Daily High-Risk Vuln Digest 2026-09-09 (78)
Daily High-Risk Vulnerability Digest · 2026-09-09
78 high-value vulnerabilities included (actively exploited [KEV], or CVSS ≥ 9.0 in widely deployed vendors & OSS).
今日收录
- CVE-2026-26084 —
9.9— A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to … - CVE-2026-68839 —
9.8— Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network. - CVE-2026-69408 —
9.8— Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. - CVE-2026-69463 —
9.8— Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network. - CVE-2026-69491 —
9.8— Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a network. - CVE-2026-69493 —
9.8— Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network. - CVE-2026-69496 —
9.8— Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network. - CVE-2026-69525 —
9.8— Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. - CVE-2026-69579 —
9.8— Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. - CVE-2026-69586 —
9.8— Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network. - CVE-2026-69590 —
9.8— Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine - CVE-2026-69595 —
9.8— Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network. - CVE-2026-69715 —
9.8— Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a network. - CVE-2026-69730 —
9.8— Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. - CVE-2026-69768 —
9.8— Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to execute code over a network. - CVE-2026-69769 —
9.8— Heap-based buffer overflow in Windows HTTP Print Provider allows an unauthorized attacker to execute code over a network. - CVE-2026-69829 —
9.8— Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network. - CVE-2026-69845 —
9.8— Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. - CVE-2026-69910 —
9.8— Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network. - CVE-2026-70296 —
9.8— Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network. - CVE-2026-72950 —
9.8— Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine - CVE-2026-72979 —
9.8— Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network. - CVE-2026-72982 —
9.8— Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network. - CVE-2026-72983 —
9.8— Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network. - CVE-2026-73009 —
9.8— Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. - CVE-2026-73010 —
9.8— Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network. - CVE-2026-73025 —
9.8— Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network. - CVE-2026-78445 —
9.8— Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network. - CVE-2026-78509 —
9.8— Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. - CVE-2026-81352 —
9.8— Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code over a network. - CVE-2026-87534 —
9.8— Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium s… - CVE-2026-87544 —
9.8— Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Lo… - CVE-2026-87595 —
9.8— Server-side request forgery in Mobile in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security sever… - CVE-2026-41871 —
9.8— Missing Authorization, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.10 through 1.22. Us… - CVE-2026-56207 —
9.8— Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user. This issue affects Apache Impala: >=4.0.0. Users are… - CVE-2026-85102 —
9.8— Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway. [KEV] - CVE-2026-85103 —
9.8— A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems. - CVE-2026-87438 —
9.6— Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) - CVE-2026-87448 —
9.6— Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low) - CVE-2026-87455 —
9.6— Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) - CVE-2026-87464 —
9.6— Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) - CVE-2026-87470 —
9.6— Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security sever… - CVE-2026-87474 —
9.6— Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) - CVE-2026-87488 —
9.6— Use after free in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) - CVE-2026-87492 —
9.6— Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) - CVE-2026-87494 —
9.6— Use after free in Browser in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium sec… - CVE-2026-87500 —
9.6— Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity… - CVE-2026-87504 —
9.6— Use after free in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security seve… - CVE-2026-87512 —
9.6— Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) - CVE-2026-87520 —
9.6— Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) - CVE-2026-87526 —
9.6— Use after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security… - CVE-2026-87527 —
9.6— Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) - CVE-2026-87528 —
9.6— Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Mediu… - CVE-2026-87529 —
9.6— Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) - CVE-2026-87547 —
9.6— Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML pa… - CVE-2026-87558 —
9.6— Use after free in Payments in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) - CVE-2026-87581 —
9.6— Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium secu… - CVE-2026-87607 —
9.6— Use after free in Device in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) - CVE-2026-87609 —
9.6— Use after free in Sharing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium) - CVE-2026-87621 —
9.6— Out of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity:… - CVE-2026-87634 —
9.6— Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low) - CVE-2026-87637 —
9.6— Use after free in Extensions in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) - CVE-2026-87638 —
9.6— Out of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) - CVE-2026-87643 —
9.6— Integer overflow in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medi… - CVE-2026-87646 —
9.6— Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) - CVE-2026-87650 —
9.6— Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) - CVE-2026-87654 —
9.6— Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) - CVE-2026-86751 —
9.6— Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note fields, allowing authenticated users to read arbitrary server files and issue server-side HTTP requests. Attackers can submit markdown image … - CVE-2026-78997 —
9.3— UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin. An att… - CVE-2026-69356 —
9.3— Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. - CVE-2026-75156 —
9.1— Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure ADid_tokens during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure… - CVE-2026-69641 —
9.1— Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. - CVE-2026-41869 —
9.1— Missing Authorization, Improper Resource Shutdown and Job Interruption vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.10 through 1.22. Users are recommended to upgrade to v… - CVE-2026-87613 —
9.0— Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security sev… - CVE-2026-19490 —
0.0— Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL V… [KEV] - CVE-2025-25249 —
0.0— Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets. [KEV] - CVE-2026-87491 —
0.0— Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers t… [KEV] - CVE-2026-20079 —
0.0— Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unau… [KEV]
Sources: NVD / CISA KEV. Auto-collected and generated by CaptainAI Labs AI agents.