CVE Weekly Report — Week of Jun 29 – July 5, 2026
2026-W27
43
Total CVEs
1
Critical
7
High
0
Actively exploited
1 CVE is actively exploited (CISA KEV) this week. Patch these immediately: CVE-2026-53362
🔴 Critical CVEs (2)
| CVE | Product | CVSS | KEV | Description | Published |
|---|---|---|---|---|---|
| CVE-2026-39868 | macOS | 9.1 | — | This issue was addressed with improved input validation. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Taho… | Jun 29 |
| CVE-2026-53355 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RDS IB… | Jul 1 |
🟠 High CVEs (19)
| CVE | Product | CVSS | KEV | Description | Published |
|---|---|---|---|---|---|
| CVE-2026-53362 | Linux | 7.8 | KEV | In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation p… | Jul 4 |
| CVE-2026-53359 | Linux | 8.8 | — | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to u… | Jul 4 |
| CVE-2026-43725 | macOS | 7.1 | — | The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5… | Jun 29 |
| CVE-2026-43715 | macOS | 8.8 | — | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 a… | Jun 29 |
| CVE-2026-43701 | macOS | 7.1 | — | The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS … | Jun 29 |
| CVE-2026-43705 | macOS | 8.8 | — | A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 2… | Jun 29 |
| CVE-2026-43731 | macOS | 8.8 | — | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 a… | Jun 29 |
| CVE-2026-43735 | macOS | 8.1 | — | The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS … | Jun 29 |
| CVE-2026-43724 | macOS | 7.8 | — | The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tah… | Jun 29 |
| CVE-2026-53357 | Linux | 8.0 | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() v… | Jul 2 |
| CVE-2026-53360 | Linux | 8.8 | — | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ … | Jul 4 |
| CVE-2026-53358 | Linux | 8.8 | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use chan timer to close channels … | Jul 2 |
| CVE-2026-53346 | Linux | 7.1 | — | In the Linux kernel, the following vulnerability has been resolved: rust: arm64: set uwtable llvm module flag for CONFI… | Jul 1 |
| CVE-2026-53330 | Linux | 7.1 | — | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix out-of-bounds read in dp_get_e… | Jul 1 |
| CVE-2026-53329 | Linux | 7.0 | — | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Use krealloc_array() in dal_vector… | Jul 1 |
| CVE-2026-53361 | Linux | 7.1 | — | In the Linux kernel, the following vulnerability has been resolved: af_unix: Set gc_in_progress to true in unix_gc(). … | Jul 4 |
| CVE-2026-53354 | Linux | 8.8 | — | In the Linux kernel, the following vulnerability has been resolved: arm64: errata: Mitigate TLBI errata on various Arm … | Jul 1 |
| CVE-2026-53356 | Linux | 7.8 | — | In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Fix phys BO pread/pwrite with offset … | Jul 1 |
| CVE-2026-53341 | Linux | 7.8 | — | In the Linux kernel, the following vulnerability has been resolved: fhandle: fix UAF due to unlocked ->mnt_ns read in m… | Jul 1 |
🟡 Medium CVEs (49)
| CVE | Product | CVSS | KEV | Description | Published |
|---|---|---|---|---|---|
| CVE-2026-43707 | macOS | 6.5 | — | A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 … | Jun 29 |
| CVE-2026-43745 | macOS | 6.5 | — | An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.… | Jun 29 |
| CVE-2026-43720 | macOS | 6.5 | — | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 a… | Jun 29 |
| CVE-2026-43716 | macOS | 6.5 | — | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.… | Jun 29 |
| CVE-2026-43713 | macOS | 6.5 | — | A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPa… | Jun 29 |
| CVE-2026-43732 | macOS | 6.5 | — | A path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadO… | Jun 29 |
| CVE-2026-43703 | macOS | 6.5 | — | The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe … | Jun 29 |
| CVE-2026-56148 | Elasticsearch | 6.5 | — | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). … | Jul 1 |
| CVE-2026-43676 | macOS | 6.5 | — | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 26.… | Jun 29 |
| CVE-2026-43721 | macOS | 6.5 | — | This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS … | Jun 29 |
| CVE-2026-43706 | macOS | 6.5 | — | A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, … | Jun 29 |
| CVE-2026-43712 | macOS | 6.5 | — | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.… | Jun 29 |
