DIRAS TAKE
Urgent: CISA put this issue on its Known Exploited Vulnerabilities list with a rapid remediation deadline, and public exploit code exists — update affected Apple devices to the listed fixes immediately or apply vendor mitigations.
What is CVE-2026-86950?
Attackers can execute arbitrary code on Apple iPhone, iPad, and Mac devices by processing a maliciously crafted file; this is tracked as CVE-2026-86950. Affected releases include iOS and iPadOS before 26.7.1 and macOS Sequoia/Tahoe before 15.8.1 and 26.7.1. Exploitation requires delivering and having the target process the malicious file (user interaction is required), not an authenticated session. The weakness is classified as CWE-787 (Out-of-bounds Write).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Which versions of Apple Multiple Products are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| iOS and iPadOS 26.x | before 26.7.1 | 26.7.1 |
| macOS 15.x | before 15.8.1 | 15.8.1 |
| macOS 26.x | before 26.7.1 | 26.7.1 |
Is CVE-2026-86950 being exploited?
CISA added CVE-2026-86950 to the Known Exploited Vulnerabilities catalog on 2026-09-29; US federal agencies must remediate by 2026-10-02. Public exploit code for this vulnerability is available.
How to fix CVE-2026-86950
- Install the vendor fixes: update iOS and iPadOS to 26.7.1 and macOS to 15.8.1 / 26.7.1 as applicable.
- If immediate patching is not possible, follow Apple’s mitigation guidance and restrict file processing from untrusted sources.
- Limit exposure by blocking or filtering untrusted file types at perimeter controls and email gateways.
- Monitor endpoints and logs for abnormal crashes or indications of code execution and follow incident response procedures.
Frequently asked questions
Is CVE-2026-86950 being actively exploited?
Yes; CISA added CVE-2026-86950 to its Known Exploited Vulnerabilities catalog on 2026-09-29 and public exploit code is available, increasing the likelihood of active exploitation against Apple devices.
Which Apple versions are affected by CVE-2026-86950?
Apple devices running iOS and iPadOS before 26.7.1 and macOS Sequoia/Tahoe releases before 15.8.1 and 26.7.1 are listed as affected.
Is there a patch for CVE-2026-86950?
Yes; Apple released fixes for this CoreGraphics out-of-bounds write in iOS/iPadOS 26.7.1 and macOS 15.8.1 and 26.7.1.
Does CVE-2026-86950 require authentication?
No authentication is required to exploit this flaw on Apple iOS, iPadOS, and macOS; an attacker needs the target to process a crafted file, which typically involves user interaction.
References
- nvd.nist.gov/vuln/detail/CVE-2026-86950
- cve.org/CVERecord?id=CVE-2026-86950
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86950
- support.apple.com/en-us/149226
- support.apple.com/en-us/149228
- support.apple.com/en-us/149229
- All Apple CVEs on CVE Radar
- CVEs published in September 2026