ARCHIVE

CVEs published in September 2026 (page 14)

Vulnerabilities added to CVE Radar in September 2026, newest first.

  1. CVE-2026-19598
    Pods – Custom Content Types and Fields privilege escalation via auth bypass sc0ttkclark Pods – Custom Content Types and Fields ·
    • PoC PUBLIC
    CRITICAL 9.8
  2. CVE-2026-15748
    Forminator Forms arbitrary file upload allows remote code execution wpmudev Forminator Forms – Contact Form, Payment Form & Custom Form Builder ·
    • PoC PUBLIC
    CRITICAL 9.8
  3. CVE-2026-78006
    The Events Calendar pre-auth remote code execution via widget unserialize stellarwp The Events Calendar ·
    • PoC PUBLIC
    CRITICAL 9.8
  4. CVE-2026-78159
    The Events Calendar remote code execution via widget parsing stellarwp The Events Calendar ·
    • PoC PUBLIC
    CRITICAL 9.8
  5. CVE-2026-54107
    Windows 10 Version 1607 race condition lets local users elevate privileges Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7
  6. CVE-2026-43813
    IOS and iPadOS code signing bypass allows malicious apps to run Apple iOS and iPadOS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.1
  7. CVE-2026-64725
    IOS and iPadOS out-of-bounds write can let a local app crash the device Apple iOS and iPadOS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.1
  8. CVE-2026-19650
    GitLab GraphQL GET-request mutation execution vulnerability GitLab GitLab ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.1
  9. CVE-2026-69451
    Windows 10 Version 1607 use-after-free in WMI allows privilege escalation Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.1
  10. CVE-2026-19760
    WP Fastest Cache – Stored XSS via Host header in Combine JS emrevona WP Fastest Cache – WordPress Cache Plugin ·
    HIGH 7.2
  11. CVE-2026-18978
    LiteSpeed Cache stored cross-site scripting via comments litespeedtech LiteSpeed Cache ·
    HIGH 7.2
  12. CVE-2026-83561
    Complianz GDPR/CCPA Cookie Consent Banner stored cross-site scripting via comments complianz Complianz GDPR/CCPA Cookie Consent Banner ·
    HIGH 7.2
  13. CVE-2026-78906
    Chrome ANGLE race condition remote code execution Google Chrome ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.5
  14. CVE-2026-85045
    Chrome V8 race condition allows remote code execution Google Chrome ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.5
  15. CVE-2015-5287
    Automatic Bug Reporting Tool symlink local privilege escalation Red Hat Automatic Bug Reporting Tool ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    HIGH 7.8
  16. CVE-2026-46680
    Containerd runAsNonRoot bypass via large numeric User value containerd containerd ·
    • PoC PUBLIC
    HIGH 7.8
  17. CVE-2026-53362
    Linux Kernel IPv6 frag handling local privilege escalation Linux Kernel ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  18. CVE-2026-49176
    Windows 10/Server privilege escalation in WalletService (local) Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  19. CVE-2026-54992
    Windows 10 Version 1607 heap-based buffer overflow local code execution Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  20. CVE-2026-58635
    Windows 10 Version 1809 Narrator Braille command injection local privilege elevation Microsoft Windows 10 Version 1809 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
20 CVEs · page 14 of 23