chiprook
← Security
SecurityOctober 2, 2026, 11:05

36 open-source device CVEs in September 2026: two already exploited

A monthly roundup of open-source device-stack vulnerabilities beyond the Linux kernel: 36 CVEs and advisories across 14 packages from 1 to 30 September 2026, including U-Boot, OpenSSL, wolfSSL, Python, FFmpeg and Chromium. Two Chromium V8 bugs are in the CISA KEV catalog with active exploitation, a proof of concept exists for a zlib issue, and BusyBox has no upstream fix yet.

36 open-source device CVEs in September 2026: two already exploited
#Chromium#OpenSSL#Python#BusyBox
Read next
AI

Google Agent Development Kit for Kotlin reaches feature parity with Python, supports on-device AI

Security

OpenSSL patches high-severity DTLS flaw leaking heap memory

Security

OpenSSL 4.0.3 released with high-severity security fixes

Security

CERT-BUND flags 36 CVEs in 16 Drupal projects, CVSS 9.8