Skip to main content

Actively exploited

Listed in CISA’s Known Exploited Vulnerabilities catalog since August 21, 2025.

CVE-2025-43300

Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability

Apple·iOS, iPadOS, and macOS

Added to KEV August 21, 2025

Alert details

Source feed
CISA KEV
CVE ID
CVE-2025-43300
CWE
CWE-787
Affected products
iOS, iPadOS, and macOS · Apple iOS, iPadOS, and macOS · Apple

What happened

Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework.

What it means for your business

Apple iOS, iPadOS, and macOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-43300). Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework. CISA remediation due date: 2025-09-11. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Required action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA due date: September 11, 2025

Sources

Related briefs

Actively exploited (KEV)

CVE-2026-18556

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able N-central is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-18556). N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass. CISA remediation due date: 2026-08-07. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

N-able·N-central

Actively exploited (KEV)

CVE-2026-34486

Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

Apache Tomcat is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-34486). Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. CISA remediation due date: 2026-08-07. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Apache·Tomcat

Industry news

Ongoing Threats of Swatting and Indicators for Community Members

Ongoing Threats of Swatting and Indicators for Community Members — FBI IC3 industry advisory relevant to cyber risk. PremierePC monitors federal alerts for Upstate SC businesses. Read the source link for full guidance or open a ticket if you want help assessing impact.

FBI IC3
Actively exploited (KEV)

CVE-2026-18577

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able N-central is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-18577). N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556. CISA remediation due date: 2026-08-06. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

N-able·N-central

Need help patching?

PremierePC monitors KEV alerts for managed clients and helps teams prioritize remediation before attackers do.