CISA has added CVE-2026-86950 to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is an out-of-bounds write in Apple CoreGraphics that may let an attacker run arbitrary code. Federal agencies must fix it by October 2, 2026.
What Is It
CVE-2026-86950 is an out-of-bounds write (CWE-787) in CoreGraphics that affects Apple iOS, iPadOS, and macOS. According to Apple's NVD description, processing a maliciously crafted file may lead to arbitrary code execution. Apple fixed the issue with improved bounds checking.
The CVSS v3.1 base score is 8.8 (HIGH), with vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. An attacker can exploit it over the network without special conditions and without any privileges. However, a user must take some action, such as processing the malicious file.
Why It Matters
CISA's KEV listing confirms active exploitation. CISA added the flaw to the catalog on September 29, 2026. Apple states it "is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27."
CISA's SSVC assessment rates exploitation as active and technical impact as total. It rates the flaw as not automatable. Known ransomware campaign use is listed as Unknown. The KEV entry also flags the CVE for forensic triage, so organizations should check for signs of compromise as well as patch.
What's Vulnerable
Per NVD's affected-version data:
- iOS and iPadOS: versions before 26.7.1
- macOS Sequoia: versions before 15.8.1
- macOS Tahoe: versions 26.0 up to but not including 26.7.1
Patch Status
Apple has released fixes in:
- iOS 26.7.1 and iPadOS 26.7.1
- macOS Sequoia 15.8.1
- macOS Tahoe 26.7.1
CISA required action: Apply mitigations according to vendor instructions, in line with CISA's BOD 26-04 (Prioritizing Security Updates Based on Risk) guidance and its Forensics Triage Requirements. If mitigations are unavailable, follow the applicable BOD 26-04 guidance for cloud services or stop using the product. Stakeholders must evaluate each asset's internet exposure and follow BOD 26-04 patching guidelines. The federal remediation due date is October 2, 2026.
The KEV entry requires forensic triage, and Apple's report describes a possible attack against specific targeted individuals. Organizations should patch first the devices of people a well-resourced attacker is most likely to single out, and check those devices for signs of compromise.
Sources
- CISA KEV Catalog – CVE-2026-86950
- NVD – CVE-2026-86950
- Apple Security Advisory 149226
- Apple Security Advisory 149228
- Apple Security Advisory 149229
- CISA BOD 26-04: Prioritizing Security Updates Based on Risk
- CISA BOD 26-04 Implementation Guidance (Forensics Triage Requirements)
- Full Disclosure – Sep 2026 #89
- Full Disclosure – Sep 2026 #90
- Full Disclosure – Sep 2026 #91