CVE Digest — September 9, 2026
4 CVE
4 KEV
4 vulnerabilities were added to the CISA KEV catalog on September 9, 2026 and published on NVD. KEV entries are known to be exploited in the wild: patch the affected products as soon as possible.
| CVE | Product | CVSS | Severity | Summary | References |
|---|---|---|---|---|---|
| CVE-2026-19490 KEV | Citrix NetScaler | – | Unknown | Citrix NetScaler ADC and NetScaler Gateway contain an authentication bypass via an alternate path or channel. When configured as an AAA virtual server or Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote attacker may bypass authentication. | |
| CVE-2025-25249 KEV | Fortinet Multiple Products | – | Unknown | Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow that allows an attacker to execute unauthorized code or commands via specially crafted packets. | |
| CVE-2026-87491 KEV | Google Chromium V8 | – | Unknown | Google Chromium V8 contains an out-of-bounds write that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. It may affect multiple Chromium-based browsers, including Google Chrome, Microsoft Edge, and Opera. | |
| CVE-2026-20079 KEV | Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management | – | Unknown | Cisco Secure Firewall Management Center (FMC) Software and Security Cloud Control (SCC) Firewall Management contain an authentication bypass via an alternate path or channel. An unauthenticated remote attacker could bypass authentication, run script files, and gain root access t… |
Disclaimer
This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.