CISA Flags Actively Exploited Apple Vulnerability, Urges Quick Patching
CISA has added CVE-2026-86950, an out-of-bounds write vulnerability affecting multiple Apple products, to its Known Exploited Vulnerabilities (KEV) Catalog. This addition means there is evidence attackers are actively exploiting the flaw, which could allow them to compromise affected devices.
While the associated directive requiring urgent patching applies only to US federal agencies, CISA recommends that all organisations, including small and medium businesses, adopt the same risk based approach: prioritise fixing vulnerabilities that are known to be under active attack, especially on internet facing devices.
Australian businesses using Apple devices such as iPhones, iPads, or Macs for work should ensure these are updated as soon as Apple releases a security fix for this issue, and should check whether devices show signs of compromise if updates were delayed.