Apple's September 28 updates fix an iPhone, iPad and Mac flaw that Apple says was reported as possibly exploited. On September 29, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added it, CVE-2026-86950, to its catalog of known exploited vulnerabilities with a federal due date of October 2. A Cisco flaw was added September 30, due October 3.
Which Apple updates fix it
Apple's September 28 security pages list the fix in three releases:
- iOS 26.7.1 and iPadOS 26.7.1, for iPhone 11 and later, and iPads back to the iPad Pro 12.9-inch (3rd generation), iPad Pro 11-inch (1st), iPad Air (3rd), iPad (8th) and iPad mini (5th).
- macOS Tahoe 26.7.1.
- macOS Sequoia 15.8.1.
Apple lists the flaw under CoreGraphics: an out-of-bounds write, a memory error, fixed with improved bounds checking. A maliciously crafted file may lead to arbitrary code execution, Apple says, meaning an attacker's own instructions could run on the device.
Apple's security releases page says keeping software up to date is among the most important things users can do for security.
What Apple and CISA say about exploitation
Apple says it is aware of a report that the flaw "may have been exploited in an extremely sophisticated attack" on particular people running iOS versions before iOS 27. The macOS pages repeat the sentence.
CISA's published criteria for the catalog turn on active exploitation: reliable evidence that an attacker ran malicious code on a system without permission, including attempts. The entry does not describe that evidence and marks ransomware use Unknown.
What the federal deadline means
The due dates apply to federal civilian executive branch agencies under CISA's Binding Operational Directive 26-04, issued June 10, 2026, which replaced directive 22-01. CISA's criteria page says other organizations are not bound but recommends they prioritize catalog entries too. The directive also sets each system's timetable by factors such as internet exposure. Both rows are flagged for forensic triage, which it defines as remediation or mitigation within three days plus a check on whether the system was compromised.
The second flaw: Cisco SD-WAN Manager
Cisco's advisory, first published September 30, rates CVE-2026-76504 Critical (base score 9.8). It says an unauthenticated, remote attacker could gain admin-user access to Cisco Catalyst SD-WAN Manager with a crafted web request that bypasses an authentication rule, whatever the configuration. Cisco says its security team became aware of active exploitation in September 2026.
Cisco lists no workaround and recommends upgrading. Its first fixed release for each version line: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1; versions earlier than 20.9 should migrate. For on-premises systems it advises restricting internet access as a mitigation; Cisco says that is already in place for its Cloud Hosted environments.
What the documents do not say
- Who was attacked, by whom, or how many, for either flaw.
- Whether iOS 27 or macOS 27 is affected. Apple lists iOS 27.0.1 and macOS Golden Gate 27.0.1, both released September 28, with no published CVE entries.
Source links
- Apple: About the security content of iOS 26.7.1 and iPadOS 26.7.1
- Apple: About the security content of macOS Tahoe 26.7.1
- Apple: About the security content of macOS Sequoia 15.8.1
- Apple security releases
- CISA Known Exploited Vulnerabilities catalog (JSON, version 2026.09.30)
- CISA: Known Exploited Vulnerabilities criteria
- CISA: BOD 26-04, Prioritizing Security Updates Based on Risk, June 10, 2026
- Cisco: Catalyst SD-WAN Manager API Authentication Bypass Vulnerability, cisco-sa-sdwan-webauth-xr8beuuU
