On September 29, 2026, CISA reported adding CVE-2026-86950 to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is described as an out-of-bounds write affecting several Apple products; the agency reports evidence of active exploitation.
The notice emphasizes prioritizing KEV vulnerabilities through risk-based management. Binding Operational Directive 26-04 sets requirements for US Federal Civilian Executive Branch agencies, including prioritizing certain risks and expectations for checking for possible compromise before applying an update.
The directive applies to the covered federal agencies, but CISA encourages all organizations to prioritize remediation of KEV-listed vulnerabilities. To act, check whether organizational assets include affected products and consult current vendor guidance; the notice does not specify affected versions or a particular fix.
Consult CISA’s original notice and the corresponding KEV catalog entry to verify the identifier, scope, and any updates. When studying the notice with AI tools, do not submit asset inventories, credentials, or other internal data: use public excerpts and follow your organization’s data policy.