Apple has released security updates addressing CVE-2026-86950. Users should update their devices to the latest available software versions. For iOS and iPadOS, go to Settings > General > Software Update. For macOS, use System Settings > General > Software Update. Organizations should ensure all managed devices are updated promptly. If immediate updating is not possible, exercise caution when opening files from untrusted sources, including email attachments, links, and downloads from the web.
Quick answers
What is CVE-2026-86950?
Apple has released security updates addressing CVE-2026-86950. Users should update their devices to the latest available software versions. For iOS and iPadOS, go to Settings > General > Software Update. For macOS, use System Settings > General > Software Update. Organizations should ensure all managed devices are updated promptly. If immediate updating is not possible, exercise caution when opening files from untrusted sources, including email attachments, links, and downloads from the web.
How severe is CVE-2026-86950?
high
Is CVE-2026-86950 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-86950 be mitigated?
Apple has released security updates addressing CVE-2026-86950. Users should update their devices to the latest available software versions. For iOS and iPadOS, go to Settings > General > Software Update. For macOS, use System Settings > General > Software Update. Organizations should ensure all managed devices are updated promptly. If immediate updating is not possible, exercise caution when opening files from untrusted sources, including email attachments, links, and downloads from the web.
CVSS
—
Vendor
Apple
Published
Sep 30, 2026 · 08:43
Patch
Unknown / not confirmed
Affected products
iOS, iPadOS, macOS
Mitigation
Apple has released security updates addressing CVE-2026-86950. Users should update their devices to the latest available software versions. For iOS and iPadOS, go to Settings > General > Software Update. For macOS, use System Settings > General > Software Update. Organizations should ensure all managed devices are updated promptly. If immediate updating is not possible, exercise caution when opening files from untrusted sources, including email attachments, links, and downloads from the web.
The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-86950 to its Known Exploited Vulnerabilities (KEV) Catalog. The vulnerability affects Apple Multiple Products and involves an out-of-bounds write flaw. Evidence of active exploitation has been confirmed, prompting CISA to require Federal Civilian Executive Branch agencies to prioritize rapid remediation on publicly exposed assets per Binding Operational Directive 26-04.
Apple has released security updates to address CVE-2026-86950, an out-of-bounds write vulnerability in the CoreGraphics component. The company reports the flaw may have been exploited in targeted attacks against older versions of iOS, iPadOS, and macOS. Successful exploitation could lead to arbitrary code execution in the context of the user. The updates are now available for affected devices.