Monday, August 24, 2026

Today's Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Today's Security Brief

Apple iOS, iPadOS, and macOS account for the largest cluster of critical disclosures, with four CVSS 9.8 flaws spanning mobile and desktop platforms, alongside enterprise infrastructure issues in VMware Cloud Foundation, Microsoft SharePoint, and Zimbra Collaboration. The set includes 23 critical CVEs (CVSS 9.0+), up 92% from the prior day's 12, and 36 high-priority CVEs, down 57% from 84. Named critical items include CVE-2026-43778, CVE-2026-43799, and CVE-2026-43805 in Apple iOS and iPadOS (all CVSS 9.8), CVE-2026-64698 in Apple macOS (CVSS 9.8), and CVE-2026-78155 in OnGres StackGres (CVSS 9.9). Remote code execution and unauthenticated access patterns dominate, affecting endpoint fleets, virtualization platforms, collaboration servers, and open-source data infrastructure such as mlflow and StackGres. Patch data is not yet published for any of these entries (0% confirmed availability), so teams should track vendor advisories directly and prepare mitigations where fixes are pending; 8 CVEs have confirmed active exploitation.

  • Apple iOS, iPadOS, and macOS carry four CVSS 9.8 critical flaws (CVE-2026-43778, CVE-2026-43799, CVE-2026-43805, CVE-2026-64698), affecting both mobile and desktop endpoint fleets
  • 23 critical CVEs (CVSS 9.0+) disclosed, a 92% increase over the prior day's 12
  • 36 high-priority CVEs (CVSS 7.0-8.9), down 57% from 84 the prior day
  • Remote code execution and authentication bypass patterns dominate, hitting VMware Cloud Foundation and vCenter, Microsoft SharePoint, Zimbra Collaboration, and TrueConf Server
  • Patch availability is unconfirmed across the set (0%), including for OnGres StackGres CVE-2026-78155 (CVSS 9.9) and the Apple platform criticals
  • 8 CVEs show confirmed active exploitation, spanning Microsoft Windows and SharePoint, VMware, Apple macOS, Zimbra, TrueConf Server, and mlflow

Immediate action: Prioritize Apple endpoint fleets (iOS, iPadOS, macOS) and internet-facing enterprise infrastructure: VMware Cloud Foundation and vCenter, Microsoft SharePoint, Zimbra Collaboration, and TrueConf Server, where active exploitation is confirmed. No patch availability is confirmed for the critical items in this set, so monitor vendor advisories and apply updates as they ship. In the interim, restrict external access to affected management and collaboration services and review logs on exposed instances for signs of compromise.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation