I read the CISA alert dated September 29, 2026. They added one entry to the Known Exploited Vulnerabilities catalog.

The entry is CVE-2026-86950. It names Apple, more than one product, and an out-of-bounds write. CISA says it has evidence the bug is already being used.

The binding order in that alert is for federal civilian agencies. I still read the vendor update if I have an Apple device on the version they flagged. I am not copying the directive.

Source I used: CISA Advisories. The link is under this column.