ARCHIVE
CVEs published in September 2026 (page 20)
Vulnerabilities added to CVE Radar in September 2026, newest first.
-
CVE-2026-56155
Active Directory Federation Services insufficient access control local privilege elevationHIGH 7.8
- CISA KEV
- EXPLOITED
- PATCH AVAILABLE
-
CVE-2026-83549
SMA1000 Appliances OS command injection requiring admin credentialsHIGH 7.8
- CISA KEV
- EXPLOITED
-
CVE-2019-1068
SQL Server remote code execution in internal function handlingHIGH 8.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-7273
Zyxel GS1900 Series Switches stack-based buffer overflow in CGIHIGH 8.8
- CISA KEV
- EXPLOITED
-
CVE-2026-68820
Windows Ancillary Function Driver for WinSock use-after-free local privilege escalationHIGH 7
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-81963
Windows local privilege escalation in Windows Update Stack (link following)HIGH 7.8
- CISA KEV
- EXPLOITED
- PATCH AVAILABLE
-
CVE-2026-85880
Windows ALPC heap overflow local privilege escalationHIGH 7.8
- CISA KEV
- EXPLOITED
- PATCH AVAILABLE
-
CVE-2008-4128
Cisco IOS cross-site request forgery lets remote attackers run commandsHIGH 8.1
- CISA KEV
- EXPLOITED
-
CVE-2026-55255
Langflow authorization bypass lets authenticated users run other users' flowsHIGH 8.4
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-45659
SharePoint Server deserialization flaw allows authenticated remote code executionHIGH 8.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-85046
Chromium V8 type confusion remote code executionHIGH 8.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-87491
Chromium V8 out-of-bounds write remote code executionHIGH 8.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2025-68686
FortiOS exposure of sensitive information to unauthenticated remote actorsMEDIUM 5.9
- CISA KEV
- EXPLOITED
-
CVE-2026-60137
WordPress Core SQL injection via author__not_in parameterMEDIUM 5.9
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-84869
ScreenConnect missing authorization lets active-session attacker transfer and run filesCRITICAL 9.9
- CISA KEV
- EXPLOITED
-
CVE-2026-67277
RouterOS missing-auth btest service kernel crash and memory disclosureHIGH 8.2
- CISA KEV
- EXPLOITED
- PATCH AVAILABLE
-
CVE-2026-34486
Tomcat encrypt interceptor bypass exposes sensitive dataHIGH 7.5
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2025-25249
Fortinet FortiOS and FortiSwitchManager heap buffer overflow remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
-
CVE-2026-39808
FortiSandbox OS command injection unauthenticated remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-33824
Internet Key Exchange (IKE) Service Extensions double free remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
No CVEs on this page match the filters.
20 CVEs · page 20 of 23