Our automated tracking framework flagged that CISA added CVE-2026-86950 (Apple Multiple Products) to the Known Exploited Vulnerabilities (KEV) catalog on September 30, 2026. A KEV listing is CISA’s official confirmation that the flaw is being exploited in the wild — U.S. federal agencies must patch it by a fixed deadline. Here is what our data shows.

What CISA Reported

CISA describes the flaw as follows: “Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.”

Under Binding Operational Directive rules, U.S. federal agencies must remediate CVE-2026-86950 by October 2, 2026 — a 3-day window. Private organizations are not bound by the deadline, but CISA treats it as the benchmark for how urgently a confirmed-exploited flaw should be patched.

The Details

CVE CVE-2026-86950
Vendor / product Apple Multiple Products
Vulnerability Apple Multiple Products Out-of-Bounds Write Vulnerability
CVSS base score 8.8
Added to KEV September 29, 2026
Days public before listing (NVD → KEV lag) 1
Federal patch deadline October 2, 2026
Known ransomware use No

How This Compares to Apple’s Track Record

This one was public for just 1 days before CISA confirmed exploitation — faster than Apple’s 56-day median, meaning attackers moved unusually quickly.

Apple in the CISA KEV catalog Value
Tracked KEV entries 95
Median lag (public → KEV listing) 56 days
0-day rate (exploited at or before disclosure) 25%
Entries tied to known ransomware campaigns 0

For perspective, the median across all 1729 tracked KEV entries is 245 days — Apple’s exploited vulnerabilities are flagged faster than the catalog average.

Other Recent Apple KEV Additions

The most recent Apple vulnerabilities CISA has confirmed as actively exploited, from our tracker:

CVE Product Added to KEV Lag (days) Ransomware
CVE-2026-65400 macOS August 18, 2026 12 No
CVE-2025-31277 Multiple Products March 20, 2026 233 No
CVE-2025-43520 Multiple Products March 20, 2026 98 No
CVE-2025-43510 Multiple Products March 20, 2026 98 No
CVE-2023-41974 iOS and iPadOS March 5, 2026 785 No

What This Means for Defenders

CISA added CVE-2026-86950 to its Known Exploited Vulnerabilities (KEV) catalog on September 29, 2026. This vulnerability, an out-of-bounds write affecting multiple Apple products, has a CVSS base score of 8.8. Federal agencies must patch by October 2, 2026. All organizations should patch exposed Apple products immediately to mitigate potential compromise. If you can’t patch before the deadline, restrict access to affected systems by isolating them and applying network segmentation.

The KEV listing occurred just one day after public disclosure. This short NVD-to-KEV lag suggests attackers likely had weaponized exploits ready at or shortly after public disclosure, giving defenders a narrow window for detection and response. This CVE isn’t known to be used by ransomware at this time.

For systems where immediate patching isn’t feasible, implement compensating controls. Strengthen endpoint detection and response (EDR) capabilities and enhance monitoring for suspicious activity related to Apple devices. Proactive threat hunting is also recommended to identify potential compromises that occurred during the brief window of opportunity.

Related Coverage

How We Track This

This report was generated from our CISA KEV Lag Tracker, which syncs the official CISA KEV catalog daily and records the date each CVE is added. For every entry we retrieve the original NVD publication date and compute the lag in calendar days. No dates or figures on this page are estimated or taken from third-party sources — they come directly from CISA and NVD records.