ARCHIVE

CVEs published in September 2026 (page 13)

Vulnerabilities added to CVE Radar in September 2026, newest first.

  1. CVE-2026-65667
    Microsoft Teams missing authorization privilege elevation Microsoft Microsoft Teams ·
    • PATCH AVAILABLE
    CRITICAL 10
  2. CVE-2026-75874
    Firefox sandbox escape in Remote Settings Client Mozilla Firefox ·
    CRITICAL 10
  3. CVE-2026-65770
    Azure Managed Instance for Apache Cassandra argument injection allows remote code execution Microsoft Azure Managed Instance for Apache Cassandra ·
    • PATCH AVAILABLE
    CRITICAL 10
  4. CVE-2026-65816
    Azure Web Apps incorrect name resolution lets unauthenticated actor elevate privileges Microsoft Azure Web Apps ·
    • PATCH AVAILABLE
    CRITICAL 10
  5. CVE-2026-69555
    Azure ARC incorrect authorization lets remote attacker escalate privileges Microsoft Azure ARC ·
    • PATCH AVAILABLE
    CRITICAL 10
  6. CVE-2026-69502
    Azure SQL Database server-side request forgery privilege elevation Microsoft Azure SQL Database ·
    • PATCH AVAILABLE
    CRITICAL 10
  7. CVE-2026-70352
    Azure AI Language Authoring missing authentication allows privilege elevation Microsoft Azure AI Language Authoring ·
    • PATCH AVAILABLE
    CRITICAL 10
  8. CVE-2026-65381
    MacOS entitlement validation sandbox escape Apple macOS ·
    • PATCH AVAILABLE
    CRITICAL 10
  9. CVE-2026-69865
    Azure Container Registry authorization bypass via user-controlled key Microsoft Azure Container Registry ·
    • PATCH AVAILABLE
    CRITICAL 10
  10. CVE-2026-62874
    Azure Billing insufficient data authenticity privilege escalation Microsoft Azure Billing ·
    • PATCH AVAILABLE
    CRITICAL 10
  11. CVE-2026-88773
    Citrix ADC HTTP request/response smuggling allows pre-auth breach Citrix ADC ·
    • PATCH AVAILABLE
    CRITICAL 10
  12. CVE-2026-6837
    Zyxel WAX650S firmware command injection post-auth (administrator) Zyxel WAX650S firmware ·
    • PoC PUBLIC
    HIGH 7.2
  13. CVE-2026-69414
    Microsoft Malware Protection Engine elevation of privilege Microsoft Microsoft Malware Protection Engine ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  14. CVE-2026-54998
    Microsoft Exchange Online authorization bypass lets authorized users escalate privileges Microsoft Microsoft Exchange Online ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  15. CVE-2026-47301
    Microsoft Configuration Manager privilege escalation over network Microsoft Microsoft Configuration Manager ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  16. CVE-2026-20200
    Cisco Unified Computing System (Standalone) authenticated remote code execution Cisco Cisco Unified Computing System (Standalone) ·
    • PoC PUBLIC
    HIGH 8.8
  17. CVE-2026-28326
    Access Rights Manager unauthenticated remote code execution SolarWinds Access Rights Manager ·
    • PoC PUBLIC
    HIGH 8.8
  18. CVE-2026-58480
    Blocksy Companion unauthenticated arbitrary file upload leads to remote code execution Creative Themes Blocksy Companion ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
  19. CVE-2026-15158
    Blocksy Companion arbitrary file upload leading to remote code execution creativethemeshq Blocksy Companion ·
    CRITICAL 9.8
  20. CVE-2026-73532
    Fluent Forms Pro embedded malicious code in tampered 6.2.7 build WPManageNinja Fluent Forms Pro ·
    CRITICAL 9.8
20 CVEs · page 13 of 23