ARCHIVE

CVEs published in September 2026 (page 2)

Vulnerabilities added to CVE Radar in September 2026, newest first.

  1. CVE-2026-85103
    Quantum Security Gateway heap buffer overflow in certificate parsing Check Point Quantum Security Gateway ·
    CRITICAL 9.8
  2. CVE-2026-84390
    FortiMonitorOnSight source-code sensitive information disclosure Fortinet FortiMonitorOnSight ·
    CRITICAL 9.8
  3. CVE-2026-20353 CRITICAL 9.8
  4. CVE-2026-76443 CRITICAL 9.8
  5. CVE-2026-76441
    Cisco Secure Email and Web Manager improper access control allows remote takeover Cisco Cisco Secure Email and Web Manager ·
    CRITICAL 9.8
  6. CVE-2026-76440 CRITICAL 9.8
  7. CVE-2026-91843
    Quantum Security Management stack overflow allows unauthenticated remote code execution Check Point Quantum Security Management ·
    • PoC PUBLIC
    CRITICAL 9.8
  8. CVE-2026-20242
    Cisco Secure Firewall Management Center insecure deserialization remote root execution Cisco Cisco Secure Firewall Management Center (FMC) ·
    CRITICAL 9.8
  9. CVE-2026-20326
    Cisco Nexus Dashboard missing authentication for critical functions Cisco Cisco Nexus Dashboard ·
    CRITICAL 9.8
  10. CVE-2026-28324
    SolarWinds Observability Self-Hosted unauthenticated remote code execution SolarWinds Observability Self-Hosted ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  11. CVE-2026-26084 CRITICAL 9.9
  12. CVE-2026-80098
    Microsoft Copilot Studio signature verification flaw allows remote privilege escalation Microsoft Microsoft Copilot Studio ·
    • PATCH AVAILABLE
    CRITICAL 10
  13. CVE-2026-83711
    Entra authorization bypass via user-controlled key Microsoft Entra ·
    • PATCH AVAILABLE
    CRITICAL 10
  14. CVE-2026-44756 CRITICAL 10
  15. CVE-2026-80462
    Chef Automate unauthenticated privilege escalation via API gateway Progress Software Chef Automate ·
    • PATCH AVAILABLE
    CRITICAL 10
  16. CVE-2026-20130
    Cisco Identity Services Engine pre-auth remote code execution Cisco Cisco Identity Services Engine Software ·
    CRITICAL 10
  17. CVE-2026-20192
    Cisco Identity Services Engine improper access control vulnerability Cisco Cisco Identity Services Engine Software ·
    CRITICAL 10
  18. CVE-2026-76423
    Cisco Identity Services Engine unauthenticated admin access via REST API Cisco Cisco Identity Services Engine Software ·
    CRITICAL 10
  19. CVE-2026-69843
    Microsoft Fabric authentication bypass by spoofing allows privilege elevation Microsoft Microsoft Fabric ·
    • PATCH AVAILABLE
    CRITICAL 10
  20. CVE-2026-75528 HIGH 7.2
20 CVEs · page 2 of 23