ARCHIVE

CVEs published in September 2026 (page 16)

Vulnerabilities added to CVE Radar in September 2026, newest first.

  1. CVE-2026-65647
    Plesk Migrator symlink flaw allows authenticated users to run code as root WebPros Plesk Migrator ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.7
  2. CVE-2025-62593
    Ray code injection via browser leading to remote code execution Ray-Project Ray ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    HIGH 8.8
  3. CVE-2026-53266
    Linux Kernel ebtables SNAT ARP rewrite out-of-bounds write Linux Kernel ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  4. CVE-2026-14431
    Chrome V8 type confusion lets remote code execution Google Chrome ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  5. CVE-2026-50369
    Windows 10 Version 1607 Remote Desktop Services use-after-free elevation of privilege Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  6. CVE-2026-54121
    Windows 10 AD CS improper authorization privilege escalation Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  7. CVE-2026-65591
    N8n sanitizer bypass authenticated remote code execution n8n-io n8n ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  8. CVE-2026-42016
    Artifactory incorrect authorization privilege escalation JFrog Artifactory ·
    • CISA KEV
    • EXPLOITED
    • PATCH AVAILABLE
    HIGH 8.8
  9. CVE-2026-17633
    Langflow OSS code injection allows authenticated remote code execution IBM Langflow OSS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  10. CVE-2026-49179
    Windows Active Directory command injection remote code execution Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  11. CVE-2026-65640
    WordPress PostScript upload remote code execution via upload_files WordPress WordPress ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  12. CVE-2026-74939
    Firefox DOM navigation privilege escalation vulnerability Mozilla Firefox ·
    • PoC PUBLIC
    HIGH 8.8
  13. CVE-2026-10053
    GitLab package registry path traversal leads to authenticated remote code execution GitLab GitLab ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  14. CVE-2026-78905
    Chrome ANGLE type confusion allows remote code execution from a web page Google Chrome ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  15. CVE-2026-78938
    Chrome type confusion in V8 remote code execution Google Chrome ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  16. CVE-2026-79266
    Chrome DevTools use-after-free allows extension to execute code Google Chrome ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  17. CVE-2026-18729
    Langflow OSS authenticated remote code execution IBM Langflow OSS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  18. CVE-2026-65643
    CPanel eval injection authenticated code execution as root WebPros cPanel ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  19. CVE-2026-84645
    Jenkins remote code execution via crafted config.xml object injection Jenkins Project Jenkins ·
    • PoC PUBLIC
    HIGH 8.8
  20. CVE-2026-28618 HIGH 8.8
20 CVEs · page 16 of 23