Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950), (Mon, Sep 28th)

Used in attacksCriticalCVSS 8.8SANS Internet Storm Center·

At a glance

Severity
CriticalCVSS 8.8
Used in attacks
Yes, 1 of 1 flaw named
Flaws named
CVE-2026-86950
Vendors and products
AppleiOS
Reported by
1 outlet

Apple today released patches for all of its operating systems. However, only patches for older branches include a security fix. The vulnerability being addressed in iOS 26, macOS 26 and macOS 15 is already being exploited. iOS and macOS 27 are not affected. Today's update for the current "27" branch does not address security issues, but fixes some functional issues that got caught after the release two weeks ago. A 27.1 version was also expected to support the new foldable iPhone and will likely include specific features geared to the soon to be available device.

Apple credits Meta Product Security with reporting the vulnerability and states that: "Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27". 

--
Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu
Twitter|

Originally published by SANS Internet Storm Center. © SANS Internet Storm Center.

Read at isc.sans.edu ↗Established Source

Vulnerabilities referenced

  • Apple Ipados

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

    Used in attacks

    Added to CISA's list 2026-09-29 · Patch or advisory available

    Full record →

Fastnexa security experts

This story involves a flaw attackers are already using. Are you exposed?

A Fastnexa penetration tester can check whether CVE-2026-86950 or anything like it can be used against your websites, apps and network.

Book a 30-min callWhatsApp us

Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →

Coverage

One outlet has carried this so far.

  1. SANS Internet Storm Center ↗Established SourceFirst reported

    2026-09-28 22:35 UTC

Related stories