MediumII Cyber Warfare & Critical Infrastructure29 September 2026, Tuesday
Apple CoreGraphics flaw exploited as a zero-day, CISA adds it to catalogue
On 28 September Apple fixed the CVE-2026-86950 flaw with the iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 updates. The US Cybersecurity and Infrastructure Security Agency (CISA) added it to its catalogue of exploited vulnerabilities on 29 September.
Apple's security releases page shows the iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 updates were published on 28 September 2026. BleepingComputer reported on 29 September that CVE-2026-86950 is an out-of-bounds write in CoreGraphics, the graphics rendering framework. In other words, the program can write data outside the memory area allocated to it. The bug can lead to arbitrary code execution on a device when 1 malicious file is opened. Apple said it was aware of 1 report that the flaw may have been exploited in an "extremely sophisticated attack". Meta's product security team found the flaw; affected devices include iPhone 11 and later and iPad 8th generation and later.
CISA's Known Exploited Vulnerabilities (KEV) catalogue lists flaws proven to have been used in attacks and obliges federal agencies to patch them. The catalogue records CVE-2026-86950 for multiple Apple products under the date of 29 September. In the 6 days from 24 to 29 September, the same catalogue took in a total of 8 flaws in Apple, Citrix, WordPress, Microsoft, MikroTik, Adobe and WSO2 products. According to BleepingComputer, this is the 2nd exploited zero-day Apple has fixed in 2026; the first was CVE-2026-20700 in the dyld component in February. The exact patch deadline for federal agencies and the targets of the attack could not be verified, as neither source states them clearly.
Talay assessment
Bottom line
Apple's 2nd exploited zero-day of 2026 is a code execution flaw that can be triggered by opening a file, which makes it a valuable tool in targeted attacks. CISA adding the flaw to its catalogue within a day creates pressure for rapid patching on federal networks. The scale of spread is unclear because the targets have not been disclosed. The most likely path is that use against a limited number of targets is closed off by the patch.
Likely effects
- Enterprise device managementNegativeWeeks
Organisations managing iPhone 11 and later and current Macs must roll out the 28 September updates quickly; delay leaves open the risk of compromise through a malicious file.
- Targeted spywareNegativeWeeks
CoreGraphics flaws triggered by file processing are typically used as the first link in targeted attack chains against journalists, executives and officials.
- TürkiyeUncertainWeeks
Organisations in Türkiye running iOS and macOS in public and corporate fleets need the same update; the flaw is platform-wide, so there is no geographic boundary.
Possibilities, ranked
- 1Closed by the patch60%
The updates spread quickly, and the flaw is reported as having stayed confined to a limited number of targets.
Watch: Whether Apple and CISA issue further exploitation notices
- 2Attack chain comes to light30%
Security researchers show that the flaw was used in a commercial spyware chain.
Watch: A technical report from Meta or independent researchers
- 3New variant10%
After the patch, a second related flaw in CoreGraphics is exploited.
Watch: A new Apple emergency update and KEV addition
Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.
Market reaction
Indicators affected
- Exploited Apple zero-days, 2026▲ 2
- KEV additions, 24–29 September▲ 8