Apple has released security updates for older versions of iOS, iPadOS, and macOS to address a critical vulnerability tracked as CVE-2026-86950. The flaw affects the CoreGraphics component and is caused by an out of bounds write that could allow arbitrary code execution when processing a specially crafted file. Apple fixed the issue through improved bounds checking and credited Meta Product Security for reporting the vulnerability. Apple stated that the vulnerability may have been exploited in a highly sophisticated targeted attack against individuals using iOS versions earlier than iOS 27. The company has not disclosed details about the number of targeted users, successful exploitation attempts, or when the attacks began. The vulnerability has been addressed in iOS 26.7.1 and iPadOS 26.7.1, covering supported iPhone and iPad models, along with macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. Users and organizations running affected Apple devices are advised to install the latest security updates as soon as possible to reduce the risk of exploitation. Administrators should verify that supported systems have received the appropriate patches and monitor for suspicious activity involving malicious files. The disclosure follows Apple's earlier remediation of CVE-2026-20700, a memory corruption vulnerability in dyld that was also reported as being exploited in sophisticated attacks.
A newly demonstrated security flaw in LibreOffice and Apache OpenOffice shows how seemingly legitimate spreadsheet features can be combined to execute malicious code without the us...
Four vulnerabilities disclosed in Apache Struts could expose affected applications to remote code execution, denial of service, resource exhaustion, and cross-user data disclosure....
Atlassian has disclosed a critical arbitrary file access vulnerability, CVE-2026-21589, affecting Jira Software Data Center and Confluence Data Center. Rated CVSS 9.3, the flaw all...