ARCHIVE
CVEs published in September 2026 (page 22)
Vulnerabilities added to CVE Radar in September 2026, newest first.
-
CVE-2026-72898
Metabase SQL injection in reset_password allows remote admin takeoverCRITICAL 10
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-15410
SMA1000 Appliances post-auth code injection allows OS command executionHIGH 7.2
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-20316
Cisco Secure Firewall Management Center hard-coded low-privileged loginMEDIUM 5.3
- CISA KEV
- EXPLOITED
-
CVE-2026-63077
TeamCity unauthenticated remote code execution via agent pollingCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-73570
Zimbra Collaboration Suite OS command injection via SMTP/SNMPHIGH 8.9
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-55040
SharePoint weak authentication pre-auth bypass vulnerabilityCRITICAL 9.1
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-58644
SharePoint deserialization remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PATCH AVAILABLE
-
CVE-2026-9198
Langflow unauthenticated remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-63030
WordPress Core REST API route confusion remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-16232
SmartConsole authentication bypass allows full admin takeoverCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-71362
Adobe Commerce and Magento incorrect authorization pre-auth privilege escalationCRITICAL 9.1
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-94127
BIG-IP APM heap buffer overflow remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-83548
SMA1000 Appliances pre-auth server-side request forgery (SSRF)CRITICAL 10
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-76460
Cisco Identity Services Engine API authentication bypassCRITICAL 10
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-75650
Adobe Commerce and Magento remote code execution via template engineCRITICAL 10
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-85706
GitLab repository commits API path traversal lets unauthenticated read filesCRITICAL 10
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-87902
Remote file inclusion via page-template resolution (get_page_template)HIGH 8.1
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-65660
code injection in SharePoint server allowing remote code executionHIGH 8.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-67279
Improper workflow enforcement in RouterOS SSH allows unauthenticated file writesMEDIUM 6.5
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-88771
Improper input validation in NetScaler ADC and Gateway allowing remote command executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
No CVEs on this page match the filters.
20 CVEs · page 22 of 23