Yesterday Apple released iOS 26.7.1 and iPadOS 26.7.1 (iPhone 11 and later; the iPad list is on Apple’s page), macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. The flaw is CVE-2026-86950. Apple credits Meta Product Security. Apple’s note, the same on each of those pages: processing a maliciously crafted file may lead to arbitrary code execution, and Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27. CISA added it to the Known Exploited Vulnerabilities catalog this morning. Federal agencies are due Friday, Oct 2.

What to do: if you use an iPhone, iPad, or a Mac on Tahoe or Sequoia, install the update today. Don’t wait for it to show up on its own. Apple’s sentence is a report about specific targeted individuals, not a count of victims, and these notes name no attacker.

One more item, for shops running AI tools. Cycode disclosed yesterday that if those tools are built on the official Python MCP library and they log into other services, update to 1.30.0 or 2.2.0 and change those login secrets.