Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950), (Mon, Sep 28th)
At a glance
- Severity
- CriticalCVSS 8.8
- Used in attacks
- Yes, 1 of 1 flaw named
- Flaws named
- CVE-2026-86950
- Reported by
- 1 outlet
Apple today released patches for all of its operating systems. However, only patches for older branches include a security fix. The vulnerability being addressed in iOS 26, macOS 26 and macOS 15 is already being exploited. iOS and macOS 27 are not affected. Today's update for the current "27" branch does not address security issues, but fixes some functional issues that got caught after the release two weeks ago. A 27.1 version was also expected to support the new foldable iPhone and will likely include specific features geared to the soon to be available device.
Apple credits Meta Product Security with reporting the vulnerability and states that: "Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27".
--
Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu
Twitter|
Originally published by SANS Internet Storm Center. © SANS Internet Storm Center.
Vulnerabilities referenced
- CVE-2026-869508.8High
Apple Ipados
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
Used in attacksAdded to CISA's list 2026-09-29 · Patch or advisory available
Full record →
Fastnexa security experts
This story involves a flaw attackers are already using. Are you exposed?
A Fastnexa penetration tester can check whether CVE-2026-86950 or anything like it can be used against your websites, apps and network.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-28 22:35 UTC
Related stories
- ISC Stormcast For Wednesday, September 30th, 2026 https://isc.sans.edu/podcastdetail/10116, (Wed, Sep 30th)
SANS Internet Storm Center · 2026-09-30
- Apple Zero-Day Vulnerability Weaponized in Targeted Attacks
Dark Reading · 2026-09-29 · exploited
- Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected
CyberScoop · 2026-09-29
- Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution
Dark Reading · 2026-09-29
- US Air Force members given over 6 years in prison for cyber theft of more than $2 million
The Record · 2026-09-29