Skip to main content

Actively exploited

Listed in CISA’s Known Exploited Vulnerabilities catalog since March 20, 2026.

CVE-2025-43520

Apple Multiple Products Classic Buffer Overflow Vulnerability

Apple · Multiple Products

Added to KEV March 20, 2026

Alert details

Source feed
CISA KEV
CVE ID
CVE-2025-43520
CWE
CWE-120
Affected products
Multiple Products · Apple Multiple Products · Apple

What happened

Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel memory.

What it means for your business

Apple Multiple Products is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-43520). Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel memory. CISA remediation due date: 2026-04-03. If you need help checking exposure, call (864) 335-9223.

Required action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA due date: April 3, 2026

Sources

Related briefs

Actively exploited (KEV)

CVE-2026-86950

Apple Multiple Products Out-of-Bounds Write Vulnerability

Apple Multiple Products is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-86950). Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution. CISA remediation due date: 2026-10-02. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-88779

Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Citrix NetScaler is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-88779). Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service. CISA remediation due date: 2026-10-07. If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2025-10502

Heap buffer overflow in ANGLE in Microsoft Edge vulnerability

Heap buffer overflow in ANGLE in Microsoft Edge vulnerability (CVE-2025-10502) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2026-96940

Microsoft Exchange Server Elevation of Privilege vulnerability

Microsoft Exchange Server Elevation of Privilege vulnerability (CVE-2026-96940) was added to Microsoft’s security update guidance. Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Need help patching?

PremierePC monitors KEV alerts for managed clients and helps teams prioritize remediation before attackers do.