ARCHIVE

CVEs published in September 2026 (page 6)

Vulnerabilities added to CVE Radar in September 2026, newest first.

  1. CVE-2026-64738
    IOS and iPadOS sandbox escape allows app to break out of sandbox Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  2. CVE-2026-64731
    MacOS path handling sandbox escape Apple macOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  3. CVE-2026-64746
    IOS and iPadOS authorization bypass lets apps add contacts Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  4. CVE-2026-64751
    IOS and iPadOS use-after-free remote code execution Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  5. CVE-2026-64767
    MacOS buffer overflow pre-auth remote code execution Apple macOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  6. CVE-2026-64762
    IOS and iPadOS out-of-bounds read may cause system termination Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  7. CVE-2026-64774
    IOS and iPadOS integer overflow leads to remote heap corruption Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  8. CVE-2026-64775
    IOS and iPadOS memory initialization flaw allows remote code execution Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  9. CVE-2026-64770
    IOS and iPadOS out-of-bounds write may allow remote impact Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  10. CVE-2026-64772
    IOS and iPadOS out-of-bounds write remote code execution Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  11. CVE-2026-64769
    IOS and iPadOS out-of-bounds write allows remote code execution Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  12. CVE-2026-64771
    IOS and iPadOS buffer overflow allows remote code execution Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  13. CVE-2026-12940
    Langflow OSS environment-variable RCE in MCP stdio launcher IBM Langflow OSS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
  14. CVE-2026-68771
    ComfyUI unsafe deserialization pre-auth remote code execution Comfy-Org ComfyUI ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
  15. CVE-2026-8457 CRITICAL 9.8
  16. CVE-2026-0163 CRITICAL 9.8
  17. CVE-2026-20272 CRITICAL 9.8
  18. CVE-2026-9205
    Langflow OSS weak key derivation allows remote secret compromise IBM Langflow OSS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  19. CVE-2026-28005
    Kadence WooCommerce Email Designer unauthenticated privilege escalation Nexcess Kadence WooCommerce Email Designer ·
    CRITICAL 9.8
  20. CVE-2026-56793
    OpenManage Server Administrator improper authentication remote access Dell OpenManage Server Administrator Managed Node (Patch) for Windows ·
    • PATCH AVAILABLE
    CRITICAL 9.8
20 CVEs · page 6 of 23