CISA has added Apple's CoreGraphics flaw, CVE-2026-86950, to its Known Exploited Vulnerabilities catalogue. The entry went up on 29 September 2026, and US federal civilian agencies had until 2 October to patch under Binding Operational Directive 26-04. Apple had already shipped the fix on 28 September.

Illustration: The Gold Standard