CISA Adds One Known Exploited Vulnerability to Catalog
CISA added actively exploited Apple out-of-bounds write CVE-2026-86950 to the KEV catalog.
CISA added CVE-2026-86950, an out-of-bounds write affecting multiple Apple products, to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. Binding Operational Directive 26-04 requires Federal Civilian Executive Branch agencies to prioritize rapid remediation of high-risk KEV entries on publicly exposed assets and to check whether systems were compromised before patching. CISA says this vulnerability class is a frequent attack vector and encourages all organizations to remediate KEV flaws using risk-based vulnerability management.
- CVE-2026-86950 is an out-of-bounds write in multiple Apple products.
- CISA added it to KEV based on evidence of active exploitation.
- BOD 26-04 requires federal agencies to prioritize high-risk KEV fixes.
- CISA urges all organizations to remediate cataloged vulnerabilities quickly.
Vulnerabilities mentionedAll →
- CVE-2026-869508.8—Out-of-Bounds Write in Apple CoreGraphics Enables Code Execution on iOS and macOSpublished · Apple iOS KEV PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-86950 | Out-of-Bounds Write in Apple CoreGraphics Enables Code Execution on iOS and macOS An out-of-bounds write vulnerability (CWE-787) in Apple's CoreGraphics framework, scored 8.8 (high), allows arbitrary code execution when a device processes a maliciously crafted file, such as a malicious image or document that triggers the vulnerable rendering path. The flaw affects iPhones, iPads, and Macs, and exploitation requires no privileges but does require user interaction — the victim must open or preview the malicious file. Successful exploitation gives the attacker the ability to run code with high impact on confidentiality, integrity, and availability of the affected device. Apple states it is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27, indicating likely limited but real in-the-wild use. Fixes were shipped in iOS 26.7.1, iPadOS 26.7.1, macOS Sequoia 15.8.1, and macOS Tahoe 26.7.1. |
Full article222 words · extracted from cisa.gov · click to collapse
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-86950 Apple Multiple Products Out-of-Bounds Write Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.
While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.cisa.gov/news-events/alerts/2026/09/29/cisa-adds-one-known-exploited-vulnerability-catalog