## Overview
CISA added CVE-2026-86950 to its Known Exploited Vulnerabilities (KEV) catalog on September 29, 2026. This vulnerability affects multiple Apple products, including iOS, iPadOS, and macOS. The addition to the KEV list indicates a federal deadline for mitigation due to evidence of exploitation.
## Technical Details
The vulnerability is an out-of-bounds write issue in CoreGraphics. It allows attackers to process a maliciously crafted file, potentially leading to arbitrary code execution. Apple has fixed this issue in the following updates: iOS 26.7.1, iPadOS 26.7.1, macOS Sequoia 15.8.1, and macOS Tahoe 26.7.1. Reports suggest that this vulnerability may have been exploited in targeted attacks against specific individuals using earlier versions of iOS.
## Impact
Successful exploitation of CVE-2026-86950 can lead to arbitrary code execution on affected devices. This could allow attackers to gain control over the device, access sensitive data, or deploy additional malicious software. The high CVSS score of 8.8 underscores the severity of this vulnerability.
## Mitigation
Defenders should prioritize applying the latest updates from Apple to mitigate this vulnerability. Users should upgrade to iOS 26.7.1, iPadOS 26.7.1, macOS Sequoia 15.8.1, or macOS Tahoe 26.7.1 as soon as possible. Regularly check for software updates and ensure that all devices are running the latest security patches.
CSURFACE Threat Sensor