Cyber & AI intelligence
Wasteland.
Briefs indexed2938
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-86950 2026-09-29

Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) Exploited in Targeted Attacks

"CISA has added CVE-2026-86950 to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is an out-of-bounds write in Apple CoreGraphics that may let an attacker run arbitrary code. Federal agencies must fix it by…"

CISA has added CVE-2026-86950 to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is an out-of-bounds write in Apple CoreGraphics that may let an attacker run arbitrary code. Federal agencies must fix it by October 2, 2026.

What Is It

CVE-2026-86950 is an out-of-bounds write (CWE-787) in CoreGraphics that affects Apple iOS, iPadOS, and macOS. According to Apple's NVD description, processing a maliciously crafted file may lead to arbitrary code execution. Apple fixed the issue with improved bounds checking.

The CVSS v3.1 base score is 8.8 (HIGH), with vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. An attacker can exploit it over the network without special conditions and without any privileges. However, a user must take some action, such as processing the malicious file.

Why It Matters

CISA's KEV listing confirms active exploitation. CISA added the flaw to the catalog on September 29, 2026. Apple states it "is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27."

CISA's SSVC assessment rates exploitation as active and technical impact as total. It rates the flaw as not automatable. Known ransomware campaign use is listed as Unknown. The KEV entry also flags the CVE for forensic triage, so organizations should check for signs of compromise as well as patch.

What's Vulnerable

Per NVD's affected-version data:

Patch Status

Apple has released fixes in:

CISA required action: Apply mitigations according to vendor instructions, in line with CISA's BOD 26-04 (Prioritizing Security Updates Based on Risk) guidance and its Forensics Triage Requirements. If mitigations are unavailable, follow the applicable BOD 26-04 guidance for cloud services or stop using the product. Stakeholders must evaluate each asset's internet exposure and follow BOD 26-04 patching guidelines. The federal remediation due date is October 2, 2026.

The KEV entry requires forensic triage, and Apple's report describes a possible attack against specific targeted individuals. Organizations should patch first the devices of people a well-resourced attacker is most likely to single out, and check those devices for signs of compromise.

Sources