Apple Patches CVE-2026-86950: CoreGraphics, Targeted Attacks
Apple patched CVE-2026-86950 in CoreGraphics on September 28 with an emergency update for iOS 26, macOS 26, and macOS 15. Apple's advisory states it may have been exploited in targeted attacks.

Apple patched CVE-2026-86950 on September 28. The flaw is in CoreGraphics. CVSS 8.8 (high, per NVD). Apple’s advisory language: “may have been exploited in targeted attacks.” Independent exploitation confirmation: none publicly available as of this writing.
What’s affected
Older supported releases of iOS, iPadOS, and macOS. Apple issued patches for iOS 26, macOS 26, and macOS 15 in the September 28 update. The fix applies to those specific branches. Per SANS Internet Storm Center, not all platform branches received the security fix in this release cycle.
Patches are available via Apple’s standard update channels.
Confidence and status
Apple’s “may have been exploited in targeted attacks” is the company’s standard advisory language when it has reason to believe exploitation has occurred. It is not independent confirmation. Not listed on CISA’s Known Exploited Vulnerabilities catalog as of September 29.
No public CVE details from NVD on attack vector or specific trigger conditions. Source: The Hacker News. Apple advisory: CVE-2026-86950.
Watch for a CISA KEV addition if third-party exploitation confirmation follows.
Related Apple coverage
- [ HIGH ]CVE-2026-86950CoreGraphics memory confusion in Apple iOS 26, iPadOS, macOS 26, macOS 15
Found this useful? Share it.


