Skip to content
High-Risk Remote Code Execution Vulnerability in Apple Products

High-Risk Remote Code Execution Vulnerability in Apple Products

First seen 29 Sep 2026, 15:40 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 16:22 UTC
  • •CVE-2026-86950 allows remote code execution on affected Apple devices.
  • •Exploitation has been confirmed against targeted individuals using outdated iOS versions.
  • •Patches for affected systems were released on 2026-09-29; immediate application is recommended.

A critical vulnerability, CVE-2026-86950, has been identified in Apple products, allowing remote code execution via maliciously crafted files. This issue affects versions of iOS prior to 26.7.1, iPadOS prior to 26.7.1, macOS Sequoia prior to 15.8.1, and macOS Tahoe prior to 26.7.1. Apple has acknowledged that this vulnerability may have been exploited in sophisticated attacks against targeted individuals. The risk level is rated as high due to the potential for arbitrary code execution, which could lead to data theft or further compromises. Users are advised to apply the patches released on 2026-09-29 promptly. The vulnerability was added to the CISA KEV list on the same day, indicating active exploitation. Organizations with large Apple device fleets are particularly at risk, especially those handling sensitive information.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-28
CVE-2026-86950 published
Apple disclosed a critical vulnerability affecting multiple versions of its operating systems.
Redpacketsecurity
2026-09-29
CISA KEV listing
CVE-2026-86950 was added to the CISA KEV catalog, indicating active exploitation in the wild.
Hkcert
2026-09-29
Patches released
Apple released updates for iOS, iPadOS, and macOS to address the vulnerability.
Hkcert

More articles in this cluster (3)

Following this threat?

Track Apple and CVE-2026-86950 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed