← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 30, 2026 · 08:04via Security Affairs

U.S. CISA adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog

Brief

U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog.

The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added an Apple Multiple Products flaw, tracked as CVE-2026-86950 (CVSS score of 8. 8), to its Known Exploited Vulnerabilities (KEV) catalog .

This week, Apple has released security updates for iOS, iPadOS and macOS to fix a zero-day vulnerability CVE-2026-86950 in CoreGraphics that may have been exploited in attacks against specific individuals. The flaw is an out-of-bounds write that can lead to arbitrary code execution when the system processes a specially crafted file.

The vulnerability affects iOS 26. 7 and earlier versions before iOS 27, as well as iPadOS 26. 7 and earlier and supported versions of macOS Tahoe and macOS Sequoia. Apple released iOS 26.

  • 1, iPadOS 26. 7.
Read more on Security Affairs→