LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
cve recordhighexploited in the wildzero day3 of 3 cataloguesexploit reported

CVE-2026-86950

Apple · Multiple Products · Apple Multiple Products Out-of-Bounds Write Vulnerability

· Added to CISA KEV
CVSS—
Severityhigh
Weakness—
EPSS1.2%68.2th percentile
Exploited3 KEV sources
Ransomware useUnknown
Federal fix dueOct 2, 2026
patch window

Called exploited the same day it was disclosed.

Measured from the CVE publication date to the earliest of 3 KEV catalogues that list it.

The life of this vulnerability

  1. CVE reserved
  2. CVE published20d
  3. First KEV listingsame day
  4. Last KEV listing1d
  5. Last sighting1d

Gaps are compressed to equal steps. The elapsed time is printed under each.

Which catalogues call it exploited

Sources3 of 3
Listings differ by1 d
Strongest claimconfirmed

3 catalogues list it. CIRCL aggregates the others and is shown but not counted.

Public exploitation evidence

3 public reports collected from VulnCheck and CIRCL, first on Sep 28, 2026. Each links to its original source. We have not verified them.

Description

Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.

Required action (CISA)

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-86950

CVE-2026-88771critical

Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploited

A 16-year-old security researcher has identified a vulnerability in Microsoft's internal analytics service, Titan, which could have exposed employee records and Bing search analytics. The flaw reportedly provided access to 17 trillion rows of data. Microsoft has not yet issued a public statement confirming the details of the vulnerability or its remediation.

CVE-2026-86950high

Apple Products Vulnerability Exploited Same Day as Disclosure

A critical out-of-bounds write vulnerability in multiple Apple products was exploited on the same day it was disclosed. Both US and EU government catalogues now list it as actively exploited.

CVE-2026-86950

Apple Zero-Day Vulnerability Weaponized in Targeted Attacks

Apple has reported that a zero-day vulnerability, identified as CVE-2026-86950, is actively being exploited in targeted attacks. The company described the exploitation as highly sophisticated, indicating a significant level of attacker capability. This out-of-bounds write flaw affects Apple products, though specific affected versions or devices were not detailed in the announcement.