Vulnerabilities CVE-2026-20700 Detail Description A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 26.3, tvOS 26.3, macOS Tahoe 26.3, visionOS 26.3, iOS 26.3 and iPadOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 and CVE-2025-43529 were also issued in response to this report. Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 4.0 Severity and Vector Strings: NIST: NVD N/A NVD assessment not yet provided. CVSS 3.x Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. ADP: CISA-ADP Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS 2.0 Severity and Vector Strings: NIST: NVD Base Score: N/A NVD assessment not yet provided. References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [email protected] . URL Source(s) Tag(s) https://support.apple.com/en-us/126346 Apple Inc. Release Notes Vendor Advisory https://support.apple.com/en-us/126348 Apple Inc. Release Notes Vendor Advisory https://support.apple.com/en-us/126351 Apple Inc. Release Notes Vendor Advisory https://support.apple.com/en-us/126352 Apple Inc. Release Notes Vendor Advisory https://support.apple.com/en-us/126353 Apple Inc. Release Notes Vendor Advisory https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20700 CISA-ADP US Government Resource This CVE is in CISA's Known Exploited Vulnerabilities Catalog Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements. Vulnerability Name Date Added Due Date Required Action Apple Multiple Buffer Overflow Vulnerability 02/12/2026 03/05/2026 Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Weakness Enumeration CWE-ID CWE Name Source CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer CISA-ADP Known Affected Software Configurations Switch to CPE 2.2 CPEs loading, please wait. Change History 6 change records found show changes Modified Analysis by NIST 2/13/2026 9:03:58 AM Action Type Old Value New Value Added Reference Type CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20700 Types: US Government Resource CVE CISA KEV Update by Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government 2/12/2026 9:00:04 PM Action Type Old Value New Value Added Date Added 2026-02-12 Added Due Date 2026-03-05 Added Required Action Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Added Vulnerability Name Apple Multiple Buffer Overflow Vulnerability CVE Modified by CISA-ADP 2/12/2026 2:15:51 PM Action Type Old Value New Value Added Reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20700 Initial Analysis by NIST 2/12/2026 1:42:15 PM Action Type Old Value New Value Added CPE Configuration OR *cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* versions up to (excluding) 26.3 *cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* versions up to (excluding) 26.3 *cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* versions up to (excluding) 26.3 *cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* versions up to (excluding) 26.3 *cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:* versions up to (excluding) 26.3 *cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* versions up to (excluding) 26.3 Added Reference Type Apple Inc.: https://support.apple.com/en-us/126346 Types: Release Notes, Vendor Advisory Added Reference Type Apple Inc.: https://support.apple.com/en-us/126348 Types: Release Notes, Vendor Advisory Added Reference Type Apple Inc.: https://support.apple.com/en-us/126351 Types: Release Notes, Vendor Advisory Added Reference Type Apple Inc.: https://support.apple.com/en-us/126352 Types: Release Notes, Vendor Advisory Added Reference Type Apple Inc.: https://support.apple.com/en-us/126353 Types: Release Notes, Vendor Advisory CVE Modified b
CVE-2026-20700 is a high-severity memory corruption vulnerability