ARCHIVE

CVEs published in September 2026 (page 12)

Vulnerabilities added to CVE Radar in September 2026, newest first.

  1. CVE-2026-70009
    Azure ARC path traversal privilege elevation Microsoft Azure ARC ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  2. CVE-2026-70200
    Azure Logic Apps path traversal allows remote privilege escalation Microsoft Azure Logic Apps ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  3. CVE-2026-85889
    Azure AI Foundry missing authentication privilege elevation Microsoft Azure AI Foundry ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  4. CVE-2026-93762 CRITICAL 9.8
  5. CVE-2026-93643
    Zimbra Collaboration Suite path-traversal pre-auth remote code execution Zimbra Zimbra Collaboration Suite (ZCS) ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  6. CVE-2026-18143
    Request a Quote for WooCommerce arbitrary file upload via popup handler Addify Request a Quote for WooCommerce ·
    • PoC PUBLIC
    CRITICAL 9.8
  7. CVE-2026-88775 CRITICAL 9.8
  8. CVE-2026-88777 CRITICAL 9.8
  9. CVE-2026-88776
    Citrix ADC memory overflow can cause service disruption Citrix ADC ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  10. CVE-2026-57983
    Microsoft Edge security feature bypass over network (pre-auth authorization bypass) Microsoft Microsoft Edge (Chromium-based) ·
    • PATCH AVAILABLE
    CRITICAL 10
  11. CVE-2026-62643
    Roundcube Webmail CSS sanitization SSRF and information disclosure Roundcube Webmail ·
    • PATCH AVAILABLE
    CRITICAL 10
  12. CVE-2026-54433
    Roundcube Webmail stored XSS zero-click via crafted email Roundcube Webmail ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 10
  13. CVE-2026-54159 CRITICAL 10
  14. CVE-2026-16367 CRITICAL 10
  15. CVE-2026-56163
    Azure Kubernetes Service missing authentication allows pre-auth privilege escalation Microsoft Azure Kubernetes Service ·
    • PATCH AVAILABLE
    CRITICAL 10
  16. CVE-2026-65880
    Balbooa Forms for Joomla unauthenticated remote code execution balbooa.com Balbooa Forms component for Joomla ·
    CRITICAL 10
  17. CVE-2026-66803
    Azure Cosmos DB improper access control pre-auth remote code execution Microsoft Azure Cosmos DB ·
    • PATCH AVAILABLE
    CRITICAL 10
  18. CVE-2026-64633
    Veeam ONE unauthenticated remote code execution Veeam ONE ·
    • PoC PUBLIC
    CRITICAL 10
  19. CVE-2026-56162
    Azure SQL Database improper authentication privilege elevation Microsoft Azure SQL Database ·
    • PATCH AVAILABLE
    CRITICAL 10
  20. CVE-2026-62836
    Azure SQL Managed Instance privilege elevation via communication channel flaw Microsoft Azure SQL Managed Instance ·
    • PATCH AVAILABLE
    CRITICAL 10
20 CVEs · page 12 of 23