Cyber Threat Brief — September 29 2026

⚠️ This report is AI-generated. Always validate findings.

1. Apple CoreGraphics OOB write may have been exploited — CVE-2026-86950

TL;DR: Apple patched a CoreGraphics out-of-bounds write that can ACE via a crafted file, and says it may have been used in an extremely sophisticated attack against specific targets on iOS before iOS 27. Push iOS/iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1 today — prioritize high-risk users.

What’s New:

  • Meta Product Security reported CVE-2026-86950 (CWE-787, CVSS 8.8); fix is improved bounds checking.
  • Apple’s exploitation statement covers iOS before iOS 27; macOS Tahoe/Sequoia got the same CVE patch. No public PoC, file format, or actor.
  • Not in CISA KEV yet (catalog still 2026.09.27 / 1728). Builds: Tahoe 25G241, Sequoia 24H32.

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
CVE-2026-86950 on CoreGraphics before iOS/iPadOS 26.7.1, before macOS Tahoe 26.7.1 (build 25G241), or before macOS Sequoia 15.8.1 (build 24H32). Advisories HT149226 / HT149228 / HT149229.Vulnerable client / possible 0-dayT1203 / T1204.002MDM / inventoryEnforce min OS. Patch iPhone 11+ / listed iPads to 26.7.1 (or move to iOS/iPadOS 27.0.1). Patch Macs to Tahoe 26.7.1 or Sequoia 15.8.1.
Crafted file processed by CoreGraphics (PDF / image / preview path possible; Apple did not publish format or delivery)Exploit deliveryT1204.002 / T1189Endpoint / mail / MDMTreat untrusted attachments and auto-previews as hostile until patched. Consider Lockdown Mode for executives, journalists, and other high-risk targets.
Devices still on iOS/iPadOS 26.x < 26.7.1 or macOS Tahoe/Sequoia below fixed buildsExposure inventoryT1082MDM complianceAlert non-compliant fleets. Re-check CISA KEV for CVE-2026-86950 after catalog updates.

Detection

SourceRuleGap
Splunk ESCUNone — verifiedNo analytic for CVE-2026-86950 / CoreGraphics crafted-file ACE. Existing macOS stealer / Gatekeeper rules are different malware classes.
ElasticNone — verifiedNo emerging-threat rule for this CVE. macOS quarantine / sandboxed-Office rules do not match an unspecified CoreGraphics file format.
SigmaNone — verifiedNo ET rule for CVE-2026-86950.

Hunt hint: Inventory Apple builds against 26.7.1 / Tahoe 25G241 / Sequoia 24H32. Prioritize high-risk users. After patch, keep watching for KEV listing and any later IoCs (none public at briefing time).

Sources: Apple HT149226 · HT149228 · HT149229 · The Hacker News · SecurityWeek · MacRumors · Threadlinqs TL-2026-2745


2. MCP Python SDK OAuth client can leak credentials to a malicious server — GHSA-qx49-fqc8-xw99

TL;DR: Affected mcp Python clients can send client_secret, authorization code, and PKCE code_verifier to a token endpoint chosen by a malicious MCP server. Upgrade to 1.30.0 or 2.2.0, pass issuer= on unattended providers, clear stored registrations, and rotate secrets if you connected to untrusted servers.

What’s New:

  • Official advisory GHSA-qx49-fqc8-xw99 (2026-09-28, High 7.5); Cycode end-to-end PoC; THN amplify 2026-09-29. No CVE assigned yet; no reported ITW.
  • Fallback discovery (MCP server returns 404 for protected-resource metadata) skipped issuer validation; attacker sets issuer to the real IdP and steals the token exchange.
  • Unattended providers still follow the server unless issuer= is set after upgrade.

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
pip package mcp 1.9.1–1.29.1 or 2.0.0–2.1.1 used as an HTTP MCP client with OAuthClientProvider, ClientCredentialsOAuthProvider, PrivateKeyJWTOAuthProvider, or deprecated 1.x RFC7523OAuthClientProviderVulnerable SDKT1552 / T1528SBOM / pip freeze / lockfilesUpgrade to mcp ≥1.30.0 (1.x) or ≥2.2.0 (2.x). Servers, stdio clients, and clients that attach their own tokens are out of scope.
Missing issuer= on ClientCredentialsOAuthProvider / PrivateKeyJWTOAuthProvider after upgrade (e.g. issuer="https://auth.example.com")Incomplete fixT1552App config / code reviewPass issuer= naming the real authorization server; without it those providers still follow the MCP server. Move off RFC7523OAuthClientProvider (no issuer= option).
Stored OAuth client registrations from pre-fix SDK; long-lived client_secret that may have hit an untrusted MCP serverCredential exposureT1552.001 / T1528IdP admin / secrets storeClear stored OAuth client registrations once after upgrade. Rotate client secrets and revoke tokens at the IdP if past exposure is possible.

Detection

SourceRuleGap
Splunk ESCUNone — verifiedExisting MCP analytics (MCP Prompt Injection, filesystem/GitHub/Postgres tool abuse) monitor server-side tool misuse. They do not detect client OAuth token-endpoint hijack or missing issuer= binding.
ElasticNone — verifiedGenAI “sensitive file access” / unusual-domain rules target process file/network behavior, not MCP OAuth discovery metadata poisoning.
SigmaNone — verifiedNo ET rule for GHSA-qx49-fqc8-xw99 / MCP OAuth credential theft.

Hunt hint: Find lockfiles and images pinning mcp below 1.30.0 / 2.2.0. Confirm HTTP clients that connect to third-party MCP servers. After upgrade, require issuer=, clear stored registrations, and rotate secrets for any prior untrusted connections.

Sources: GHSA-qx49-fqc8-xw99 · Cycode · The Hacker News · THN on X


Status Updates

  • CVE-2026-88771 / CVE-2026-88772 (Citrix NetScaler): KEV due TOMORROW 2026-09-30 (forensic triage Yes). Preserve snapshot/support bundle//var/core, then patch ≥14.1-73.37 / ≥13.1-64.23; keep AA: UA, pitboss/NSPPE;, .ctxs.receiver hunts. Sep 28 brief.
  • CVE-2026-65660 (SharePoint) / CVE-2026-67279 (MikroTik) / CVE-2026-87902 (WordPress): KEV due was 2026-09-28. Confirm fixed builds / RouterOS floors / WP ≥7.1.2. Sep 26 · Sep 24 · Sep 06.
  • Carbonato / CVE-2026-62062 (Elementor): No material change. Keep TCP/2375, GH0ST/SOUL.md, and elementor/v1/events/ hunts; Elementor ≥4.3.2. Sep 28 brief.
  • CVE-2026-18143 (WooCommerce RFQ) / Mini Shai-Hulud (actions-cool/*): No material change. Keep afrfq_submit_quote_via_popup and secret rotation for Sep 16–25 tag-ref runs. Sep 27 brief.
  • CVE-2026-35273 (PeopleSoft / UNC6240) / CVE-2026-48842 (Roundcube): No material change. Keep /%50SEMHUB/ + SIDEEYE; Roundcube ≥1.6.16 / ≥1.7.1. Sep 26 brief.
  • CVE-2026-94127 (F5) / CVE-2026-93616 (CP Mgmt) / CVE-2026-93952 (Arista) / CVE-2026-85102 (CP VPN) / CVE-2026-42016+42018 (JFrog): KEV due was 2026-09-25. Confirm Eng HF / Jumbo / VCO / sk1000117 / Artifactory. Sep 23 · Sep 12 · Sep 11.