ARCHIVE

CVEs published in September 2026 (page 19)

Vulnerabilities added to CVE Radar in September 2026, newest first.

  1. CVE-2026-59822
    LiteLLM improper authentication allows unauthenticated MCP session creation BerriAI LiteLLM ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    HIGH 8.2
  2. CVE-2026-15583
    Grafana MCP Server confused-deputy header token exfiltration and SSRF Grafana Grafana MCP Server ·
    • PoC PUBLIC
    HIGH 8.6
  3. CVE-2026-48019
    Laravel framework CRLF injection in email validation laravel framework ·
    • PoC PUBLIC
    HIGH 8.9
  4. CVE-2026-15733
    WGDashboard command injection leads to remote code execution WGDashboard WGDashboard ·
    CRITICAL 9.8
  5. CVE-2026-72530
    TrueConf Server code injection allows remote unauthenticated code execution TrueConf Server ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9
  6. CVE-2021-23758
    Ajax.NET Professional deserialization pre-auth remote code execution Ajax.NET Professional Ajax.NET Professional ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
  7. CVE-2023-49105
    OwnCloud pre-auth improper authentication lets attackers modify or delete files ownCloud ownCloud ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    CRITICAL 9.8
  8. CVE-2025-39682
    Linux Kernel TLS zero-length record handling leads to remote code execution Linux Kernel ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
  9. CVE-2026-46817
    Oracle E-Business Suite Payments unauthenticated takeover Oracle E-Business Suite ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    CRITICAL 9.8
  10. CVE-2026-48939
    ICagenda file upload leads to remote PHP code execution iCagenda iCagenda ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    CRITICAL 9.8
  11. CVE-2026-48908
    SP Page Builder unrestricted file upload leads to remote code execution JoomShaper SP Page Builder ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    CRITICAL 9.8
  12. CVE-2026-56290
    Page Builder unauthenticated file upload leading to remote code execution Joomlack Page Builder ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    CRITICAL 9.8
  13. CVE-2026-72529
    TrueConf Server missing-authentication remote script execution via port 4307 TrueConf Server ·
    • CISA KEV
    • EXPLOITED
    • PATCH AVAILABLE
    CRITICAL 9.8
  14. CVE-2026-81578
    PaperCut NG/MF missing authentication lets unauthenticated remote modify configs PaperCut NG/MF ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
  15. CVE-2026-86218
    N-central pre-auth remote code execution N-able N-central ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
  16. CVE-2026-49869
    Kestra OSS unauthenticated remote code execution Kestra Kestra OSS ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    CRITICAL 10
  17. CVE-2026-48282
    ColdFusion path traversal pre-auth remote code execution Adobe ColdFusion ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    CRITICAL 10
  18. CVE-2026-16812
    VeloCloud Orchestrator pre-auth command injection in on‑prem VCO Arista VeloCloud Orchestrator ·
    • CISA KEV
    • EXPLOITED
    • PATCH AVAILABLE
    CRITICAL 10
  19. CVE-2026-5430
    WSO2 Multiple Products JWT verification bypass remote code execution WSO2 Multiple Products ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 10
  20. CVE-2026-93952
    VeloCloud Orchestrator improper input validation allows remote privileged access Arista VeloCloud Orchestrator ·
    • CISA KEV
    • EXPLOITED
    CRITICAL 10
20 CVEs · page 19 of 23