CVE-2026-20700

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: Feb. 18, 2026 9 articles

EPSS Score

Source: FIRST.org · 2026-05-24
0.43%
probability
This CVE has a 0.43% probability of being exploited in the next 30 days.
0% Top 63.1th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Description

Project Zero
Memory corruption in dyld

Attack Intelligence

Google Project Zero

Patched
Feb. 11, 2026
Reported by
Google Threat Analysis Group

Signal Intelligence

Confidence
92%
EPSS 0.43%
Mentions 9
Last Seen Apr 01, 2026

CNA Information

Analyst Note

This CVE demonstrates strong confirmation indicators: Apple explicitly acknowledged active exploitation in sophisticated targeted attacks, it appears in Google Project Zero records, and multiple reputable sources (BleepingComputer, TheHackerNews, CyberScoop) independently reported the zero-day with consistent technical details. The HIGH CVSS score (7.8) combined with vendor confirmation of real-world exploitation and the availability of patches across all affected platforms provides high confidence in the CONFIRMED status.

Triage Info

Decided atFeb 18, 2026