Skip to content
RegionAmericas

MediumII Cyber Warfare & Critical Infrastructure29 September 2026, Tuesday

Apple CoreGraphics flaw exploited as a zero-day, CISA adds it to catalogue

On 28 September Apple fixed the CVE-2026-86950 flaw with the iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 updates. The US Cybersecurity and Infrastructure Security Agency (CISA) added it to its catalogue of exploited vulnerabilities on 29 September.

Location: CUPERTINO

Apple's security releases page shows the iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 updates were published on 28 September 2026. BleepingComputer reported on 29 September that CVE-2026-86950 is an out-of-bounds write in CoreGraphics, the graphics rendering framework. In other words, the program can write data outside the memory area allocated to it. The bug can lead to arbitrary code execution on a device when 1 malicious file is opened. Apple said it was aware of 1 report that the flaw may have been exploited in an "extremely sophisticated attack". Meta's product security team found the flaw; affected devices include iPhone 11 and later and iPad 8th generation and later.

CISA's Known Exploited Vulnerabilities (KEV) catalogue lists flaws proven to have been used in attacks and obliges federal agencies to patch them. The catalogue records CVE-2026-86950 for multiple Apple products under the date of 29 September. In the 6 days from 24 to 29 September, the same catalogue took in a total of 8 flaws in Apple, Citrix, WordPress, Microsoft, MikroTik, Adobe and WSO2 products. According to BleepingComputer, this is the 2nd exploited zero-day Apple has fixed in 2026; the first was CVE-2026-20700 in the dyld component in February. The exact patch deadline for federal agencies and the targets of the attack could not be verified, as neither source states them clearly.

Talay assessment

Bottom line

Apple's 2nd exploited zero-day of 2026 is a code execution flaw that can be triggered by opening a file, which makes it a valuable tool in targeted attacks. CISA adding the flaw to its catalogue within a day creates pressure for rapid patching on federal networks. The scale of spread is unclear because the targets have not been disclosed. The most likely path is that use against a limited number of targets is closed off by the patch.

Likely effects

  • Enterprise device managementNegativeWeeks

    Organisations managing iPhone 11 and later and current Macs must roll out the 28 September updates quickly; delay leaves open the risk of compromise through a malicious file.

  • Targeted spywareNegativeWeeks

    CoreGraphics flaws triggered by file processing are typically used as the first link in targeted attack chains against journalists, executives and officials.

  • TürkiyeUncertainWeeks

    Organisations in Türkiye running iOS and macOS in public and corporate fleets need the same update; the flaw is platform-wide, so there is no geographic boundary.

Possibilities, ranked

  1. 1
    Closed by the patch60%

    The updates spread quickly, and the flaw is reported as having stayed confined to a limited number of targets.

    Watch: Whether Apple and CISA issue further exploitation notices

  2. 2
    Attack chain comes to light30%

    Security researchers show that the flaw was used in a commercial spyware chain.

    Watch: A technical report from Meta or independent researchers

  3. 3
    New variant10%

    After the patch, a second related flaw in CoreGraphics is exploited.

    Watch: A new Apple emergency update and KEV addition

Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.

Market reaction

Indicators affected

  • Exploited Apple zero-days, 2026▲ 2
  • KEV additions, 24–29 September▲ 8

Sources

  1. Apple — Apple security releases
  2. CISA — Known Exploited Vulnerabilities Catalog
  3. BleepingComputer — Apple patches CoreGraphics zero-day flaw exploited in attacks