ARCHIVE

CVEs published in September 2026 (page 18)

Vulnerabilities added to CVE Radar in September 2026, newest first.

  1. CVE-2026-58048
    CPanel SQL injection lets low-privilege users run SQL as root WebPros cPanel ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.4
  2. CVE-2026-77179
    Docker Sandboxes virtio-fs symlink escape to host code execution Docker Docker Sandboxes ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.4
  3. CVE-2026-14382
    Chrome ANGLE sandbox escape via crafted HTML Google Chrome ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.6
  4. CVE-2026-76036
    Chrome Dawn buffer overflow remote code execution Google Chrome ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.6
  5. CVE-2026-78904
    Chrome ANGLE type confusion remote code execution Google Chrome ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.6
  6. CVE-2026-87492
    Chrome DevTools incorrect authorization allows remote code execution Google Chrome ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.6
  7. CVE-2026-12944
    Langflow OSS remote code execution as root via component imports IBM Langflow OSS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.6
  8. CVE-2026-19295
    Langflow OSS authenticated OS command execution via crafted flow IBM Langflow OSS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.9
  9. CVE-2026-67401
    CPanel EmailTrack SQL injection remote code execution WebPros cPanel ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.9
  10. CVE-2026-14802
    Create-react-app os command injection in react-dev-utils openBrowser react create-react-app ·
    • PoC PUBLIC
    HIGH 7.3
  11. CVE-2026-18556
    N-central authentication bypass via alternate path (pre-auth) N-able N-central ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    HIGH 7.4
  12. CVE-2023-4346
    KNX Protocol Connection Authorization Option 1 account lockout vulnerability KNX Association KNX Protocol Connection Authorization Option 1 ·
    • CISA KEV
    • EXPLOITED
    HIGH 7.5
  13. CVE-2026-42018
    Artifactory improper authentication returns internal anonymous token JFrog Artifactory ·
    • CISA KEV
    • EXPLOITED
    • PATCH AVAILABLE
    HIGH 7.5
  14. CVE-2026-73633
    Apache Struts JSON plugin uncontrolled resource consumption Apache Software Foundation Apache Struts ·
    • PoC PUBLIC
    HIGH 7.5
  15. CVE-2026-65343
    IOS and iPadOS use-after-free causes remote denial of service Apple iOS and iPadOS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.5
  16. CVE-2026-63072
    OpenSSL CMS heap out-of-bounds write via CMS_decrypt OpenSSL OpenSSL ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.5
  17. CVE-2026-84543
    MacOS out-of-bounds SMB client access from a remote server Apple macOS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.5
  18. CVE-2026-42533
    NGINX Plus heap buffer overflow with regex map leading to remote code execution F5 NGINX Plus ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.1
  19. CVE-2021-27137
    DD-WRT UPnP stack buffer overflow allows remote code execution DD-WRT DD-WRT ·
    • CISA KEV
    • EXPLOITED
    • PATCH AVAILABLE
    HIGH 8.1
  20. CVE-2026-63520
    Microsoft SharePoint Enterprise Server 2016 improper input validation RCE Microsoft Microsoft SharePoint Enterprise Server 2016 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.1
20 CVEs · page 18 of 23