September 2026
CVE-2026-21643: Fortinet FortiClient EMS SQL Injection VulnerabilityNew!!
CISA lists CVE-2026-21643 as exploited. TechGeeks action notice for Fortinet FortiClient EMS SQL Injection Vulnerability, with scope, remediation, investigation guidance, and official sources.
CVE-2009-0238: Legacy Microsoft Excel file remote code executionNew!!
CISA lists CVE-2009-0238 as exploited. TechGeeks action notice for Legacy Microsoft Excel file remote code execution, with scope, remediation, investigation guidance, and official sources.
CVE-2026-32201: SharePoint unauthenticated spoofing vulnerabilityNew!!
CISA lists CVE-2026-32201 as exploited. TechGeeks action notice for SharePoint unauthenticated spoofing vulnerability, with scope, remediation, investigation guidance, and official sources.
CVE-2026-20122: Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs VulnerabilityNew!!
CISA lists CVE-2026-20122 as exploited. TechGeeks action notice for Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability, with scope, remediation, investigation guidance, and official sources.
CVE-2026-20128: Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format VulnerabilityNew!!
CISA lists CVE-2026-20128 as exploited. TechGeeks action notice for Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability, with scope, remediation, investigation guidance, and official sources.
CVE-2026-20133: Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor VulnerabilityNew!!
CISA lists CVE-2026-20133 as exploited. TechGeeks action notice for Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability, with scope, remediation, investigation guidance, and official sources.
CVE-2026-33825: Microsoft Defender local privilege escalationNew!!
CISA lists CVE-2026-33825 as exploited. TechGeeks action notice for Microsoft Defender local privilege escalation, with scope, remediation, investigation guidance, and official sources.
CVE-2025-29635: D-Link DIR-823X authenticated command injection on an end-of-life routerNew!!
CISA lists CVE-2025-29635 as exploited. TechGeeks action notice for D-Link DIR-823X authenticated command injection on an end-of-life router, with scope, remediation, investigation guidance, and official sources.
CVE-2026-32202: Windows Shell spoofing vulnerabilityNew!!
CISA lists CVE-2026-32202 as exploited. TechGeeks action notice for Windows Shell spoofing vulnerability, with scope, remediation, investigation guidance, and official sources.
CVE-2026-0300: PAN-OS User-ID Authentication Portal unauthenticated root RCENew!!
CISA lists CVE-2026-0300 as exploited. TechGeeks action notice for PAN-OS User-ID Authentication Portal unauthenticated root RCE, with scope, remediation, investigation guidance, and official sources.
