5d ago
2026-09-08 20:17Z
CRIT

CVE-2026-19232 — Adobe: Experience Manager is affected by an Incorrect Authorization vulnerability that could result in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19232

Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. A low-privileged attacker could exploit this vulnerability to gain elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 9.9 (CRITICAL)

CWECWE 863VNDAdobeTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
5d ago
2026-09-08 19:20Z
HIGH

CVE-2026-82537 — Roo: Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability that allows attackers to execute denied

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82537

Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability that allows attackers to execute denied shell commands by exploiting a word-boundary mismatch in comment handling between the approval gate's shell parser and bash. Attackers can craft a command string with an allowlisted word immediately followed by a hash character, separator, and denied command to pass the approval gate while bash executes the denied command with the agent's auto-execute privileges on th CVSSv3.1 8.8 (HIGH)

CWECWE 436VNDRooTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 19:20Z
HIGH

CVE-2026-82536 — Roo: Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability in the shell command parsing logic

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82536

Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability in the shell command parsing logic that allows attackers to execute denied shell commands by exploiting the omission of the bash pipe operator from the command parser's operator token set. Attackers can craft a command line with an allowlisted prefix followed by the stderr-redirecting pipe operator and a denied command, causing the parser to approve the full pipeline while bash executes the denied component CVSSv3.1 8.8 (HIGH)

CWECWE 184VNDRooTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 19:19Z
CRIT

CVE-2026-82004 — Adobe: Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82004

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 10.0 (CRITICAL)

CWECWE 78VNDAdobeTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
5d ago
2026-09-08 19:19Z
HIGH

CVE-2026-77774 — Adobe: Commerce is affected by an Incorrect Authorization vulnerability that could result in a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77774

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 8.6 (HIGH)

CWECWE 863VNDAdobeTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
5d ago
2026-09-08 19:19Z
HIGH

CVE-2026-77111 — Adobe: Commerce is affected by an Incorrect Authorization vulnerability that could result in a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77111

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to bypass security measures and gain unauthorized write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 8.7 (HIGH)

CWECWE 863VNDAdobeTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 19:19Z
HIGH

CVE-2026-77109 — Adobe: Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77109

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to restricted resources. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 8.6 (HIGH)

CWECWE 863VNDAdobeTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
728 × 90 / responsive · programmatic ad slot
5d ago
2026-09-08 19:19Z
HIGH

CVE-2026-76202 — Adobe: Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76202

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue does not require user interaction. CVSSv3.1 8.2 (HIGH)

CWECWE 863VNDAdobeTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
5d ago
2026-09-08 19:19Z
CRIT

CVE-2026-76201 — Adobe: Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76201

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed. CVSSv3.1 9.3 (CRITICAL)

CWECWE 79VNDAdobeTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
5d ago
2026-09-08 19:19Z
CRIT

CVE-2026-76200 — Adobe: Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76200

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed. CVSSv3.1 9.3 (CRITICAL)

CWECWE 79VNDAdobeTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
5d ago
2026-09-08 19:19Z
HIGH

CVE-2026-69646 — Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-69646

Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network. CVSSv3.1 8.3 (HIGH)

CWECWE 347TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
5d ago
2026-09-08 19:18Z
CRIT

CVE-2026-66302 — External: control of file name or path in Skype for Business allows an unauthorized

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66302

External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 73TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
5d ago
2026-09-08 19:18Z
CRIT

CVE-2026-58822 — This could lead to remote code execution with no additional execution privileges needed.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58822

In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. CVSSv3.1 9.8 (CRITICAL)

CWECWE 704TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
5d ago
2026-09-08 19:18Z
HIGH

CVE-2026-55277 — RoutingManager: In checkUiccListenConfigNeeded of RoutingManager.cpp, there is a possible out of bounds write due to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55277

In checkUiccListenConfigNeeded of RoutingManager.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. CVSSv3.1 8.0 (HIGH)

CWECWE 120VNDRoutingmanagerTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
5d ago
2026-09-08 19:17Z
CRIT

CVE-2026-49921 — In multiple locations, there is a possible memory safety issue due to a heap

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49921

In multiple locations, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. CVSSv3.1 9.8 (CRITICAL)

CWECWE 122TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
5d ago
2026-09-08 19:17Z
HIGH

CVE-2026-49882 — In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible memory safety issue due to a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49882

In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. CVSSv3.1 8.8 (HIGH)

CWECWE 122TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 19:17Z
HIGH

CVE-2026-49879 — In multiple functions of rw_t3t.cc, there is a possible out of bounds write due

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49879

In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. CVSSv3.1 8.8 (HIGH)

CWECWE 787TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 19:17Z
HIGH

CVE-2026-28666 — LocalImageResolver: In multiple functions of LocalImageResolver.java, there is a possible Remote Persistent Denial of Service

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28666

In multiple functions of LocalImageResolver.java, there is a possible Remote Persistent Denial of Service due to a DNG image rendering check bypass. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDLocalimageresolverTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 19:17Z
HIGH

CVE-2026-28662 — In p2p_process_prov_disc_bootstrap_req of p2p_pd.c, there is a possible out of bounds write due to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28662

In p2p_process_prov_disc_bootstrap_req of p2p_pd.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. CVSSv3.1 8.0 (HIGH)

CWECWE 787CWECWE 122TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
5d ago
2026-09-08 19:17Z
HIGH

CVE-2026-28618 — In dec_frm_prepare of oapv.c, there is a possible OOB write due to a heap

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28618

In dec_frm_prepare of oapv.c, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. CVSSv3.1 8.8 (HIGH)

CWECWE 787CWECWE 122TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 19:17Z
HIGH

CVE-2026-28609 — MatroskaExtractor: In read of MatroskaExtractor.cpp, there is a possible out-of-bounds write due to improper casting.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28609

In read of MatroskaExtractor.cpp, there is a possible out-of-bounds write due to improper casting. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. CVSSv3.1 8.8 (HIGH)

CWECWE 704VNDMatroskaextractorTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 19:17Z
CRIT

CVE-2026-28606 — AdapterService: This could lead to remote escalation of privilege without user consent with no additional

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-28606

In handleBondStateChanged of AdapterService.java, there is a possible way to skip pairing due to a logic error in the code. This could lead to remote escalation of privilege without user consent with no additional execution privileges needed. User interaction is not needed for exploitation. CVSSv3.1 9.8 (CRITICAL)

VNDAdapterserviceTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
5d ago
2026-09-08 18:32Z
CRIT

The September 2026 Security Update Review

Microsoft released 972 CVEs in September 2026 (997 total including Chromium/external), with 114 rated Critical and only one actively exploited at release. Adobe released 172 CVEs across 10 bulletins, including an out-of-band critical template-injection in Commerce (CVE-2026-75650) already under active attack. Twenty wormable RCE vulnerabilities affecting Windows core services (DHCP, DNS, RRAS, Message Queuing, Netlogon, SMB) require immediate patching.

SRFApplicationSRFOsSRFNetworkVNDMicrosoftVNDAdobeTYPAdvisoryEXPPrivilege EscalationEXPRce
82
Edit Score
5d ago
2026-09-08 18:21Z
HIGH

CVE-2026-85880 — Microsoft Windows_10_1607: Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85880in the wild

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally. CVSSv3.1 7.8 (HIGH)

CWECWE 122CWECWE 908VNDMicrosoftVNDHeapTYPVulnerabilitySTAitw exploited
7.8
CVSS v3.1
89
Edit Score
5d ago
2026-09-08 18:21Z
HIGH

CVE-2026-85877 — Heap: Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85877

Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score