• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-86950: remote arbitrary code execution in Apple Multiple Products

Attackers can execute arbitrary code on Apple iPhone, iPad, and Mac devices by processing a maliciously crafted file; this is tracked as CVE-2026-86950. Affected releases include iOS and iPadOS before 26.7.1 and macOS Sequoia/Tahoe before 15.8.1 and 26.7.1. Exploitation requires delivering and having the target process the malicious file (user interaction is required), not an authenticated session.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
8.8HIGH
EPSS
0.00812
CWE
CWE-787
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent: CISA put this issue on its Known Exploited Vulnerabilities list with a rapid remediation deadline, and public exploit code exists — update affected Apple devices to the listed fixes immediately or apply vendor mitigations.

What is CVE-2026-86950?

Attackers can execute arbitrary code on Apple iPhone, iPad, and Mac devices by processing a maliciously crafted file; this is tracked as CVE-2026-86950. Affected releases include iOS and iPadOS before 26.7.1 and macOS Sequoia/Tahoe before 15.8.1 and 26.7.1. Exploitation requires delivering and having the target process the malicious file (user interaction is required), not an authenticated session. The weakness is classified as CWE-787 (Out-of-bounds Write).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Which versions of Apple Multiple Products are affected?

BRANCHAFFECTEDFIXED
iOS and iPadOS 26.xbefore 26.7.126.7.1
macOS 15.xbefore 15.8.115.8.1
macOS 26.xbefore 26.7.126.7.1

Is CVE-2026-86950 being exploited?

CISA added CVE-2026-86950 to the Known Exploited Vulnerabilities catalog on 2026-09-29; US federal agencies must remediate by 2026-10-02. Public exploit code for this vulnerability is available.

How to fix CVE-2026-86950

  1. Install the vendor fixes: update iOS and iPadOS to 26.7.1 and macOS to 15.8.1 / 26.7.1 as applicable.
  2. If immediate patching is not possible, follow Apple’s mitigation guidance and restrict file processing from untrusted sources.
  3. Limit exposure by blocking or filtering untrusted file types at perimeter controls and email gateways.
  4. Monitor endpoints and logs for abnormal crashes or indications of code execution and follow incident response procedures.

Frequently asked questions

Is CVE-2026-86950 being actively exploited?

Yes; CISA added CVE-2026-86950 to its Known Exploited Vulnerabilities catalog on 2026-09-29 and public exploit code is available, increasing the likelihood of active exploitation against Apple devices.

Which Apple versions are affected by CVE-2026-86950?

Apple devices running iOS and iPadOS before 26.7.1 and macOS Sequoia/Tahoe releases before 15.8.1 and 26.7.1 are listed as affected.

Is there a patch for CVE-2026-86950?

Yes; Apple released fixes for this CoreGraphics out-of-bounds write in iOS/iPadOS 26.7.1 and macOS 15.8.1 and 26.7.1.

Does CVE-2026-86950 require authentication?

No authentication is required to exploit this flaw on Apple iOS, iPadOS, and macOS; an attacker needs the target to process a crafted file, which typically involves user interaction.

References