September 2026
CVE-2026-20127: Cisco Catalyst SD-WAN controller authentication bypass to fabric administrationNew!!
CISA lists CVE-2026-20127 as exploited. TechGeeks action notice for Cisco Catalyst SD-WAN controller authentication bypass to fabric administration, with scope, remediation, investigation guidance, and official sources.
CVE-2026-21385: Qualcomm graphics memory corruptionNew!!
CISA lists CVE-2026-21385 as exploited. TechGeeks action notice for Qualcomm graphics memory corruption, with scope, remediation, investigation guidance, and official sources.
CVE-2021-30952: Apple WebKit arbitrary code executionNew!!
CISA lists CVE-2021-30952 as exploited. TechGeeks action notice for Apple WebKit arbitrary code execution, with scope, remediation, investigation guidance, and official sources.
CVE-2023-41974: iPhone and iPad kernel privilege escalationNew!!
CISA lists CVE-2023-41974 as exploited. TechGeeks action notice for iPhone and iPad kernel privilege escalation, with scope, remediation, investigation guidance, and official sources.
CVE-2023-43000: Apple WebKit use-after-free memory corruptionNew!!
CISA lists CVE-2023-43000 as exploited. TechGeeks action notice for Apple WebKit use-after-free memory corruption, with scope, remediation, investigation guidance, and official sources.
CVE-2026-1603: Ivanti Endpoint Manager (EPM) Authentication Bypass VulnerabilityNew!!
CISA lists CVE-2026-1603 as exploited. TechGeeks action notice for Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability, with scope, remediation, investigation guidance, and official sources.
CVE-2026-3909: Skia out-of-bounds write exploited through crafted web contentNew!!
CISA lists CVE-2026-3909 as exploited. TechGeeks action notice for Skia out-of-bounds write exploited through crafted web content, with scope, remediation, investigation guidance, and official sources.
CVE-2026-20963: SharePoint unauthenticated deserialization RCENew!!
CISA lists CVE-2026-20963 as exploited. TechGeeks action notice for SharePoint unauthenticated deserialization RCE, with scope, remediation, investigation guidance, and official sources.
CVE-2026-20131: Cisco FMC unauthenticated Java deserialization RCE as rootNew!!
CISA lists CVE-2026-20131 as exploited. TechGeeks action notice for Cisco FMC unauthenticated Java deserialization RCE as root, with scope, remediation, investigation guidance, and official sources.
CVE-2025-31277: Apple WebKit memory corruptionNew!!
CISA lists CVE-2025-31277 as exploited. TechGeeks action notice for Apple WebKit memory corruption, with scope, remediation, investigation guidance, and official sources.
