CVE-2026-2713Disclosure(apple / macos)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple macos systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

IBM Trusteer Rapport installer 3.5.2309.290 IBM Trusteer Rapport could allow a local attacker to execute arbitrary code on the system, caused by DLL uncontrolled search path element vulnerability. By placing a specially crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system.

1.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-427

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • macos
  • trusteer_rapport
  • windows

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-10); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
macostrusteer_rapportwindows

2 versions affected across 3 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-10: 1Mentions · 2026-03-17: 1Patch / Workaround · 2026-03-17: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-17: 103-1003-17
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-101
Disclosure1
2026-03-171
Patch1
Full discourse2 posts
  • Autumn Good@autumn_good_35
    Patch

    RapportのインストーラでDLLサイドローディングの脆弱性。国内で提供している銀行は対応済みなんですかね? CVE-2026-2713 Security Bulletin: IBM Trusteer Rapport installer affected by uncontrolled search path element vulnerability https://www.ibm.com/support/pages/node/7263031

    Post summary

    IBM Trusteer Rapport installer suffers from a DLL side‑loading vulnerability (CVE‑2026‑2713); a security bulletin with patch details is available, but no evidence of active exploitation or PoC is provided.

    00020500
    6.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2713 IBM Trusteer Rapport installer 3.5.2309.290 IBM Trusteer Rapport could allow a local attacker to execute arbitrary code on the system, caused by DLL uncontrolled search… https://www.cve.org/CVERecord?id=CVE-2026-2713

    Post summary

    IBM Trusteer Rapport installer 3.5.2309.290 suffers from a local arbitrary code execution vulnerability caused by DLL uncontrolled search order (CVE‑2026‑2713).

    00000176
    56.7K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appibmtrusteer_rapport3.5.2309.290--
OSmicrosoftwindows---

Explore more