Cyber Threat Brief — September 29 2026
1. Apple CoreGraphics OOB write may have been exploited — CVE-2026-86950
TL;DR: Apple patched a CoreGraphics out-of-bounds write that can ACE via a crafted file, and says it may have been used in an extremely sophisticated attack against specific targets on iOS before iOS 27. Push iOS/iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1 today — prioritize high-risk users.
What’s New:
- Meta Product Security reported CVE-2026-86950 (CWE-787, CVSS 8.8); fix is improved bounds checking.
- Apple’s exploitation statement covers iOS before iOS 27; macOS Tahoe/Sequoia got the same CVE patch. No public PoC, file format, or actor.
- Not in CISA KEV yet (catalog still 2026.09.27 / 1728). Builds: Tahoe 25G241, Sequoia 24H32.
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
| CVE-2026-86950 on CoreGraphics before iOS/iPadOS 26.7.1, before macOS Tahoe 26.7.1 (build 25G241), or before macOS Sequoia 15.8.1 (build 24H32). Advisories HT149226 / HT149228 / HT149229. | Vulnerable client / possible 0-day | T1203 / T1204.002 | MDM / inventory | Enforce min OS. Patch iPhone 11+ / listed iPads to 26.7.1 (or move to iOS/iPadOS 27.0.1). Patch Macs to Tahoe 26.7.1 or Sequoia 15.8.1. |
| Crafted file processed by CoreGraphics (PDF / image / preview path possible; Apple did not publish format or delivery) | Exploit delivery | T1204.002 / T1189 | Endpoint / mail / MDM | Treat untrusted attachments and auto-previews as hostile until patched. Consider Lockdown Mode for executives, journalists, and other high-risk targets. |
| Devices still on iOS/iPadOS 26.x < 26.7.1 or macOS Tahoe/Sequoia below fixed builds | Exposure inventory | T1082 | MDM compliance | Alert non-compliant fleets. Re-check CISA KEV for CVE-2026-86950 after catalog updates. |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | None — verified | No analytic for CVE-2026-86950 / CoreGraphics crafted-file ACE. Existing macOS stealer / Gatekeeper rules are different malware classes. |
| Elastic | None — verified | No emerging-threat rule for this CVE. macOS quarantine / sandboxed-Office rules do not match an unspecified CoreGraphics file format. |
| Sigma | None — verified | No ET rule for CVE-2026-86950. |
Hunt hint: Inventory Apple builds against 26.7.1 / Tahoe 25G241 / Sequoia 24H32. Prioritize high-risk users. After patch, keep watching for KEV listing and any later IoCs (none public at briefing time).
Sources: Apple HT149226 · HT149228 · HT149229 · The Hacker News · SecurityWeek · MacRumors · Threadlinqs TL-2026-2745
2. MCP Python SDK OAuth client can leak credentials to a malicious server — GHSA-qx49-fqc8-xw99
TL;DR: Affected mcp Python clients can send client_secret, authorization code, and PKCE code_verifier to a token endpoint chosen by a malicious MCP server. Upgrade to 1.30.0 or 2.2.0, pass issuer= on unattended providers, clear stored registrations, and rotate secrets if you connected to untrusted servers.
What’s New:
- Official advisory GHSA-qx49-fqc8-xw99 (2026-09-28, High 7.5); Cycode end-to-end PoC; THN amplify 2026-09-29. No CVE assigned yet; no reported ITW.
- Fallback discovery (MCP server returns 404 for protected-resource metadata) skipped issuer validation; attacker sets
issuerto the real IdP and steals the token exchange. - Unattended providers still follow the server unless
issuer=is set after upgrade.
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
pip package mcp 1.9.1–1.29.1 or 2.0.0–2.1.1 used as an HTTP MCP client with OAuthClientProvider, ClientCredentialsOAuthProvider, PrivateKeyJWTOAuthProvider, or deprecated 1.x RFC7523OAuthClientProvider | Vulnerable SDK | T1552 / T1528 | SBOM / pip freeze / lockfiles | Upgrade to mcp ≥1.30.0 (1.x) or ≥2.2.0 (2.x). Servers, stdio clients, and clients that attach their own tokens are out of scope. |
Missing issuer= on ClientCredentialsOAuthProvider / PrivateKeyJWTOAuthProvider after upgrade (e.g. issuer="https://auth.example.com") | Incomplete fix | T1552 | App config / code review | Pass issuer= naming the real authorization server; without it those providers still follow the MCP server. Move off RFC7523OAuthClientProvider (no issuer= option). |
Stored OAuth client registrations from pre-fix SDK; long-lived client_secret that may have hit an untrusted MCP server | Credential exposure | T1552.001 / T1528 | IdP admin / secrets store | Clear stored OAuth client registrations once after upgrade. Rotate client secrets and revoke tokens at the IdP if past exposure is possible. |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | None — verified | Existing MCP analytics (MCP Prompt Injection, filesystem/GitHub/Postgres tool abuse) monitor server-side tool misuse. They do not detect client OAuth token-endpoint hijack or missing issuer= binding. |
| Elastic | None — verified | GenAI “sensitive file access” / unusual-domain rules target process file/network behavior, not MCP OAuth discovery metadata poisoning. |
| Sigma | None — verified | No ET rule for GHSA-qx49-fqc8-xw99 / MCP OAuth credential theft. |
Hunt hint: Find lockfiles and images pinning mcp below 1.30.0 / 2.2.0. Confirm HTTP clients that connect to third-party MCP servers. After upgrade, require issuer=, clear stored registrations, and rotate secrets for any prior untrusted connections.
Sources: GHSA-qx49-fqc8-xw99 · Cycode · The Hacker News · THN on X
Status Updates
- CVE-2026-88771 / CVE-2026-88772 (Citrix NetScaler): KEV due TOMORROW 2026-09-30 (forensic triage Yes). Preserve snapshot/support bundle/
/var/core, then patch ≥14.1-73.37 / ≥13.1-64.23; keepAA:UA,pitboss/NSPPE;,.ctxs.receiverhunts. Sep 28 brief. - CVE-2026-65660 (SharePoint) / CVE-2026-67279 (MikroTik) / CVE-2026-87902 (WordPress): KEV due was 2026-09-28. Confirm fixed builds / RouterOS floors / WP ≥7.1.2. Sep 26 · Sep 24 · Sep 06.
- Carbonato / CVE-2026-62062 (Elementor): No material change. Keep TCP/2375,
GH0ST/SOUL.md, andelementor/v1/events/hunts; Elementor ≥4.3.2. Sep 28 brief. - CVE-2026-18143 (WooCommerce RFQ) / Mini Shai-Hulud (
actions-cool/*): No material change. Keepafrfq_submit_quote_via_popupand secret rotation for Sep 16–25 tag-ref runs. Sep 27 brief. - CVE-2026-35273 (PeopleSoft / UNC6240) / CVE-2026-48842 (Roundcube): No material change. Keep
/%50SEMHUB/+ SIDEEYE; Roundcube ≥1.6.16 / ≥1.7.1. Sep 26 brief. - CVE-2026-94127 (F5) / CVE-2026-93616 (CP Mgmt) / CVE-2026-93952 (Arista) / CVE-2026-85102 (CP VPN) / CVE-2026-42016+42018 (JFrog): KEV due was 2026-09-25. Confirm Eng HF / Jumbo / VCO / sk1000117 / Artifactory. Sep 23 · Sep 12 · Sep 11.