ARCHIVE
CVEs published in September 2026 (page 21)
Vulnerabilities added to CVE Radar in September 2026, newest first.
-
CVE-2026-8037
LoadMaster command injection pre-auth remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-25089
FortiSandbox OS command injection unauthenticated remote command executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-86060
RouterOS SSH login username handling lets unauthenticated users escalate privilegesCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-85102
Quantum Security Gateway improper certificate validation lets unauthenticated attacker run codeCRITICAL 9.8
- CISA KEV
- EXPLOITED
-
CVE-2026-76461
Cisco Secure Email Gateway SQL injection leads to pre-auth remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-93616
Quantum Security Management directory traversal allows unauthenticated code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-20079
Cisco Secure Firewall Management Center authentication bypass and RCECRITICAL 10
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-15409
SonicWall SMA1000 SSRF allows unauthenticated request forgingCRITICAL 10
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-0770
Langflow exec_globals pre-auth remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-8452
Citrix NetScaler ADC and Gateway memory overflow pre-auth remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-50522
SharePoint deserialization pre-auth remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-56164
SharePoint Server missing authentication allows privilege elevationCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-59310
VMware vCenter directory traversal lets network attacker execute codeCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-65400
MacOS Screen Sharing improper authentication lets network attacker bypass credentialsCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-19478
GitLab GraphQL directive lets unauthenticated users modify public projectsCRITICAL 9.1
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-18577
N-central authentication bypass that can enable account takeoverHIGH 8.1
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-56291
Balbooa Forms unauthenticated file upload remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-9586
Switchvox SQL injection allows unauthenticated remote SQL executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-60004
Gitea code injection via diffpatch API remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-82329
Artifactory authentication weakness allows pre-auth admin takeoverCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
No CVEs on this page match the filters.
20 CVEs · page 21 of 23