CVE-2026-28966
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS
CVSS
4.3
Medium
EPSS
0.4%
p35
KEV
—
Exploit Today
10
0-100
Published: Sep 14, 2026 · Last modified: Sep 18, 2026 · CWE-787
0.2%EPSS · 30 days0.4%
2026-09-152026-09-23
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. Processing a maliciously crafted file may lead to unexpected app termination.
- support.apple.comhttps://support.apple.com/en-us/149034
- support.apple.comhttps://support.apple.com/en-us/149035
- support.apple.comhttps://support.apple.com/en-us/149036
- support.apple.comhttps://support.apple.com/en-us/149038
- support.apple.comhttps://support.apple.com/en-us/149041
- support.apple.comhttps://support.apple.com/en-us/149042
- support.apple.comhttps://support.apple.com/en-us/149043
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-968919.8 CRI—
———A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipulation of the argument peer_hostname leads to out-of-bounds write. The attack may be initiated remotely.7hCVE-2026-888396.7 MED—
——0BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers.14hCVE-2026-888327.3 HIG—
——0BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images.6hCVE-2026-918157.8 HIG8.4%
——3Foxit PDF Editor/Reader does not perform sufficient verification of the JPEG2000 image metadata in the PDF file, which leads to out-of-bounds write in the heap buffer during decoding, potentially causing the program to crash and introducing the risk of arbitrary code execution.16hCVE-2026-918117.8 HIG6.8%
——2A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s PRC parser due to insufficient validation of vertex indices in triangular fan texture meshes. Successful exploitation could result in memory corruption and an application crash.16hCVE-2026-918047.8 HIG6.8%
——2A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s rendering of Circle annotations with malformed Cloudy appearance streams in specially crafted PDF files. Insufficient validation of the appearance geometry can result in memory corruption and application crashes.16h