CVE Digest — September 18, 2026
8 CVE
3 KEV
Digest for September 18, 2026: 3 new entries in the CISA KEV catalog and 5 advisories from ACN, the Italian cybersecurity agency. KEV entries are known to be exploited in the wild: patch the affected products as soon as possible.
ACN advisories (Italy)
| CVE | Product | CVSS | Severity | Summary | References |
|---|---|---|---|---|---|
| CVE-2025-39964 KEV | Linux Kernel | – | Unknown | Linux kernel race condition in AF_ALG sockets allows concurrent writes to the same socket, unpredictably interleaving data and corrupting internal socket state. Apply vendor mitigations per CISA BOD 26-04 guidance. Added to KEV on 2026-09-18. | |
| CVE-2026-53266 KEV | Linux Kernel | – | Unknown | Linux kernel out-of-bounds write in the ebtables SNAT target: an ARP sender hardware address rewrite can write into a nonlinear socket-buffer fragment backed by a splice-imported file page. Affected versions may be EoL/EoS; discontinue use or upgrade to a supported version. KEV … | |
| CVE-2025-39682 KEV | Linux Kernel | – | Unknown | Linux kernel improper exceptional-condition check in the TLS receive path lets a zero-length record from rx_list bypass intended recvmsg() record-type handling, causing later TLS records to be processed with wrong zero-copy and queuing assumptions. Affected versions may be EoL/E… | |
| CVE-2026-81934 | – | – | Unknown | CVE-2026-81934: a public proof-of-concept exists for a vulnerability in Redis, an in-memory data store, and active exploitation has been detected in the wild. Update Redis and monitor for indicators of compromise. ACN advisory published 2026-09-18. | |
| risolte-vulnerabilita-in-grafana-7 | – | – | Unknown | Multiple vulnerabilities were fixed in Grafana, a popular web application for interactive data visualization and analysis; 3 have high severity. Exploitation could allow privilege escalation and/or remote arbitrary code execution. Update to the latest version. ACN advisory publi… | |
| vulnerabilita-in-solarwinds-6 | – | – | Unknown | A high-severity security vulnerability was fixed in SolarWinds Access Rights Manager. Exploitation could allow a remote attacker to execute arbitrary code on affected systems. Apply the vendor update. ACN advisory published 2026-09-18. | |
| risolte-vulnerabilita-in-pgadmin | – | – | Unknown | An update fixes 2 critical-severity vulnerabilities in pgAdmin, the open-source administration and development platform for PostgreSQL. Exploitation could allow authentication bypass and arbitrary file writes on affected systems. Apply the update. ACN advisory published 2026-09-… | |
| risolte-vulnerabilita-in-google-chrome-74 | – | – | Unknown | Google released a Chrome update fixing 16 new security vulnerabilities, 2 of critical and 7 of high severity. Update Chrome to the latest version to mitigate potential exploitation. ACN advisory published 2026-09-18. |
Disclaimer
This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.