{"id":403,"date":"2026-10-06T12:05:10","date_gmt":"2026-10-06T12:05:10","guid":{"rendered":"https:\/\/managedt.com\/blog\/cisa-adds-apple-out-of-bounds-write-vulnerability-kev-catalog\/"},"modified":"2026-10-09T02:41:23","modified_gmt":"2026-10-09T02:41:23","slug":"cisa-adds-apple-out-of-bounds-write-vulnerability-kev-catalog","status":"publish","type":"post","link":"https:\/\/managedt.com\/blog\/cisa-adds-apple-out-of-bounds-write-vulnerability-kev-catalog\/","title":{"rendered":"CISA Adds Apple Out-of-Bounds Write Vulnerability to KEV Catalog"},"content":{"rendered":"<p>CISA added one new vulnerability, CVE-2026-86950, an out-of-bounds write affecting multiple Apple products, to the Known Exploited Vulnerabilities (KEV) Catalog on September 29, 2026, citing evidence of active exploitation. Federal civilian agencies are required to act on KEV entries quickly under Binding Operational Directive 26-04, and CISA is encouraging every organization that runs Apple software to follow the same risk-based approach.<\/p>\n<h2>What was added to the KEV Catalog?<\/h2>\n<p>The new entry is CVE-2026-86950, an out-of-bounds write vulnerability that affects multiple Apple products. An out-of-bounds write is a class of memory error where a program writes past the boundary of an allocated buffer, and that class of bug has long been a reliable foothold for attackers who want to take over a device or process.<\/p>\n<p>CISA flagged it as a frequent attack vector and a meaningful risk to the federal enterprise, which is what moves a vulnerability onto the catalog and turns it into something agencies have to fix on a deadline.<\/p>\n<h2>Why this listing triggers federal action<\/h2>\n<p>Binding Operational Directive 26-04, titled Prioritizing Security Updates Based on Risk, sets out vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. The directive ties the KEV Catalog to remediation timing in two specific ways:<\/p>\n<ul>\n<li>Agencies must prioritize rapid remediation of high-risk vulnerabilities, specifically CVEs listed in CISA&#8217;s KEV Catalog that sit on publicly exposed assets and that grant total control of the asset after exploitation. Lower-risk items can be deferred.<\/li>\n<li>Agencies must check whether threat actors compromised the system before any patch is applied.<\/li>\n<\/ul>\n<p>BOD 26-04 applies only to FCEB agencies, but CISA&#8217;s standing guidance is that every organization should adopt risk-based vulnerability management and prioritize remediation of KEV Catalog entries.<\/p>\n<h2>How to respond if your environment runs Apple software<\/h2>\n<p>Patch the affected Apple products against CVE-2026-86950 as soon as the vendor-fixed build is available in your support channel, then verify the install on every publicly exposed device that matches the CVE&#8217;s scope. After patching, run compromise assessment steps on any internet-facing system where the vulnerable build was live before the update went on, because BOD 26-04 treats that kind of pre-patch review as the minimum bar for high-risk KEV items. Organizations outside the federal government that want to track which devices still need the update can pull the Apple advisory for CVE-2026-86950 and cross-check it against their asset inventory before the next exposure scan.<\/p>\n<h2>How a vulnerability gets nominated for the KEV Catalog<\/h2>\n<p>CISA adds vulnerabilities to the KEV Catalog when they meet the catalog&#8217;s criteria, and the agency also accepts outside submissions through the KEV Nomination Form. For a candidate to be considered, three things are required:<\/p>\n<ul>\n<li>A CVE ID.<\/li>\n<li>Evidence of exploitation in the wild.<\/li>\n<li>Clear mitigation guidance that defenders can act on.<\/li>\n<\/ul>\n<p>Submissions without all three are set aside. The form is the direct channel for security teams that have spotted a working exploit chain that is not yet listed.<\/p>\n<h2>FAQ<\/h2>\n<h3>What vulnerability did CISA add to the KEV Catalog on September 29, 2026?<\/h3>\n<p>CISA added CVE-2026-86950, an out-of-bounds write vulnerability affecting multiple Apple products, based on evidence of active exploitation.<\/p>\n<h3>Does the KEV Catalog listing require my organization to patch?<\/h3>\n<p>Binding Operational Directive 26-04 requires Federal Civilian Executive Branch agencies to prioritize remediation of KEV Catalog vulnerabilities on publicly exposed assets. CISA encourages all other organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities as well.<\/p>\n<h3>How can a vulnerability be nominated for the KEV Catalog?<\/h3>\n<p>Submissions are filed through CISA&#8217;s KEV Nomination Form and must include a CVE ID, evidence of exploitation, and clear mitigation guidance.<\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What vulnerability did CISA add to the KEV Catalog on September 29, 2026?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"CISA added CVE-2026-86950, an out-of-bounds write vulnerability affecting multiple Apple products, based on evidence of active exploitation.\"}},{\"@type\":\"Question\",\"name\":\"Does the KEV Catalog listing require my organization to patch?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Binding Operational Directive 26-04 requires Federal Civilian Executive Branch agencies to prioritize remediation of KEV Catalog vulnerabilities on publicly exposed assets. CISA encourages all other organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities as well.\"}},{\"@type\":\"Question\",\"name\":\"How can a vulnerability be nominated for the KEV Catalog?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Submissions are filed through CISA's KEV Nomination Form and must include a CVE ID, evidence of exploitation, and clear mitigation guidance.\"}}]}]}<\/script><\/p>\n<hr style=\"margin:2.5em 0 1em;opacity:.35\" \/>\n<p style=\"font-size:.85em;opacity:.7\">This article summarizes reporting from <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/09\/29\/cisa-adds-one-known-exploited-vulnerability-catalog\" target=\"_blank\" rel=\"nofollow noopener\">cisa.gov<\/a>.<\/p>\n<p><!-- seo-pro:slop-fixed --><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CISA added one Apple vulnerability, CVE-2026-86950, to the Known Exploited Vulnerabilities Catalog on September 29, 2026.<\/p>\n","protected":false},"author":3,"featured_media":402,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-403","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/403","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/comments?post=403"}],"version-history":[{"count":2,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/403\/revisions"}],"predecessor-version":[{"id":489,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/403\/revisions\/489"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media\/402"}],"wp:attachment":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media?parent=403"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/categories?post=403"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/tags?post=403"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}