Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🛡️
CISA KEV · ACTIVELY EXPLOITED
HIGH severity

CVE-2026-86950 — IPADOS

HIGH

CVE-2026-86950 is a high-severity (CVSS 8.8) Out-of-bounds Write vulnerability in apple ipados. It is in CISA's Known Exploited Vulnerabilities catalog (added 2026-09-29) — treat it as actively exploited and patch now. A fix is available — see the affected versions and patch details below.

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a…

Published
Sep 28, 2026
Updated
Sep 30, 2026
Affected
3 products
Patched
See advisory
Exploits
None indexed
Exploitation data as of Sep 30, 2026 · OSV.dev, NVD, CISA KEV, FIRST.org (EPSS)

Exploitation Status

Actively exploited in the wild

  • Confirmed by CISA's Known Exploited Vulnerabilities catalog on 2026-09-29. Federal agencies were required to remediate by 2026-10-02.
  • A successful exploit gives an attacker total control of the affected component, not partial access.

Exploitation and automatability from CISA (KEV catalog and SSVC triage) for CVE-2026-86950.

EPSS Exploitation Probability

via FIRST.org ↗
1.2%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs68th percentile — riskier than 68% of all scored CVEsHighest risk

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

How urgent is this, really

CVE-2026-86950 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.

Where this sits among everything scored

Of 380,526 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.

Description

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

Affected Products

3 products · 4 configurations
OS
ipadosapple
< 26.7.1
range
OS
iphone osapple
< 26.7.1
range
OS
macosapple
≥ 26.0 && < 26.7.1
range

Detection & mitigation playbook

Vendor / appliance
  1. Detect

    Inventory every apple ipados deployment and check each version against the affected-products list above.

  2. Fix

    Apply the apple ipados security patch or hotfix for CVE-2026-86950 on the affected version, following the vendor advisory for your exact build.

  3. Workarounds

    Stop feeding it untrusted input: reject or quarantine files and payloads from unverified sources until you can upgrade, restrict accepted formats to the ones you actually need, and run the parsing or decoding step in a least-privileged sandbox or short-lived worker so a crash or corrupted read cannot reach the rest of the process. Alongside that, restrict the management interface to trusted networks and apply the vendor's recommended configuration mitigations.

Frequently Asked Questions

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
O3 Security · Runtime Protection

Is CVE-2026-86950 being exploited in your environment?

Detect and block the exploit chain at execution, on systems you cannot patch yet.

CVE-2026-86950: Memory Corruption (KEV) | O3 Security