Our automated tracking framework flagged that CISA added CVE-2026-86950 (Apple Multiple Products) to the Known Exploited Vulnerabilities (KEV) catalog on September 30, 2026. A KEV listing is CISA’s official confirmation that the flaw is being exploited in the wild — U.S. federal agencies must patch it by a fixed deadline. Here is what our data shows.
What CISA Reported
CISA describes the flaw as follows: “Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.”
Under Binding Operational Directive rules, U.S. federal agencies must remediate CVE-2026-86950 by October 2, 2026 — a 3-day window. Private organizations are not bound by the deadline, but CISA treats it as the benchmark for how urgently a confirmed-exploited flaw should be patched.
The Details
| CVE | CVE-2026-86950 |
| Vendor / product | Apple Multiple Products |
| Vulnerability | Apple Multiple Products Out-of-Bounds Write Vulnerability |
| CVSS base score | 8.8 |
| Added to KEV | September 29, 2026 |
| Days public before listing (NVD → KEV lag) | 1 |
| Federal patch deadline | October 2, 2026 |
| Known ransomware use | No |
How This Compares to Apple’s Track Record
This one was public for just 1 days before CISA confirmed exploitation — faster than Apple’s 56-day median, meaning attackers moved unusually quickly.
| Apple in the CISA KEV catalog | Value |
|---|---|
| Tracked KEV entries | 95 |
| Median lag (public → KEV listing) | 56 days |
| 0-day rate (exploited at or before disclosure) | 25% |
| Entries tied to known ransomware campaigns | 0 |
For perspective, the median across all 1729 tracked KEV entries is 245 days — Apple’s exploited vulnerabilities are flagged faster than the catalog average.
Other Recent Apple KEV Additions
The most recent Apple vulnerabilities CISA has confirmed as actively exploited, from our tracker:
| CVE | Product | Added to KEV | Lag (days) | Ransomware |
|---|---|---|---|---|
| CVE-2026-65400 | macOS | August 18, 2026 | 12 | No |
| CVE-2025-31277 | Multiple Products | March 20, 2026 | 233 | No |
| CVE-2025-43520 | Multiple Products | March 20, 2026 | 98 | No |
| CVE-2025-43510 | Multiple Products | March 20, 2026 | 98 | No |
| CVE-2023-41974 | iOS and iPadOS | March 5, 2026 | 785 | No |
What This Means for Defenders
CISA added CVE-2026-86950 to its Known Exploited Vulnerabilities (KEV) catalog on September 29, 2026. This vulnerability, an out-of-bounds write affecting multiple Apple products, has a CVSS base score of 8.8. Federal agencies must patch by October 2, 2026. All organizations should patch exposed Apple products immediately to mitigate potential compromise. If you can’t patch before the deadline, restrict access to affected systems by isolating them and applying network segmentation.
The KEV listing occurred just one day after public disclosure. This short NVD-to-KEV lag suggests attackers likely had weaponized exploits ready at or shortly after public disclosure, giving defenders a narrow window for detection and response. This CVE isn’t known to be used by ransomware at this time.
For systems where immediate patching isn’t feasible, implement compensating controls. Strengthen endpoint detection and response (EDR) capabilities and enhance monitoring for suspicious activity related to Apple devices. Proactive threat hunting is also recommended to identify potential compromises that occurred during the brief window of opportunity.
Related Coverage
- Apple’s CVE-2026-65400 Was Exploited in 12 Days — Faster Than Its 56-Day Median (August 2026)
- Critical Microsoft SharePoint Flaw CVE-2026-50522 (CVSS 9.8) Added to CISA KEV (July 2026)
How We Track This
This report was generated from our CISA KEV Lag Tracker, which syncs the official CISA KEV catalog daily and records the date each CVE is added. For every entry we retrieve the original NVD publication date and compute the lag in calendar days. No dates or figures on this page are estimated or taken from third-party sources — they come directly from CISA and NVD records.