CISA added CVE-2026-86950 to its Known Exploited Vulnerabilities (KEV) catalogue on 29 September 2026. The vulnerability affects Apple’s iOS, macOS and iPadOS products. Known as the Apple Multiple Products Out-of-Bounds Write Vulnerability, it affects CoreGraphics and may allow arbitrary code execution.
The flaw is an out-of-bounds write vulnerability in Apple’s CoreGraphics component. Successful exploitation could enable an attacker to execute arbitrary code. The available data does not specify the attack vector or authentication requirements. NVD assigns the vulnerability a CVSS score of 8.8, rated High. Patch availability is currently unknown, although Apple has published product-specific guidance.
CISA’s KEV listing confirms that attackers are actively exploiting the vulnerability. The available information does not confirm use in ransomware campaigns. Federal Civilian Executive Branch (FCEB) agencies must remediate the vulnerability by 2 October 2026.
CISA requires agencies to apply mitigations in accordance with Apple’s instructions and ensure compliance with BOD 26-04, Prioritising Security Updates Based on Risk, and CISA’s Forensics Triage Requirements. Agencies must follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset’s internet exposure and follow BOD 26-04 patching requirements. Although the mandate applies directly to FCEB agencies, all organisations should review their exposure and apply available Apple guidance.
See the NVD entry and CISA KEV catalogue for full details.