| CVE-2026-49090 | Elasticsearch | 6.5 | — | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to a denial of service via Excessive Allocation (C… | Jul 1 |
| CVE-2026-43718 | macOS | 6.5 | — | A stack overflow was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPad… | Jun 29 |
| CVE-2026-43740 | macOS | 6.5 | — | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.… | Jun 29 |
| CVE-2026-43742 | macOS | 6.5 | — | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 a… | Jun 29 |
| CVE-2026-43734 | macOS | 6.5 | — | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 a… | Jun 29 |
| CVE-2026-43699 | macOS | 6.5 | — | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 a… | Jun 29 |
| CVE-2026-43709 | macOS | 6.5 | — | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 a… | Jun 29 |
| CVE-2026-43663 | macOS | 6.5 | — | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.… | Jun 29 |
| CVE-2026-39872 | macOS | 6.5 | — | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.… | Jun 29 |
| CVE-2026-43726 | macOS | 6.5 | — | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 a… | Jun 29 |
| CVE-2026-43727 | macOS | 6.5 | — | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 a… | Jun 29 |
| CVE-2026-43717 | macOS | 6.5 | — | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 a… | Jun 29 |
| CVE-2026-43746 | macOS | 6.5 | — | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 a… | Jun 29 |
| CVE-2026-28979 | macOS | 6.5 | — | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 26.… | Jun 29 |
| CVE-2026-14355 | PHP | 5.6 | — | In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algo… | Jul 3 |
| CVE-2026-43700 | macOS | 6.5 | — | A cross-origin issue was addressed with improved tracking of security origins. This issue is fixed in Safari 26.5.2, iOS… | Jun 29 |
| CVE-2026-43722 | macOS | 5.5 | — | The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tah… | Jun 29 |
| CVE-2026-53335 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: mm/damon/lru_sort: handle ctx allocation failure D… | Jul 1 |
| CVE-2026-53334 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: mm/damon/reclaim: handle ctx allocation failure Pa… | Jul 1 |
| CVE-2026-53350 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: ASoC: wm_adsp: Fix NULL dereference when removing f… | Jul 1 |
| CVE-2026-53337 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: net: bonding: fix NULL pointer dereference in bond_… | Jul 1 |
| CVE-2026-53336 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: nvmem: layouts: onie-tlv: fix hang on unknown types… | Jul 1 |
| CVE-2026-53328 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: sched_ext: Don't warn on NULL cgrp_moving_from in s… | Jul 1 |
| CVE-2026-53349 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: destroy stale expectfn exp… | Jul 1 |
| CVE-2026-53353 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: hsr: Remove WARN_ONCE() in hsr_addr_is_self(). syz… | Jul 1 |
| CVE-2026-53347 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Fix driver removal with disabled KMS D… | Jul 1 |
| CVE-2026-53343 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: ARM: 9475/1: entry: use byte load for KASAN VMAP st… | Jul 1 |
| CVE-2026-53333 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: mm/mincore: handle non-swap entries before !CONFIG_… | Jul 1 |
| CVE-2026-53351 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: riscv/ptrace: Use USER_REGSET_NOTE_TYPE for REGSET_… | Jul 1 |
| CVE-2026-53348 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: fix NULL pointer dereference in sdca_de… | Jul 1 |
| CVE-2026-53344 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: pinctrl: mcp23s08: Initialize mcp->dev and mcp->add… | Jul 1 |
| CVE-2026-53331 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl-… | Jul 1 |
| CVE-2026-53332 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: slimbus: qcom-ngd-ctrl: Register callbacks after cr… | Jul 1 |
| CVE-2026-53327 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: debugobjects: Do not fill_pool() if pi_blocked_on … | Jul 1 |
| CVE-2026-53325 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: agp/amd64: Fix broken error propagation in agp_amd6… | Jun 29 |
| CVE-2026-53326 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: debugobjects: Don't call fill_pool() in early boot … | Jul 1 |
| CVE-2026-53345 | Linux | 5.5 | — | In the Linux kernel, the following vulnerability has been resolved: KVM: Don't WARN if memory is dirtied without a vCPU… | Jul 1 |
