Skip to content
Hugin
A black smartphone with a dark screen standing upright on a bare grey steel shelf, a small blue light glowing at its base.

Hugin News

Apple fixed an iPhone, iPad and Mac flaw it says was reported as possibly exploited in a targeted attack; CISA set federal civilian agencies an October 2 deadline

3 min read

Original editorial artwork generated for Hugin.

Apple's September 28 updates (iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1, macOS Sequoia 15.8.1) fix a CoreGraphics flaw; Apple says it is aware of a report that the flaw may have been exploited in an attack on specific people. CISA added it to its exploited-vulnerabilities catalog September 29, with an October 2 due date that applies to federal civilian agencies, not the public. A Cisco SD-WAN Manager flaw was added September 30, due October 3. Apple advises keeping software up to date.

cybersecurityappleiosmacoscisaknown-exploited-vulnerabilitiescisco
8source receipts3source hosts3 minread timelinkedprimary source

Apple's September 28 updates fix an iPhone, iPad and Mac flaw that Apple says was reported as possibly exploited. On September 29, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added it, CVE-2026-86950, to its catalog of known exploited vulnerabilities with a federal due date of October 2. A Cisco flaw was added September 30, due October 3.

Which Apple updates fix it

Apple's September 28 security pages list the fix in three releases:

  • iOS 26.7.1 and iPadOS 26.7.1, for iPhone 11 and later, and iPads back to the iPad Pro 12.9-inch (3rd generation), iPad Pro 11-inch (1st), iPad Air (3rd), iPad (8th) and iPad mini (5th).
  • macOS Tahoe 26.7.1.
  • macOS Sequoia 15.8.1.

Apple lists the flaw under CoreGraphics: an out-of-bounds write, a memory error, fixed with improved bounds checking. A maliciously crafted file may lead to arbitrary code execution, Apple says, meaning an attacker's own instructions could run on the device.

Apple's security releases page says keeping software up to date is among the most important things users can do for security.

What Apple and CISA say about exploitation

Apple says it is aware of a report that the flaw "may have been exploited in an extremely sophisticated attack" on particular people running iOS versions before iOS 27. The macOS pages repeat the sentence.

CISA's published criteria for the catalog turn on active exploitation: reliable evidence that an attacker ran malicious code on a system without permission, including attempts. The entry does not describe that evidence and marks ransomware use Unknown.

What the federal deadline means

The due dates apply to federal civilian executive branch agencies under CISA's Binding Operational Directive 26-04, issued June 10, 2026, which replaced directive 22-01. CISA's criteria page says other organizations are not bound but recommends they prioritize catalog entries too. The directive also sets each system's timetable by factors such as internet exposure. Both rows are flagged for forensic triage, which it defines as remediation or mitigation within three days plus a check on whether the system was compromised.

The second flaw: Cisco SD-WAN Manager

Cisco's advisory, first published September 30, rates CVE-2026-76504 Critical (base score 9.8). It says an unauthenticated, remote attacker could gain admin-user access to Cisco Catalyst SD-WAN Manager with a crafted web request that bypasses an authentication rule, whatever the configuration. Cisco says its security team became aware of active exploitation in September 2026.

Cisco lists no workaround and recommends upgrading. Its first fixed release for each version line: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1; versions earlier than 20.9 should migrate. For on-premises systems it advises restricting internet access as a mitigation; Cisco says that is already in place for its Cloud Hosted environments.

What the documents do not say

  • Who was attacked, by whom, or how many, for either flaw.
  • Whether iOS 27 or macOS 27 is affected. Apple lists iOS 27.0.1 and macOS Golden Gate 27.0.1, both released September 28, with no published CVE entries.

Source links