LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
CVE-2026-86950high

Apple Products Vulnerability Exploited Same Day as Disclosure

A critical out-of-bounds write vulnerability in multiple Apple products was exploited on the same day it was disclosed. Both US and EU government catalogues now list it as actively exploited.

ZeroDay News ·

Photo: Joe Ravi (Shutterstock iStock Dreamstime) (CC BY-SA 3.0) via Wikimedia Commons

A critical out-of-bounds write vulnerability, identified as CVE-2026-86950, affecting Apple's iOS, macOS, and iPadOS operating systems, was actively exploited on the same day it was publicly disclosed. The flaw, located within the CoreGraphics component, could enable arbitrary code execution.

Apple confirmed the active exploitation of this zero-day vulnerability in targeted attacks, describing the exploitation as highly sophisticated. While the company acknowledged the issue, specific affected versions or devices were not detailed in their initial public statements.

The vulnerability was assigned CVE-2026-86950, and its CVE record was reserved on September 8, 2026. Public disclosure and the CVE publication occurred on September 28, 2026. On this same day, evidence of active exploitation was reported, with Apple itself confirming the attacks.

Multiple vulnerability tracking sources corroborated the immediate exploitation. VulnCheck KEV, a commercial research catalog, listed the vulnerability as exploited on September 28, 2026. The U.S. federal CISA Known Exploited Vulnerabilities (KEV) catalog and the European Union's ENISA EUVD both added CVE-2026-86950 to their lists on September 29, 2026. CIRCL, an aggregator, also mirrored these listings.

The CISA KEV entry for CVE-2026-86950 carries a "high" severity rating and an EPSS (Exploit Prediction Scoring System) percentile of 55.3%, indicating a moderate likelihood of exploitation. CISA issued a directive for federal agencies, requiring them to apply mitigations in accordance with vendor instructions by October 2, 2026. This includes adherence to CISA's BOD 26-04 guidance on prioritizing security updates and forensics triage requirements.

Public exploitation evidence was linked to three support articles on Apple's website, dated September 28, 2026, which likely detail the security updates addressing the vulnerability. These articles are support.apple.com/en-us/149226, support.apple.com/en-us/149228, and support.apple.com/en-us/149229.

The rapid exploitation of CVE-2026-86950 highlights the critical challenge of patching zero-day vulnerabilities, especially when attackers are prepared to weaponize them immediately upon public disclosure. Organizations are urged to apply vendor-provided patches and mitigations without delay.

vulnerabilities in this storyCVE-2026-86950
vulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-88779

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Citrix has confirmed the active exploitation of a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler appliances. This new flaw reportedly emerged and was exploited just days after the company released patches for two other previously exploited vulnerabilities in the same product line.

CVE-2026-88779high

Citrix NetScaler Flaw Exploited Before CVE Publication

The CVE-2026-88779 vulnerability in Citrix NetScaler was exploited before its official publication date. A second independent catalogue now confirms exploitation.

CVE-2026-88779

Citrix patches NetScaler SAML zero-day exploited in attacks

Citrix has issued urgent security updates for a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler ADC and NetScaler Gateway appliances. The flaw, described as a memory buffer issue, has been actively exploited in targeted attacks, primarily leading to denial-of-service conditions.

patch

Three questions a hospital CISO should ask a healthcare fintech vendor

A cybersecurity expert has outlined key questions hospital CISOs should pose to healthcare fintech vendors to assess their security posture, particularly concerning patient data and financial transactions. Drew McCombs, who holds both CTO and CISO roles at Cylerity, emphasizes that security should be an integral part of development processes, not an afterthought, especially when patient data…

cloud

Keyorix: Open-source secrets management for teams that can’t use SaaS

Keyorix, an open-source secrets management solution, has been released, offering an on-premises alternative for organizations unable to utilize cloud-based services for credential storage. The system is designed to run entirely on a company's own infrastructure, with its core functionality requiring no internet connection.

security

How RMM abuse gives attackers a way in that looks like business as usual

Attackers are increasingly leveraging legitimate remote monitoring and management (RMM) software to gain persistent access to victim systems, a tactic observed in 45% of endpoint-related incidents recorded by security firm Huntress in the first quarter of 2026. This method allows attackers to execute commands remotely and maintain access in a way that often appears to be normal administrative…