VORANT. Threat Intelligence Research Sign in Create a free account

Apple patches actively exploited zero-day CVE-2026-86950

high vulnerability technology

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

CERT-FR warns of an actively exploited Apple vulnerability allowing remote code execution across iOS, iPadOS, and macOS; patch immediately.

CERT-FR issued an advisory regarding CVE-2026-86950, a vulnerability affecting multiple Apple operating systems that allows an attacker to achieve remote code execution. Apple has confirmed that this vulnerability is being actively exploited in the wild, making it a priority for patching across affected fleets.

Affected systems include iOS and iPadOS prior to version 26.7.1, macOS Sequoia prior to 15.8.1, and macOS Tahoe prior to 26.7.1. Apple released fixes via three separate security bulletins (149226, 149228, 149229) dated September 28, 2026. No technical details on the exploitation vector or attacker objectives beyond code execution were disclosed in this advisory.

Defenders managing Apple device fleets—particularly iOS/iPadOS mobile devices and macOS endpoints—should prioritize deployment of the referenced updates given the confirmed active exploitation. Given the lack of further detail from CERT-FR, organizations should monitor Apple's own security bulletins for any updates on exploitation indicators or additional context.

Mentioned in this report

Vulnerabilities CVE-2026-86950KEV

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1236

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 11,316 reports from 152 sources, 2,734 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs