Monthly Vuln Summary 2026-09 (42)
Monthly Vulnerability Summary · 2026-09
42 CVEs added to CISA KEV this month (actively exploited; 0 ransomware-related).
All CVEs
- CVE-2026-86950 —
—— Apple Multiple Products — Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution. - CVE-2026-88772 —
—— Citrix NetScaler — Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code executi… - CVE-2026-88771 —
—— Citrix NetScaler — Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. - CVE-2026-67279 —
—— MikroTik RouterOS — Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec reques… - CVE-2026-65660 —
—— Microsoft SharePoint — Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network. - CVE-2026-87902 —
—— WordPress Core — WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local.php… - CVE-2026-5430 —
—— WSO2 Multiple Products — WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote cod… - CVE-2026-71362 —
—— **Adobe Commerce and Magento ** — Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resour… - CVE-2026-93952 —
—— Arista VeloCloud Orchestrator — Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and imp… - CVE-2026-94127 —
—— F5 BIG-IP APM — F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unau… - CVE-2026-93616 —
—— Check Point Multiple Products — Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that all… - CVE-2026-85102 —
—— Check Point Multiple Products — Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow a… - CVE-2026-7273 —
—— Zyxel GS1900 Series Switches — Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and … - CVE-2025-39964 —
—— Linux Kernel — Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistenc… - CVE-2026-53266 —
—— Linux Kernel — Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket… - CVE-2025-39682 —
—— Linux Kernel — Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to … - CVE-2026-58704 —
—— Google Pixel — Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges. - CVE-2026-76460 —
—— Cisco Identity Services Engine — Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticate… - CVE-2026-87886 —
—— Acronis Backup — Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation. - CVE-2026-76461 —
—— Cisco Secure Email Gateway — Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary command… - CVE-2026-84869 —
—— ConnectWise ScreenConnect — ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an… - CVE-2026-42016 —
—— JFrog Artifactory — JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the … - CVE-2026-42018 —
—— JFrog Artifactory — JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disable… - CVE-2026-85706 —
—— GitLab Community Edition and Enterprise Edition — GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinem… - CVE-2026-86060 —
—— MikroTik RouterOS — MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacker to change the trusted RouterOS policy mask, leading… - CVE-2026-67277 —
—— MikroTik RouterOS — MikroTik RouterOS contains a missing authentication for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service. - CVE-2026-19490 —
—— Citrix NetScaler — Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an A… - CVE-2025-25249 —
—— Fortinet Multiple Products — Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via speciall… - CVE-2026-87491 —
—— Google Chromium V8 — Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerabil… - CVE-2026-20079 —
—— Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management — Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channe… - CVE-2026-75650 —
—— Adobe Commerce and Magento — Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitr… - CVE-2026-81963 —
—— Microsoft Windows — Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM. - CVE-2026-86218 —
—— N-able N-central — N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution. - CVE-2026-85880 —
—— Microsoft Windows — Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally. - CVE-2026-85046 —
—— Google Chromium V8 — Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability co… - CVE-2026-59822 —
—— BerriAI LiteLLM — BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP… - CVE-2026-48710 —
—— Kludex Starlette — Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issue… - CVE-2026-49869 —
—— Kestra Kestra OSS — Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials. - CVE-2026-82329 —
—— JFrog Artifactory — JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrat… - CVE-2026-9586 —
—— Sangoma Switchvox — Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database… - CVE-2026-83548 —
—— SonicWall SMA1000 Appliances — SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functi… - CVE-2026-83549 —
—— SonicWall SMA1000 Appliances — SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, res…
Source: CISA KEV. Auto-compiled by CaptainAI Labs AI agents.