Monthly Vuln Summary 2026-09 (42)

Monthly Vulnerability Summary · 2026-09

42 CVEs added to CISA KEV this month (actively exploited; 0 ransomware-related).

All CVEs

  • CVE-2026-86950 — — — Apple Multiple Products — Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.
  • CVE-2026-88772 — — — Citrix NetScaler — Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code executi…
  • CVE-2026-88771 — — — Citrix NetScaler — Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.
  • CVE-2026-67279 — — — MikroTik RouterOS — Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec reques…
  • CVE-2026-65660 — — — Microsoft SharePoint — Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.
  • CVE-2026-87902 — — — WordPress Core — WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local .php …
  • CVE-2026-5430 — — — WSO2 Multiple Products — WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote cod…
  • CVE-2026-71362 — — — **Adobe Commerce and Magento ** — Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resour…
  • CVE-2026-93952 — — — Arista VeloCloud Orchestrator — Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and imp…
  • CVE-2026-94127 — — — F5 BIG-IP APM — F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unau…
  • CVE-2026-93616 — — — Check Point Multiple Products — Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that all…
  • CVE-2026-85102 — — — Check Point Multiple Products — Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow a…
  • CVE-2026-7273 — — — Zyxel GS1900 Series Switches — Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and …
  • CVE-2025-39964 — — — Linux Kernel — Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistenc…
  • CVE-2026-53266 — — — Linux Kernel — Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket…
  • CVE-2025-39682 — — — Linux Kernel — Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to …
  • CVE-2026-58704 — — — Google Pixel — Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.
  • CVE-2026-76460 — — — Cisco Identity Services Engine — Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticate…
  • CVE-2026-87886 — — — Acronis Backup — Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation.
  • CVE-2026-76461 — — — Cisco Secure Email Gateway — Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary command…
  • CVE-2026-84869 — — — ConnectWise ScreenConnect — ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an…
  • CVE-2026-42016 — — — JFrog Artifactory — JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the …
  • CVE-2026-42018 — — — JFrog Artifactory — JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disable…
  • CVE-2026-85706 — — — GitLab Community Edition and Enterprise Edition — GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinem…
  • CVE-2026-86060 — — — MikroTik RouterOS — MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacker to change the trusted RouterOS policy mask, leading…
  • CVE-2026-67277 — — — MikroTik RouterOS — MikroTik RouterOS contains a missing authentication for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.
  • CVE-2026-19490 — — — Citrix NetScaler — Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an A…
  • CVE-2025-25249 — — — Fortinet Multiple Products — Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via speciall…
  • CVE-2026-87491 — — — Google Chromium V8 — Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerabil…
  • CVE-2026-20079 — — — Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management — Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channe…
  • CVE-2026-75650 — — — Adobe Commerce and Magento — Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitr…
  • CVE-2026-81963 — — — Microsoft Windows — Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.
  • CVE-2026-86218 — — — N-able N-central — N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.
  • CVE-2026-85880 — — — Microsoft Windows — Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.
  • CVE-2026-85046 — — — Google Chromium V8 — Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability co…
  • CVE-2026-59822 — — — BerriAI LiteLLM — BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP…
  • CVE-2026-48710 — — — Kludex Starlette — Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issue…
  • CVE-2026-49869 — — — Kestra Kestra OSS — Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.
  • CVE-2026-82329 — — — JFrog Artifactory — JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrat…
  • CVE-2026-9586 — — — Sangoma Switchvox — Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database…
  • CVE-2026-83548 — — — SonicWall SMA1000 Appliances — SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functi…
  • CVE-2026-83549 — — — SonicWall SMA1000 Appliances — SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, res…

Source: CISA KEV. Auto-compiled by CaptainAI Labs AI agents.