ARCHIVE

CVEs published in September 2026 (page 15)

Vulnerabilities added to CVE Radar in September 2026, newest first.

  1. CVE-2026-50343
    Windows Install Service local privilege escalation Microsoft Windows 10 Version 1809 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  2. CVE-2026-50402
    Windows NTFS numeric conversion local privilege escalation Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  3. CVE-2026-28912
    MacOS local privilege escalation via logic issue Apple macOS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  4. CVE-2026-39875
    MacOS permission flaw local privilege escalation Apple macOS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  5. CVE-2026-64747
    IOS and iPadOS buffer overflow allows kernel code execution Apple iOS and iPadOS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  6. CVE-2026-14266
    7-Zip XZ heap buffer overflow remote code execution 7-Zip 7-Zip ·
    • PoC PUBLIC
    HIGH 7.8
  7. CVE-2026-54984
    Windows 10 Version 1607 heap buffer overflow local code execution Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  8. CVE-2026-62735
    Windows HTTP.sys heap buffer overflow local privilege escalation Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  9. CVE-2026-62737
    Windows 11 untrusted pointer dereference local privilege escalation Microsoft Windows 11 Version 24H2 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  10. CVE-2026-66804
    Windows 10 Version 22H2 cross-device service local privilege escalation Microsoft Windows 10 Version 22H2 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  11. CVE-2026-69328
    Windows 10 Version 1607 untrusted search path local privilege escalation Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  12. CVE-2026-49881
    Android InCallController logic error local privilege escalation Google Android ·
    • PoC PUBLIC
    HIGH 7.8
  13. CVE-2026-43783
    MacOS race condition lets low-privileged app gain root Apple macOS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  14. CVE-2026-43786
    MacOS entitlement check bypass lets local user gain root privileges Apple macOS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  15. CVE-2026-84568
    MacOS path traversal remote code execution (root) Apple macOS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  16. CVE-2026-87886
    Acronis Backup local privilege escalation via insecure permissions Acronis Backup ·
    • CISA KEV
    • EXPLOITED
    • PATCH AVAILABLE
    HIGH 7.8
  17. CVE-2026-62911
    Microsoft Exchange Server authentication bypass (capture-replay) Microsoft Microsoft Exchange Server 2016 Cumulative Update 23 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8
  18. CVE-2026-50338
    Azure Spring Apps improper authentication privilege escalation Microsoft Azure Spring Apps ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.2
  19. CVE-2026-53413
    Zoom Clients annotator buffer overwrite remote code execution Zoom Communications Zoom Clients ·
    • PoC PUBLIC
    HIGH 8.3
  20. CVE-2026-85048
    Chrome use-after-free in Compositing allows renderer escape and code execution Google Chrome ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.3
20 CVEs · page 15 of 23