CISA added Apple’s CVE-2026-86950 to its Known Exploited Vulnerabilities (KEV) catalog on September 29, 2026, and lists October 2 as the deadline for mitigation and forensic triage. That action applies to federal civilian executive branch agencies covered by BOD 26-04. Apple released fixes for the flaw on September 28.
CISA adds CVE-2026-86950 to KEV
CISA’s entry lists October 2, 2026, as the due date for the required mitigation and forensic triage. The deadline is scoped to federal civilian executive branch agencies covered by BOD 26-04.
Apple’s updates fix the CoreGraphics flaw
Apple identifies CVE-2026-86950 as an out-of-bounds write in CoreGraphics. Processing a maliciously crafted file may lead to arbitrary code execution. Apple says improved bounds checking addresses the flaw and credits Meta Product Security with reporting it.
Apple released iOS 26.7.1 and iPadOS 26.7.1, along with macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1, on September 28, 2026.
Apple’s iOS and iPadOS advisory lists iPhone 11 and later, as well as iPad Pro 12.9-inch (3rd generation and later), iPad Pro 11-inch (1st generation and later), iPad Air (3rd generation and later), iPad (8th generation and later) and iPad mini (5th generation and later).
What Apple says about possible exploitation
Apple says it is aware of a report that the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals using iOS versions before iOS 27.