack needs to be approached locally. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.1dCVE-2026-941288.8 HIG2.5%
——1A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500. This affects the function sub_1105C of the file BS_LED64.sys of the component IOCTL Handler. The manipulation of the argument AssociatedIrp leads to write-what-where condition. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.1d