• PATCH AVAILABLE

CVE-2026-86881: certificate validation bypass in Apple iOS and iPadOS

An attacker who controls or has compromised an intermediate certificate authority can issue forged certificates that iOS and iPadOS may accept, allowing impersonation of services or interception of TLS connections, tracked as CVE-2026-86881. Affected releases include iOS and iPadOS before 26.7 and before 27 (fixed in 26.7 and 27), and related Apple platforms listed below; an attacker needs control of an intermediate CA to exploit this certificate validation flaw. The issue stems from improper certificate validation that permits certificates with arbitrary extended key usages.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.1CRITICAL
EPSS
0.00398
CWE
CWE-295
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgently install Apple’s updates: fixes are available for iOS/iPadOS (26.7 and 27) and other Apple platforms. Treat exposed TLS services and systems that trust external CAs as high priority because a compromised intermediate CA can enable broad impersonation.

What is CVE-2026-86881?

An attacker who controls or has compromised an intermediate certificate authority can issue forged certificates that iOS and iPadOS may accept, allowing impersonation of services or interception of TLS connections, tracked as CVE-2026-86881. Affected releases include iOS and iPadOS before 26.7 and before 27 (fixed in 26.7 and 27), and related Apple platforms listed below; an attacker needs control of an intermediate CA to exploit this certificate validation flaw. The issue stems from improper certificate validation that permits certificates with arbitrary extended key usages. The weakness is classified as CWE-295 (Improper Certificate Validation).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Which versions of Apple iOS and iPadOS are affected?

BRANCHAFFECTEDFIXED
iOS and iPadOS 26.xbefore 26.726.7
iOS and iPadOS 27.xbefore 2727
macOS 15.xbefore 15.815.8
macOS 26.xbefore 26.726.7
macOS 27.xbefore 2727
tvOS 27.xbefore 2727
visionOS 27.xbefore 2727
watchOS 27.xbefore 2727

Is CVE-2026-86881 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-86881

  1. Apply Apple’s fixes: update iOS/iPadOS to 26.7 or 27 and other affected platforms to the fixed releases listed by Apple (see affected fixed versions).
  2. Restrict trust: limit trusted intermediate CAs and remove any unnecessary external intermediates from device trust stores.
  3. Monitor: check TLS certificate chains your devices accept and look for unexpected intermediate CAs or certificates with unusual extended key usages.
  4. Follow vendor guidance: apply any additional mitigations Apple publishes alongside these updates.

Frequently asked questions

Is CVE-2026-86881 being actively exploited?

There are no public reports of active exploitation of CVE-2026-86881 as of 2026-09-30.

Which iOS and iPadOS versions are affected by CVE-2026-86881?

iOS and iPadOS releases before 26.7 and before 27 are affected; Apple lists fixes in 26.7 and 27.

Is there a patch for CVE-2026-86881?

Yes. Apple published fixes: iOS and iPadOS fixed in 26.7 and 27, and corresponding fixed releases for macOS, tvOS, visionOS, and watchOS are available.

Does CVE-2026-86881 require authentication?

No authentication on the device is required; exploitation relies on an attacker controlling or compromising an intermediate certificate authority, not on user login.

References