36 open-source device CVEs in September 2026: two already exploited
A monthly roundup of open-source device-stack vulnerabilities beyond the Linux kernel: 36 CVEs and advisories across 14 packages from 1 to 30 September 2026, including U-Boot, OpenSSL, wolfSSL, Python, FFmpeg and Chromium. Two Chromium V8 bugs are in the CISA KEV catalog with active exploitation, a proof of concept exists for a zlib issue, and BusyBox has no upstream fix yet.
- 36 CVEs and advisories across 14 packages from 1 to 30 September 2026
- Two Chromium V8 bugs in CISA KEV with active exploitation
- Proof of concept published for zlib CVE-2026-85091; no fixed release
- BusyBox 1.38.0 affected with no upstream fix found
Read next
AI