CVE-2026-86950: listed in the CISA KEV catalog

CVE-2026-86950 · CVSS 8.8 HIGH · KEV 2026-09-29 · patch available

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

Is CVE-2026-86950 exploited?

Which products and versions are affected?

Is there a patch?

What PlainSec published about CVE-2026-86950

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-09-29.