« All news

Follow-up · active exploitationHigh

CISA confirms active exploitation of the CoreGraphics flaw in iOS, iPadOS and macOS (CVE-2026-86950)

CISA has added CVE-2026-86950, the CoreGraphics vulnerability Apple patched on 28 September, to its KEV catalogue, confirming it is being exploited in real-world attacks. It affects iPhone, iPad and Mac, with a federal remediation deadline of 2 October 2026.

What happened

This is a follow-up to our 29 September report on the Apple flaw in iOS, iPadOS and macOS. What is new is that on 29 September 2026 CISA added CVE-2026-86950 to its Known Exploited Vulnerabilities (KEV) catalogue, officially confirming that the flaw is being used in active attacks.

The remediation deadline set for US federal agencies is 2 October 2026, a very tight window that reflects the urgency of the case. For any organisation, a KEV listing is the clearest signal that the patch should be applied without waiting for the next maintenance cycle.

Who is affected

The flaw lies in the CoreGraphics component and allows arbitrary code execution when a maliciously crafted file is processed. It carries a CVSS score of 8.8 (high) and requires the victim to open or process the file.

According to Apple's advisory, the fixed versions are iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1 and macOS Tahoe 26.7.1. The advisory lists the covered devices as iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.

Exploitation status

Apple states it is aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals, on versions of iOS before iOS 27. The discovery is credited to Meta Product Security. CISA has not determined whether the vulnerability is used in ransomware campaigns.

FIRST estimates a 0.8 % probability of exploitation over the next 30 days, statistically a low figure. It should be read with care: EPSS reflects mass exploitation and does not capture narrowly targeted attacks of the kind Apple describes, where real-world exploitation is already confirmed.

What to do

The recommendation is to patch all managed Apple devices as a matter of urgency, starting with high-risk profiles (executives, finance staff, publicly exposed employees, journalists or activists).

Sources

Affected technologies

Apple iOSApple iPadOSApple macOS

Vulnerabilities (1)

CVESeverityActive exploitationPublishedNVD status
CVE-2026-86950High (8.8)⚠ Active exploitation9/28/2026Analyzed

Written automatically from NVD, CISA KEV and vendor advisory data. Always check affected versions and patches in the vendor's official advisory before acting.