Apple Zero-Day Vulnerability Weaponized in Targeted Attacks
At a glance
- Severity
- CriticalCVSS 8.8
- Used in attacks
- Yes, 1 of 1 flaw named
- Flaws named
- CVE-2026-86950
- Vendors and products
- Apple
- Reported by
- 1 outlet
Attackers are exploiting CVE-2026-86950, an out-of-bounds write flaw, in an extremely sophisticated fashion, according to Apple.
We summarise and link; this source is not one we hold a licence to reproduce. Everything below is what CyberBrief adds: the vulnerabilities involved, whether they are being exploited, who is named, and who else covered it.
Vulnerabilities referenced
- CVE-2026-869508.8High
Apple Ipados
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
Used in attacksAdded to CISA's list 2026-09-29 · Patch or advisory available
Full record →
Fastnexa security experts
This story involves a flaw attackers are already using. Are you exposed?
A Fastnexa penetration tester can check whether CVE-2026-86950 or anything like it can be used against your websites, apps and network.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-29 21:31 UTC
Related stories
- Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected
CyberScoop · 2026-09-29
- Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution
Dark Reading · 2026-09-29
- US Air Force members given over 6 years in prison for cyber theft of more than $2 million
The Record · 2026-09-29
- [Control systems] Hitachi security advisory (AV26-975)
Canadian Centre for Cyber Security · 2026-09-29
- TeamViewer security advisory (AV26-977)
Canadian Centre for Cyber Security · 2026-09-29