ARCHIVE

CVEs published in September 2026 (page 22)

Vulnerabilities added to CVE Radar in September 2026, newest first.

  1. CVE-2026-72898
    Metabase SQL injection in reset_password allows remote admin takeover Metabase Metabase ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 10
  2. CVE-2026-15410
    SMA1000 Appliances post-auth code injection allows OS command execution SonicWall SMA1000 Appliances ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    HIGH 7.2
  3. CVE-2026-20316
    Cisco Secure Firewall Management Center hard-coded low-privileged login Cisco Secure Firewall Management Center (FMC) ·
    • CISA KEV
    • EXPLOITED
    MEDIUM 5.3
  4. CVE-2026-63077
    TeamCity unauthenticated remote code execution via agent polling JetBrains TeamCity ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
  5. CVE-2026-73570
    Zimbra Collaboration Suite OS command injection via SMTP/SNMP Synacor Zimbra Collaboration Suite (ZCS) ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.9
  6. CVE-2026-55040
    SharePoint weak authentication pre-auth bypass vulnerability Microsoft SharePoint ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.1
  7. CVE-2026-58644
    SharePoint deserialization remote code execution Microsoft SharePoint ·
    • CISA KEV
    • EXPLOITED
    • PATCH AVAILABLE
    CRITICAL 9.8
  8. CVE-2026-9198
    Langflow unauthenticated remote code execution IBM Langflow ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
  9. CVE-2026-63030
    WordPress Core REST API route confusion remote code execution WordPress Core ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
  10. CVE-2026-16232
    SmartConsole authentication bypass allows full admin takeover Check Point SmartConsole ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    CRITICAL 9.8
  11. CVE-2026-71362
    Adobe Commerce and Magento incorrect authorization pre-auth privilege escalation Adobe Commerce and Magento ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    CRITICAL 9.1
  12. CVE-2026-94127
    BIG-IP APM heap buffer overflow remote code execution F5 BIG-IP APM ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
  13. CVE-2026-83548
    SMA1000 Appliances pre-auth server-side request forgery (SSRF) SonicWall SMA1000 Appliances ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    CRITICAL 10
  14. CVE-2026-76460
    Cisco Identity Services Engine API authentication bypass Cisco Identity Services Engine ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    CRITICAL 10
  15. CVE-2026-75650
    Adobe Commerce and Magento remote code execution via template engine Adobe Commerce and Magento ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    CRITICAL 10
  16. CVE-2026-85706
    GitLab repository commits API path traversal lets unauthenticated read files GitLab Community Edition and Enterprise Edition ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 10
  17. CVE-2026-87902
    Remote file inclusion via page-template resolution (get_page_template) WordPress Core ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.1
  18. CVE-2026-65660
    code injection in SharePoint server allowing remote code execution Microsoft SharePoint ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  19. CVE-2026-67279
    Improper workflow enforcement in RouterOS SSH allows unauthenticated file writes MikroTik RouterOS ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    MEDIUM 6.5
  20. CVE-2026-88771
    Improper input validation in NetScaler ADC and Gateway allowing remote command execution Citrix NetScaler ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
20 CVEs · page 22 of 23