ARCHIVE

CVEs published in September 2026 (page 7)

Vulnerabilities added to CVE Radar in September 2026, newest first.

  1. CVE-2026-34265
    SAP NetWeaver and ABAP Platform DIAG parsing memory corruption vulnerability SAP SAP NetWeaver and ABAP Platform ·
    CRITICAL 9.8
  2. CVE-2026-62815
    Windows 11 use-after-free in Microsoft QUIC allows remote code execution Microsoft Windows 11 version 23H2 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  3. CVE-2026-62878
    Windows Server DNS stack buffer overflow remote code execution Microsoft Windows Server 2012 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
  4. CVE-2026-62893
    Windows Server use-after-free in Windows Deployment Services allows remote code execution Microsoft Windows Server 2012 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  5. CVE-2026-65768
    Microsoft Teams for Android path traversal pre-auth remote code execution Microsoft Microsoft Teams for Android ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  6. CVE-2026-65791
    Windows iSCSI Target heap buffer overflow remote code execution Microsoft Windows 10 Version 1607 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  7. CVE-2026-26035 CRITICAL 9.8
  8. CVE-2026-19001
    MongoDB BI Connector ODBC Driver buffer overflow in metadata functions MongoDB BI Connector ODBC Driver ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  9. CVE-2026-75003
    Roundcube Webmail SVG url() bypass lets crafted images leak data Roundcube Webmail ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  10. CVE-2026-74936
    Firefox use-after-free in WebAssembly remote code execution Mozilla Firefox ·
    • PoC PUBLIC
    CRITICAL 9.8
  11. CVE-2026-74943
    Firefox use-after-free in ImageLib allows remote code execution Mozilla Firefox ·
    • PoC PUBLIC
    CRITICAL 9.8
  12. CVE-2026-74940 CRITICAL 9.8
  13. CVE-2026-74944
    Firefox use-after-free in DOM remote code execution Mozilla Firefox ·
    CRITICAL 9.8
  14. CVE-2026-74964 CRITICAL 9.8
  15. CVE-2026-74979 CRITICAL 9.8
  16. CVE-2026-74987
    Firefox memory-corruption remote attack Mozilla Firefox ·
    CRITICAL 9.8
  17. CVE-2026-74990 CRITICAL 9.8
  18. CVE-2026-74988
    Firefox pre-auth remote code execution Mozilla Firefox ·
    CRITICAL 9.8
  19. CVE-2026-74989
    Firefox memory-corruption remote code execution Mozilla Firefox ·
    CRITICAL 9.8
  20. CVE-2026-74985 CRITICAL 9.8
20 CVEs · page 7 of 23