# CISA adds Apple OOB write flaw to KEV

Published: 2026-09-29 · Severity: high · Sectors: technology
Canonical: https://vorant.io/reports/777d55df-95a6-5c82-bd1f-886158817494/cisa-adds-apple-oob-write-flaw-to-kev

> CISA added CVE-2026-86950, an actively exploited out-of-bounds write vulnerability in multiple Apple products, to its Known Exploited Vulnerabilities catalog.

CISA has added CVE-2026-86950, described as an Apple Multiple Products Out-of-Bounds Write Vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation in the wild. No technical details of the exploitation chain, affected specific products/versions, or threat actor attribution were provided in this bulletin.

Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies are required to prioritize remediation of KEV-listed vulnerabilities, particularly those on publicly exposed assets that could grant an attacker total control post-exploitation, and to check for prior compromise before patching. While BOD 26-04 legally applies only to FCEB agencies, CISA recommends all organizations adopt the same risk-based prioritization for this and other KEV entries.

Defenders should identify any Apple products in their environment potentially affected by CVE-2026-86950, consult Apple's advisory for patch details and affected version ranges, and apply updates promptly given confirmed active exploitation. Organizations should also review logs for indicators of compromise predating patch deployment, consistent with BOD 26-04 guidance.

## Mentioned in this report

- Vulnerabilities: CVE-2026-86950 (KEV)

Source reporting: https://www.cisa.gov/news-events/alerts/2026/09/29/cisa-adds-one-known-exploited-vulnerability-catalog

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/777d55df-95a6-5c82-bd1f-886158817494/cisa-adds-apple-oob-write-flaw-to-kev.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
