ARCHIVE

CVEs published in September 2026 (page 17)

Vulnerabilities added to CVE Radar in September 2026, newest first.

  1. CVE-2026-28609 HIGH 8.8
  2. CVE-2026-65374
    MacOS WebDAV memory corruption remote code execution Apple macOS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  3. CVE-2026-58704
    Pixel cellular modem permission bypass privilege escalation Google Pixel ·
    • CISA KEV
    • EXPLOITED
    HIGH 8.8
  4. CVE-2026-86950
    Apple CoreGraphics out-of-bounds write leads to code execution Apple Multiple Products ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  5. CVE-2026-64638
    WordPress pre-auth reflected XSS on login page WordPress WordPress ·
    • PoC PUBLIC
    HIGH 8.9
  6. CVE-2026-48710
    Starlette Host header validation bypass alters reconstructed request URL Kludex Starlette ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    MEDIUM 6.5
  7. CVE-2026-89274
    WP Recipe Maker arbitrary shortcode execution in metadata brechtvds WP Recipe Maker ·
    • PoC PUBLIC
    CRITICAL 9.1
  8. CVE-2026-93399
    Bookly Insecure direct object reference exposes order tokens ladela Online Scheduling and Appointment Booking System – Bookly ·
    • PoC PUBLIC
    CRITICAL 9.1
  9. CVE-2026-84388
    FortiPAM Chrome Extension information disclosure via UI layer restriction Fortinet FortiPAM Chrome Extension ·
    • PoC PUBLIC
    CRITICAL 9.6
  10. CVE-2026-15826
    User Profile Builder authentication bypass lets unauthenticated users become admin cozmoslabs User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor ·
    • PoC PUBLIC
    CRITICAL 9.8
  11. CVE-2026-12793
    JetFormBuilder privilege escalation lets unauthenticated attacker create admin jetmonsters JetFormBuilder — Dynamic Blocks Form Builder ·
    • PoC PUBLIC
    CRITICAL 9.8
  12. CVE-2026-82901
    Ultra Addons for Contact Form 7 arbitrary file upload (unauthenticated) themefic Ultra Addons for Contact Form 7 ·
    • PoC PUBLIC
    CRITICAL 9.8
  13. CVE-2026-20303
    Cisco Catalyst SD-WAN Controller improper input validation remote code execution Cisco Cisco Catalyst SD-WAN Controller ·
    • PoC PUBLIC
    CRITICAL 9.9
  14. CVE-2026-43825
    Apache OpenNLP LibSVM untrusted Java deserialization remote code execution Apache Software Foundation Apache OpenNLP :: Core :: ML :: LibSVM ·
    • PATCH AVAILABLE
    HIGH 7.3
  15. CVE-2026-20217
    Cisco Secure Endpoint ClamAV PESpin parser remote denial-of-service Cisco Cisco Secure Endpoint ·
    • PoC PUBLIC
    HIGH 7.5
  16. CVE-2026-13181
    Telerik UI for ASP.NET AJAX pre-auth remote code execution Progress Software Telerik UI for ASP.NET AJAX ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.1
  17. CVE-2026-67276
    RouterOS SSH RSA key validation authentication bypass MikroTik RouterOS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.1
  18. CVE-2026-19516
    Grafana MCP Server server-side request forgery (SSRF) Grafana Grafana MCP Server ·
    • PoC PUBLIC
    CRITICAL 9.1
  19. CVE-2026-82078
    PaperCut NG/MF unsafe dynamic class loading allows remote code execution PaperCut NG/MF ·
    • CISA KEV
    • EXPLOITED
    • PATCH AVAILABLE
    CRITICAL 9.1
  20. CVE-2026-48356
    Adobe Commerce unrestricted file upload leading to remote code execution Adobe Adobe Commerce ·
    • PoC PUBLIC
    CRITICAL 9.3
20 CVEs · page 17 of 23