A critical out-of-bounds write vulnerability, identified as CVE-2026-86950, affecting Apple's iOS, macOS, and iPadOS operating systems, was actively exploited on the same day it was publicly disclosed. The flaw, located within the CoreGraphics component, could enable arbitrary code execution.
Apple confirmed the active exploitation of this zero-day vulnerability in targeted attacks, describing the exploitation as highly sophisticated. While the company acknowledged the issue, specific affected versions or devices were not detailed in their initial public statements.
The vulnerability was assigned CVE-2026-86950, and its CVE record was reserved on September 8, 2026. Public disclosure and the CVE publication occurred on September 28, 2026. On this same day, evidence of active exploitation was reported, with Apple itself confirming the attacks.
Multiple vulnerability tracking sources corroborated the immediate exploitation. VulnCheck KEV, a commercial research catalog, listed the vulnerability as exploited on September 28, 2026. The U.S. federal CISA Known Exploited Vulnerabilities (KEV) catalog and the European Union's ENISA EUVD both added CVE-2026-86950 to their lists on September 29, 2026. CIRCL, an aggregator, also mirrored these listings.
The CISA KEV entry for CVE-2026-86950 carries a "high" severity rating and an EPSS (Exploit Prediction Scoring System) percentile of 55.3%, indicating a moderate likelihood of exploitation. CISA issued a directive for federal agencies, requiring them to apply mitigations in accordance with vendor instructions by October 2, 2026. This includes adherence to CISA's BOD 26-04 guidance on prioritizing security updates and forensics triage requirements.
Public exploitation evidence was linked to three support articles on Apple's website, dated September 28, 2026, which likely detail the security updates addressing the vulnerability. These articles are support.apple.com/en-us/149226, support.apple.com/en-us/149228, and support.apple.com/en-us/149229.
The rapid exploitation of CVE-2026-86950 highlights the critical challenge of patching zero-day vulnerabilities, especially when attackers are prepared to weaponize them immediately upon public disclosure. Organizations are urged to apply vendor-provided patches and mitigations without delay.






