Apple security advisory (AV26-971)
At a glance
- Severity
- CriticalCVSS 8.8
- Used in attacks
- Yes, 1 of 1 flaw named
- Flaws named
- CVE-2026-86950
- Industries
- Government
- Reported by
- 1 outlet
As of September 28, 2026, Apple is affected by a vulnerability in the following products:
- iOS and iPadOS
- Prior to 27.0.1
- Prior to 26.7.1
- macOS Golden Gate
- Prior to 27.0.1
- macOS Tahoe
- Prior to 26.7.1
- macOS Sequoia
- Prior to 15.8.1
- watchOS
- Prior to 27.0.1
- visionOS 27
- Prior to 27.0.1
Apple has indicated that CVE-2026-86950 may have been exploited.
On September 29, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-86950 to their Known Exploited Vulnerabilities (KEV) Database.
The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.
Originally published by Canadian Centre for Cyber Security. © Canadian Centre for Cyber Security. Written by Canadian Centre for Cyber Security.
Vulnerabilities referenced
- CVE-2026-869508.8High
Apple Ipados
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
Used in attacksAdded to CISA's list 2026-09-29 · Patch or advisory available
Full record →
Fastnexa security experts
This story involves a flaw attackers are already using. Are you exposed?
A Fastnexa penetration tester can check whether CVE-2026-86950 or anything like it can be used against your websites, apps and network.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-29 12:30 UTC
Related stories
- Apple Zero-Day Vulnerability Weaponized in Targeted Attacks
Dark Reading · 2026-09-29 · exploited
- Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected
CyberScoop · 2026-09-29
- Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution
Dark Reading · 2026-09-29
- US Air Force members given over 6 years in prison for cyber theft of more than $2 million
The Record · 2026-09-29
- [Control systems] Hitachi security advisory (AV26-975)
Canadian Centre for Cyber Security · 2026-09-29