Critical Vulnerabilities: Act Now or Pay Later

Threats & Attacks

Critical Vulnerabilities: Act Now or Pay Later

The Apple CoreGraphics Zero-Day

It’s happening again, and this time Apple devices are in the crosshairs. CVE-2026-86950 is an out-of-bounds write vulnerability lurking in Apple’s CoreGraphics, affecting iOS, macOS, and iPadOS. What does it mean for UK SMBs? Quite simply, if your device can execute arbitrary code, your data is vulnerable. Dark Reading reports that this zero-day is actively being exploited in targeted attacks (source).

What You Need to Do:

  • Patch now: Apple has released updates. Compliance is not just recommended, it’s imperative.
  • Review exposure: According to CISA BOD 26-04, ensure these devices’ internet exposure is minimised.

Critical Dockhand Authentication Bypass

For those using Dockhand, CVE-2026-53988 should be a wake-up call. Achieving a maximum CVSS score of 10.0, this vulnerability lets remote attackers bypass authentication and redeploy stacks without permissions. NIST’s NVD details how this flaw can escalate into full host compromise if combined with write access.

Immediate Steps:

  • Check your versions: Ensure you’re running Dockhand 1.0.40 or later.
  • Restrict remote access: Limit which webhooks can communicate with your network.

The RPyC Disaster with LightLLM

LightLLM’s fault extends to CVE-2026-103040, an RPyC-based vulnerability allowing unauthenticated remote code execution when profiling is enabled. This isn’t just technical mumbo jumbo, it’s a serious threat that lets attackers control your system remotely.

Your Action Items:

  • Disable profiling: Until the issue is resolved, turn off this setting entirely.
  • Vulnerability assessments: Run a full sweep of your network for any unauthorized changes.

How to Turn This Into a Competitive Advantage

In the UK market, competence around cybersecurity is increasingly seen as a competitive edge. Your clients and partners are watching.

  • Communicate updates: Let stakeholders know your business adapts swiftly to vulnerabilities.
  • Leverage compliance: Use the compliance to new patches as a selling point in tenders and negotiations.

Making the Business Case

  • Data protection saves costs: It’s cheaper to patch than to pay ransoms or data breach fines.
  • Maintain trust: Show customers you take their data security seriously.
  • Board support on updates: The technical team can only propose, the board should enable and provide budget.

What This Means for Your Business

  1. Apply all relevant patches immediately, starting with critical components like Apple devices.
  2. Reassess firewall rules and internet-facing services to minimise exposure.
  3. Educate your staff regularly on security awareness and encourage them to report anomalies.
  4. Increase investment in professional penetration testing and risk assessments.

Before you go: follow the show wherever you listen, leave a rating or review, drop a comment with your thoughts, and share it with someone who would find it useful.

SourceArticle
Dark ReadingApple Zero-Day Vulnerability Weaponized
NIST NVDDockhand Authentication Bypass
CISA KEVKnown Exploited Vulnerabilities
The Cyber ThroneApple CoreGraphics Zero-Day
The Hacker NewsNew Spectre-v2 BTR Attack

Filed under

  • uk-business
  • smb-security
  • business-risk
  • remote-access
  • incident-response