CVE Digest

CVE Digest — September 18, 2026

  • Security Bulletin
8 CVE 3 KEV

Digest for September 18, 2026: 3 new entries in the CISA KEV catalog and 5 advisories from ACN, the Italian cybersecurity agency. KEV entries are known to be exploited in the wild: patch the affected products as soon as possible.

ACN advisories (Italy)

CVEProductCVSSSeveritySummaryReferences
CVE-2025-39964 KEVLinux Kernel–UnknownLinux kernel race condition in AF_ALG sockets allows concurrent writes to the same socket, unpredictably interleaving data and corrupting internal socket state. Apply vendor mitigations per CISA BOD 26-04 guidance. Added to KEV on 2026-09-18.
CVE-2026-53266 KEVLinux Kernel–UnknownLinux kernel out-of-bounds write in the ebtables SNAT target: an ARP sender hardware address rewrite can write into a nonlinear socket-buffer fragment backed by a splice-imported file page. Affected versions may be EoL/EoS; discontinue use or upgrade to a supported version. KEV …
CVE-2025-39682 KEVLinux Kernel–UnknownLinux kernel improper exceptional-condition check in the TLS receive path lets a zero-length record from rx_list bypass intended recvmsg() record-type handling, causing later TLS records to be processed with wrong zero-copy and queuing assumptions. Affected versions may be EoL/E…
CVE-2026-81934––UnknownCVE-2026-81934: a public proof-of-concept exists for a vulnerability in Redis, an in-memory data store, and active exploitation has been detected in the wild. Update Redis and monitor for indicators of compromise. ACN advisory published 2026-09-18.
risolte-vulnerabilita-in-grafana-7––UnknownMultiple vulnerabilities were fixed in Grafana, a popular web application for interactive data visualization and analysis; 3 have high severity. Exploitation could allow privilege escalation and/or remote arbitrary code execution. Update to the latest version. ACN advisory publi…
vulnerabilita-in-solarwinds-6––UnknownA high-severity security vulnerability was fixed in SolarWinds Access Rights Manager. Exploitation could allow a remote attacker to execute arbitrary code on affected systems. Apply the vendor update. ACN advisory published 2026-09-18.
risolte-vulnerabilita-in-pgadmin––UnknownAn update fixes 2 critical-severity vulnerabilities in pgAdmin, the open-source administration and development platform for PostgreSQL. Exploitation could allow authentication bypass and arbitrary file writes on affected systems. Apply the update. ACN advisory published 2026-09-…
risolte-vulnerabilita-in-google-chrome-74––UnknownGoogle released a Chrome update fixing 16 new security vulnerabilities, 2 of critical and 7 of high severity. Update Chrome to the latest version to mitigate potential exploitation. ACN advisory published 2026-09-18.

Disclaimer

This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.