CVE-2026-43819
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.6. An app may be able to access se
CVSS
5.5
Medio
EPSS
0.1%
p4
KEV
—
Exploit Today
1
0-100
Publicado: 27 jul 2026 · Última mod.: 28 jul 2026 · CWE-284
Sin historial EPSS suficiente todavía.
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.6. An app may be able to access sensitive user data.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-65888——
———Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.3hCVE-2026-65887——
———Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins.3hCVE-2026-65889——
———Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.3hCVE-2026-659437.5 ALT—
———Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.02hCVE-2026-65884——
———Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions.3hCVE-2026-419209.3 CRÍ—
——0Improper Access Control vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.1.15 or 10.1.4, which fixes the issue.4h