CVE-2026-86950がCISA KEVに追加 — Apple Multiple ProductsのCVE-2026-86950
CISA(米サイバーセキュリティ・インフラセキュリティ庁)のKnown Exploited Vulnerabilities(KEV)カタログに、2026-09-29付けで1件のCVEが新規追加された。KEVは実際の悪用が確認された脆弱性のみを掲載するリストであり、追加された時点で攻撃者による悪用が現に進行している可能性が高い。
CVE-2026-86950 — Apple Multiple Products
脆弱性名: CVE-2026-86950
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
| 項目 | 内容 |
|---|---|
| ベンダー/製品 | Apple / Multiple Products |
| 対応期限(CISA) | 2026-10-02 |
| ランサムウェア悪用 | Unknown |
| 詳細 | NVD: CVE-2026-86950 |
※本記事はCISA KEVの公開データをもとに機械的に生成している。対応要否は各組織の環境に応じて判断すること。