ARCHIVE

CVEs published in September 2026 (page 5)

Vulnerabilities added to CVE Radar in September 2026, newest first.

  1. CVE-2026-76183
    Apache Tomcat authentication bypass for WebSocket endpoints Apache Software Foundation Apache Tomcat ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  2. CVE-2026-86248
    Apache Tomcat CLIENT_CERT authentication bypass (pre-auth) Apache Software Foundation Apache Tomcat ·
    CRITICAL 9.8
  3. CVE-2026-83021
    Oracle WebLogic Server unauthenticated HTTP remote takeover Oracle Oracle WebLogic Server ·
    CRITICAL 10
  4. CVE-2026-96587
    Dashcam Android Application embedded cloud credentials allow full storage access Viidure Dashcam Android Application ·
    CRITICAL 10
  5. CVE-2026-92229
    Forminator Forms pre-auth shortcode execution wpmudev Forminator Forms – Contact Form, Payment Form & Custom Form Builder ·
    • PoC PUBLIC
    CRITICAL 9.1
  6. CVE-2026-93485
    WordPress DOM-based cross-site scripting vulnerability Automattic WordPress ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.1
  7. CVE-2026-89055
    Customer Reviews for WooCommerce authorization bypass deletes media ivole Customer Reviews for WooCommerce ·
    • PoC PUBLIC
    CRITICAL 9.1
  8. CVE-2026-64703
    MacOS use-after-free lets an app cause denial-of-service Apple macOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  9. CVE-2026-64695
    IOS and iPadOS kernel memory corruption over network Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  10. CVE-2026-64697
    MacOS kernel memory corruption remote code execution Apple macOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  11. CVE-2026-64704
    MacOS type confusion pre-auth remote code execution Apple macOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  12. CVE-2026-64702
    MacOS sandbox escape lets an app break out of its sandbox Apple macOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  13. CVE-2026-64700
    IOS and iPadOS use-after-free may let an app terminate the system Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  14. CVE-2026-64694
    MacOS integer overflow leads to remote code execution potential Apple macOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  15. CVE-2026-64698
    MacOS kernel memory bug lets local apps crash or read kernel memory Apple macOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  16. CVE-2026-64720
    IOS and iPadOS race condition lets remote attacker crash system Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  17. CVE-2026-64727 CRITICAL 9.8
  18. CVE-2026-64726
    IOS and iPadOS memory corruption allows remote code execution Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  19. CVE-2026-64729
    IOS and iPadOS use-after-free lets an app cause system termination Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  20. CVE-2026-64733
    IOS and iPadOS app fingerprinting information disclosure Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
20 CVEs · page 5 of 23