DIRAS TAKE
Urgently install Apple’s updates: fixes are available for iOS/iPadOS (26.7 and 27) and other Apple platforms. Treat exposed TLS services and systems that trust external CAs as high priority because a compromised intermediate CA can enable broad impersonation.
What is CVE-2026-86881?
An attacker who controls or has compromised an intermediate certificate authority can issue forged certificates that iOS and iPadOS may accept, allowing impersonation of services or interception of TLS connections, tracked as CVE-2026-86881. Affected releases include iOS and iPadOS before 26.7 and before 27 (fixed in 26.7 and 27), and related Apple platforms listed below; an attacker needs control of an intermediate CA to exploit this certificate validation flaw. The issue stems from improper certificate validation that permits certificates with arbitrary extended key usages. The weakness is classified as CWE-295 (Improper Certificate Validation).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Which versions of Apple iOS and iPadOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| iOS and iPadOS 26.x | before 26.7 | 26.7 |
| iOS and iPadOS 27.x | before 27 | 27 |
| macOS 15.x | before 15.8 | 15.8 |
| macOS 26.x | before 26.7 | 26.7 |
| macOS 27.x | before 27 | 27 |
| tvOS 27.x | before 27 | 27 |
| visionOS 27.x | before 27 | 27 |
| watchOS 27.x | before 27 | 27 |
Is CVE-2026-86881 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-86881
- Apply Apple’s fixes: update iOS/iPadOS to 26.7 or 27 and other affected platforms to the fixed releases listed by Apple (see affected fixed versions).
- Restrict trust: limit trusted intermediate CAs and remove any unnecessary external intermediates from device trust stores.
- Monitor: check TLS certificate chains your devices accept and look for unexpected intermediate CAs or certificates with unusual extended key usages.
- Follow vendor guidance: apply any additional mitigations Apple publishes alongside these updates.
Frequently asked questions
Is CVE-2026-86881 being actively exploited?
There are no public reports of active exploitation of CVE-2026-86881 as of 2026-09-30.
Which iOS and iPadOS versions are affected by CVE-2026-86881?
iOS and iPadOS releases before 26.7 and before 27 are affected; Apple lists fixes in 26.7 and 27.
Is there a patch for CVE-2026-86881?
Yes. Apple published fixes: iOS and iPadOS fixed in 26.7 and 27, and corresponding fixed releases for macOS, tvOS, visionOS, and watchOS are available.
Does CVE-2026-86881 require authentication?
No authentication on the device is required; exploitation relies on an attacker controlling or compromising an intermediate certificate authority, not on user login.
References
- nvd.nist.gov/vuln/detail/CVE-2026-86881
- cve.org/CVERecord?id=CVE-2026-86881
- support.apple.com/en-us/149034
- support.apple.com/en-us/149035
- support.apple.com/en-us/149036
- support.apple.com/en-us/149037
- support.apple.com/en-us/149038
- support.apple.com/en-us/149041
- support.apple.com/en-us/149042
- support.apple.com/en-us/149043
- All Apple CVEs on CVE Radar
- CVEs published in September 2026