ARCHIVE
CVEs published in September 2026 (page 13)
Vulnerabilities added to CVE Radar in September 2026, newest first.
-
CVE-2026-65667
Microsoft Teams missing authorization privilege elevationCRITICAL 10
- PATCH AVAILABLE
- CVE-2026-75874 CRITICAL 10
-
CVE-2026-65770
Azure Managed Instance for Apache Cassandra argument injection allows remote code executionCRITICAL 10
- PATCH AVAILABLE
-
CVE-2026-65816
Azure Web Apps incorrect name resolution lets unauthenticated actor elevate privilegesCRITICAL 10
- PATCH AVAILABLE
- CVE-2026-69555 CRITICAL 10
- CVE-2026-69502 CRITICAL 10
- CVE-2026-70352 CRITICAL 10
-
CVE-2026-65381
MacOS entitlement validation sandbox escapeCRITICAL 10
- PATCH AVAILABLE
- CVE-2026-69865 CRITICAL 10
- CVE-2026-62874 CRITICAL 10
- CVE-2026-88773 CRITICAL 10
- CVE-2026-6837 HIGH 7.2
-
CVE-2026-69414
Microsoft Malware Protection Engine elevation of privilegeHIGH 7.8
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-54998
Microsoft Exchange Online authorization bypass lets authorized users escalate privilegesHIGH 8.8
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-47301
Microsoft Configuration Manager privilege escalation over networkHIGH 8.8
- PoC PUBLIC
- PATCH AVAILABLE
- CVE-2026-20200 HIGH 8.8
- CVE-2026-28326 HIGH 8.8
-
CVE-2026-58480
Blocksy Companion unauthenticated arbitrary file upload leads to remote code executionCRITICAL 9.8
- PoC PUBLIC
- PATCH AVAILABLE
- CVE-2026-15158 CRITICAL 9.8
- CVE-2026-73532 CRITICAL 9.8
No CVEs on this page match the filters.
20 CVEs · page 13 of 23