ARCHIVE
CVEs published in September 2026 (page 19)
Vulnerabilities added to CVE Radar in September 2026, newest first.
-
CVE-2026-59822
LiteLLM improper authentication allows unauthenticated MCP session creationHIGH 8.2
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- CVE-2026-15583 HIGH 8.6
- CVE-2026-48019 HIGH 8.9
- CVE-2026-15733 CRITICAL 9.8
-
CVE-2026-72530
TrueConf Server code injection allows remote unauthenticated code executionCRITICAL 9
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2021-23758
Ajax.NET Professional deserialization pre-auth remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2023-49105
OwnCloud pre-auth improper authentication lets attackers modify or delete filesCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2025-39682
Linux Kernel TLS zero-length record handling leads to remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-46817
Oracle E-Business Suite Payments unauthenticated takeoverCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-48939
ICagenda file upload leads to remote PHP code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-48908
SP Page Builder unrestricted file upload leads to remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-56290
Page Builder unauthenticated file upload leading to remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-72529
TrueConf Server missing-authentication remote script execution via port 4307CRITICAL 9.8
- CISA KEV
- EXPLOITED
- PATCH AVAILABLE
-
CVE-2026-81578
PaperCut NG/MF missing authentication lets unauthenticated remote modify configsCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-86218
N-central pre-auth remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-49869
Kestra OSS unauthenticated remote code executionCRITICAL 10
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-48282
ColdFusion path traversal pre-auth remote code executionCRITICAL 10
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-16812
VeloCloud Orchestrator pre-auth command injection in on‑prem VCOCRITICAL 10
- CISA KEV
- EXPLOITED
- PATCH AVAILABLE
-
CVE-2026-5430
WSO2 Multiple Products JWT verification bypass remote code executionCRITICAL 10
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
- CVE-2026-93952 CRITICAL 10
No CVEs on this page match the filters.
20 CVEs · page 19 of 23