Apple's CoreGraphics Zero-Day CVE-2026-86950 Has a CISA Deadline of October 13, Not the October 2 Being Reported
Security / news
Apple's CoreGraphics Zero-Day CVE-2026-86950 Has a CISA Deadline of October 13, Not the October 2 Being Reported
Trade coverage gives a three-day federal deadline. The catalogue entry itself carries 14 days and no forensic-triage flag.

A crafted file can trigger an out-of-bounds write in Apple's CoreGraphics framework and run arbitrary code, and Apple says the flaw, CVE-2026-86950, may have been exploited in an extremely sophisticated attack. The fixes shipped on September 28, 2026 in iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1.
The federal deadline is reported inconsistently. The Hacker News wrote that CISA added the flaw to its Known Exploited Vulnerabilities catalogue on September 29 and that agencies must apply fixes by October 2. The catalogue itself lists the same September 29 addition date but a due date of October 13, which is 14 days, not three.

What Apple has said
Apple's security release notes list a single CoreGraphics entry. The impact line says processing a crafted file "may lead to arbitrary code execution". Apple says the issue may have been exploited against specific targeted individuals on versions of iOS before iOS 27, and that it was addressed with improved bounds checking.
Apple has not said how many people were targeted, whether any attempt succeeded, or when exploitation began. The Hacker News reports that Meta Product Security is credited with the report. The Apple page lists the name beside the CVE without a labelled credit line, so the attribution rests on that outlet's reading.
The release notes contain no other CVE, which makes this a one-bug update. The exploitation wording is narrower than the patch list: it names iOS before 27, while the fixed builds are on the 26.7 line.
Fixed builds
| Platform | Fixed version | Devices covered |
|---|---|---|
| iOS and iPadOS | 26.7.1 | iPhone 11 and later, plus listed iPad Pro, Air, standard and mini models |
| macOS Tahoe | 26.7.1 | Macs running Tahoe |
| macOS Sequoia | 15.8.1 | Macs running Sequoia |
Why the deadline differs
The catalogue entry's required action points to CISA's BOD 26-04, the directive issued on June 10, 2026 that replaced BOD 22-01. The Apple entry has forensicTriage set to No and a 14-day due date. The directive's own text says timelines turn on four facts: whether the asset is publicly exposed, whether the flaw is in the catalogue, whether the exploit can be automated, and whether the attacker gains partial or total control. CISA has not said which of those set the Apple timeline.
A 14-day window is the exception in the catalogue. Of the 122 entries added since the directive, 99 carry three days and 23 carry 14. Other 14-day entries include two Chromium V8 flaws, two Windows flaws, LiteLLM and Starlette, all added in the first half of September. Other patch-deadline stories on this site include the Citrix NetScaler zero-day and the Exchange Server flaw.
The score reported by aggregators for this flaw is 8.8, but that figure did not appear on the Apple page or in the catalogue, and the practical risk turns on exposure rather than the number. Apple's wording describes targeted attacks against individuals, not mass exploitation. A fleet owner should patch iPhones and Macs to the builds above now, rather than wait for October 13, and an individual at risk of targeted surveillance should check that the device is on 26.7.1.
The next date to watch is October 13, when the catalogue's listed deadline for federal agencies arrives.
Sources
More in Security
- 01CISA Gave Agencies Three Days for Five 2015-2023 Bugs, and Four Come With a Forensic Triage OrderThe October 8 additions to the exploited-vulnerabilities catalogue show how BOD 26-04 has changed what a deadline means: the patch is the smaller job.
- 02Rejetto HFS CVE-2026-61500, Found With Anthropic's Mythos, Was Probed One Day After DisclosureA predictable session-signing key lets an unauthenticated attacker forge an HFS admin cookie and run server-side JavaScript; HFS 3.2.1 has carried the fix since July.
- 03Exchange CVE-2026-96940 Lets Any Mailbox User Read Others' Mail, and Patched Servers Need V2Microsoft's out-of-band September V2 update closes an 8.8-rated authorization flaw in on-premises Exchange, with four KBs and a support cliff for 2016 and 2019.
- 04Citrix's Third NetScaler Zero-Day in Seven Days Crashes Appliances Already PatchedCVE-2026-88779 hits SAML-configured NetScaler boxes that had just taken the Sept. 27 fixes, and attackers were already trying to drop a payload through it.