ARCHIVE

CVEs published in September 2026 (page 20)

Vulnerabilities added to CVE Radar in September 2026, newest first.

  1. CVE-2026-56155
    Active Directory Federation Services insufficient access control local privilege elevation Microsoft Active Directory Federation Services ·
    • CISA KEV
    • EXPLOITED
    • PATCH AVAILABLE
    HIGH 7.8
  2. CVE-2026-83549
    SMA1000 Appliances OS command injection requiring admin credentials SonicWall SMA1000 Appliances ·
    • CISA KEV
    • EXPLOITED
    HIGH 7.8
  3. CVE-2019-1068
    SQL Server remote code execution in internal function handling Microsoft SQL Server ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    HIGH 8.8
  4. CVE-2026-7273
    Zyxel GS1900 Series Switches stack-based buffer overflow in CGI Zyxel GS1900 Series Switches ·
    • CISA KEV
    • EXPLOITED
    HIGH 8.8
  5. CVE-2026-68820
    Windows Ancillary Function Driver for WinSock use-after-free local privilege escalation Microsoft Windows Ancillary Function Driver for WinSock ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7
  6. CVE-2026-81963
    Windows local privilege escalation in Windows Update Stack (link following) Microsoft Windows ·
    • CISA KEV
    • EXPLOITED
    • PATCH AVAILABLE
    HIGH 7.8
  7. CVE-2026-85880
    Windows ALPC heap overflow local privilege escalation Microsoft Windows ·
    • CISA KEV
    • EXPLOITED
    • PATCH AVAILABLE
    HIGH 7.8
  8. CVE-2008-4128 HIGH 8.1
  9. CVE-2026-55255
    Langflow authorization bypass lets authenticated users run other users' flows Langflow Langflow ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    HIGH 8.4
  10. CVE-2026-45659
    SharePoint Server deserialization flaw allows authenticated remote code execution Microsoft SharePoint Server ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  11. CVE-2026-85046
    Chromium V8 type confusion remote code execution Google Chromium V8 ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  12. CVE-2026-87491
    Chromium V8 out-of-bounds write remote code execution Google Chromium V8 ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  13. CVE-2025-68686
    FortiOS exposure of sensitive information to unauthenticated remote actors Fortinet FortiOS ·
    • CISA KEV
    • EXPLOITED
    MEDIUM 5.9
  14. CVE-2026-60137
    WordPress Core SQL injection via author__not_in parameter WordPress Core ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    MEDIUM 5.9
  15. CVE-2026-84869
    ScreenConnect missing authorization lets active-session attacker transfer and run files ConnectWise ScreenConnect ·
    • CISA KEV
    • EXPLOITED
    CRITICAL 9.9
  16. CVE-2026-67277
    RouterOS missing-auth btest service kernel crash and memory disclosure MikroTik RouterOS ·
    • CISA KEV
    • EXPLOITED
    • PATCH AVAILABLE
    HIGH 8.2
  17. CVE-2026-34486
    Tomcat encrypt interceptor bypass exposes sensitive data Apache Tomcat ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    HIGH 7.5
  18. CVE-2025-25249
    Fortinet FortiOS and FortiSwitchManager heap buffer overflow remote code execution Fortinet Multiple Products ·
    • CISA KEV
    • EXPLOITED
    CRITICAL 9.8
  19. CVE-2026-39808
    FortiSandbox OS command injection unauthenticated remote code execution Fortinet FortiSandbox ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    CRITICAL 9.8
  20. CVE-2026-33824
    Internet Key Exchange (IKE) Service Extensions double free remote code execution Microsoft Internet Key Exchange (IKE) Service Extensions ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
20 CVEs · page 20 of 23