ARCHIVE

CVEs published in September 2026 (page 4)

Vulnerabilities added to CVE Radar in September 2026, newest first.

  1. CVE-2026-43790 CRITICAL 9.1
  2. CVE-2026-84625
    IOS and iPadOS permissions issue lets an app fingerprint the user Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.1
  3. CVE-2026-86881
    IOS and iPadOS certificate validation bypass Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.1
  4. CVE-2026-92034 CRITICAL 9.1
  5. CVE-2026-92038
    Firefox mitigation bypass in Remote Settings Client Mozilla Firefox ·
    CRITICAL 9.1
  6. CVE-2026-92041 CRITICAL 9.1
  7. CVE-2026-92051 CRITICAL 9.1
  8. CVE-2026-92050
    Firefox sandbox escape via XPConnect race condition Mozilla Firefox ·
    CRITICAL 9.1
  9. CVE-2026-92057
    Firefox Enterprise Policies mitigation bypass Mozilla Firefox ·
    CRITICAL 9.1
  10. CVE-2026-92075
    Firefox mitigation bypass in Networking component Mozilla Firefox ·
    CRITICAL 9.1
  11. CVE-2026-92079
    Firefox Widget Win32 mitigation bypass Mozilla Firefox ·
    CRITICAL 9.1
  12. CVE-2026-83944
    Azure Logic Apps pre-auth privilege escalation via improper access control Microsoft Azure Logic Apps ·
    • PATCH AVAILABLE
    CRITICAL 9.1
  13. CVE-2026-93765 CRITICAL 9.1
  14. CVE-2026-89282
    Apache Lounge Windows insecure install directory permissions allow file modification Apache HTTP Server Project Apache Lounge Windows ·
    • PATCH AVAILABLE
    CRITICAL 9.1
  15. CVE-2026-86350
    Apache Tomcat HTTP/2 request smuggling regression Apache Software Foundation Apache Tomcat ·
    • PoC PUBLIC
    CRITICAL 9.1
  16. CVE-2026-86246
    Apache Tomcat Native insecure-default TLS options Apache Software Foundation Apache Tomcat Native ·
    CRITICAL 9.1
  17. CVE-2026-77987
    GitHub Enterprise Server SSRF leads to remote code execution GitHub Enterprise Server ·
    • PATCH AVAILABLE
    CRITICAL 9.3
  18. CVE-2026-70757
    Oracle WebLogic Server unauthenticated remote code execution via T3/IIOP Oracle Oracle WebLogic Server ·
    CRITICAL 9.8
  19. CVE-2026-70748
    Oracle WebLogic Server unauthenticated remote takeover via T3/IIOP Oracle Oracle WebLogic Server ·
    CRITICAL 9.8
  20. CVE-2026-70756
    Oracle WebLogic Server unauthenticated remote takeover via T3/IIOP Oracle Oracle WebLogic Server ·
    CRITICAL 9.8
20 CVEs · page 4 of 23