Apple Patches Zero-Day CVE-2026-86950 in CoreGraphics Exploited in Targeted iOS Attacks
Apple has issued urgent security updates for iPhone, iPad, and macOS devices to close a zero-day vulnerability identified as CVE-2026-86950. The company confirmed that the flaw was actively exploited in sophisticated, targeted cyberattacks against selected iOS users.
The issue was discovered by Meta Product Security researchers within the CoreGraphics system component, which handles rendering of images, text, and two-dimensional graphics. According to Apple’s advisory, processing a maliciously crafted file could trigger an out-of-bounds write, potentially leading to arbitrary code execution on the affected device.
This class of memory corruption vulnerability can result in a range of consequences, from application crashes to full system compromise. Apple emphasized that the attacks were limited to specific individuals running versions of iOS prior to the newly released updates and did not constitute mass distribution of malware.
The fixes are delivered in the following releases: iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. Supported devices include iPhone 11 and newer models, various iPad Pro, iPad Air, standard iPad, and iPad mini variants, as well as vulnerable macOS systems.
Apple strengthened memory boundary checks to prevent exploitation. While the probability of encountering such a targeted attack remains low for most users, the company strongly recommends immediate installation of the updates because the vulnerability was already being used in the wild before public disclosure.
Related articles
cKEV Index Launches to Prioritize Vulnerabilities Using Urgent Patch Score Methodology
CyberOK has introduced the open cKEV Index, a catalog of high-priority vulnerabilities based on the Urgent Patch Score (UPS) framework that tracks signals such as exploit publication and confirmed attacks. The index addresses the growing gap between accelerated vulnerability discovery powered by AI and the slower pace of patching, testing, and deployment in real environments. It incorporates timelines from sources including Anthropic reports on AI-assisted campaigns GTG-50014 and GTG-50029, the rust-in-peace framework, Microsoft Exchange Server Subscription Edition delays, and Oracle’s record 1,434 CVE fixes. UPS defines progressive phases from Radar to Emergency/IR, allowing teams to link specific events like PoC releases or CISA KEV additions to concrete actions under resource constraints. Research using 2025 CISA KEV data shows that early signals enable 35–53% of patches to be completed before official exploitation confirmation. The public version displays only Urgent Patch and Emergency stages with event histories, while full data and API access are available to CyberOK customers.
Multiple Vulnerabilities Found in WatchGuard Access Points Including Critical Flaw
WatchGuard Technologies has disclosed three vulnerabilities affecting its WatchGuard AP access point products, one of which is rated critical. The issues were detailed in an advisory published on September 28 and involve flaws in internal API services and a diagnostic command-line interface. CVE-2026-86102 allows OS command injection that can lead to arbitrary shell command execution on the underlying operating system when an attacker has network access. CVE-2026-101891 stems from improper access controls that permit unauthenticated acquisition of valid API sessions. CVE-2026-87969 affects the diagnostic CLI and enables arbitrary OS command execution but requires administrator privileges to exploit. The findings were reported by Security NEXT.
CISA Adds Two Critical Citrix NetScaler Flaws to Known Exploited Vulnerabilities Catalog
The CISA has added two critical vulnerabilities affecting Citrix NetScaler ADC and Gateway to its Known Exploited Vulnerabilities catalog following reports of active global exploitation. Both CVE-2026-88771 and CVE-2026-88772 carry a CVSS score of 9.5 and were patched by Citrix on September 27, the same day they were added to the catalog. The first flaw stems from improper input validation and allows unauthenticated arbitrary command execution on default installations. The second issue involves a buffer overflow that can lead to remote code execution or denial of service when DTLS is enabled on VPN virtual servers. Affected versions include 14.1-73.32, 13.1-63.21 and earlier, with fixes available in 14.1-73.37, 13.1-64.23 and later releases including FIPS variants. The issues were identified by watchTowr on September 26, and Citrix confirmed ongoing attacks against unpatched systems. Organizations are advised to apply patches immediately while preserving evidence and following full incident response procedures.
Apple Releases macOS Updates to Fix CoreGraphics Vulnerability Possibly Exploited in Targeted iOS Attacks
Apple has issued security updates for multiple macOS versions to address a serious vulnerability in the CoreGraphics framework. The flaw, tracked as CVE-2026-86950, involves an out-of-bounds write that could allow arbitrary code execution when processing specially crafted files. The company also noted that the same issue may have been exploited in sophisticated, targeted attacks against older versions of iOS. CISA assigned the vulnerability a CVSS v3.1 base score of 8.8, classifying it as High severity. Patches are now available in macOS Tahoe 26.7.1, macOS Sequoia 15.8.1, and the latest macOS Golden Gate 27.0.1 release.