SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-43687

MEDIUM · CVSS 6.5 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability allows for the potential disclosure of kernel memory when connecting to a malicious NFS server, impacting devices running affected versions of iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. Organizations using these operating systems should prioritize updates to versions 26.7 or 27 to mitigate the risk of sensitive information exposure. This issue highlights the importance of secure network connections, particularly in environments where NFS is utilized.

CVE
CVE-2026-43687
Severity
MEDIUM
CVSS
6.5
EPSS
0.35%

Original NVD Description

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Connecting to a malicious NFS server may disclose kernel memory.

Related CVEs

Other vulnerabilities affecting the same vendor(s)