· via dev.to (home feed)
September 2026 device CVE roundup: 36 flaws across 14 packages, two already exploited
A TECH VEDA roundup counts 36 actionable open-source device CVEs across 14 packages including U-Boot, OpenSSL and BusyBox; two Chromium V8 bugs are already being exploited.

September 2026 produced 36 open-source device CVEs and advisories meriting action, spread across 14 packages that sit above the Linux kernel inside shipped device images. That is the tally from a monthly roundup by TECH VEDA republished on dev.to, which tracks the bootloader, the C library, the TLS libraries, the media pipeline, the language runtimes and the container runtime that end up in a product. The reporting window ran from 1 to 30 September.
Two of the 36 entries sit in the CISA Known Exploited Vulnerabilities catalog, and both are Chromium V8 bugs: a type confusion (CVE-2026-85046) and an out-of-bounds write (CVE-2026-87491), each scored 8.8 with active exploitation recorded by CISA. Fixes arrive in Chrome 152.0.7977.82 and 153.0.8010.36 respectively. A proof of concept is also public for a zlib heap overflow in gzprintf() (CVE-2026-85091, 7.4) that follows a stalled non-blocking gzwrite() — and no zlib release carries the fix, which exists only as a commit, while 1.3.2 remains the newest and affected release.
What to patch, by vertical
The report's guidance is straightforward: move each affected package to its fixed version, take the distribution's patched package, or cherry-pick the commit where nothing has been released, then rebuild the image. What applies depends on what is in the image and its software bill of materials.
Embedded and IoT teams carry the widest exposure, with nine of the 14 packages flagged. U-Boot leads with eight CVEs, largely in network boot code: IP fragment reassembly flaws scored as high as 9.0, NFS reply parsing and a use-after-free in the lwIP wget client at 8.2, and a DHCPv6 options bug at 7.1. Everything except two issues is resolved by 2026.10-rc5 or later, but the final 2026.10 tag had not been published and those two fixes exist as commits only. BusyBox has two heap overflows, in the TLS test applet ssl_server (7.5) and romfs volume ID parsing (7.3), with no upstream fix found; the newest release, 1.38.0, is affected.
Mobile and automotive builders share the U-Boot and TLS problems and add the media stack. wolfSSL 5.9.4 closes three certificate and authentication bypasses scored 8.3, among them a trusted-peer match that ignores the public key. FFmpeg 8.1 and 9.0 address an out-of-bounds write in the RTP muxer (8.8) plus an HEIF integer overflow. GStreamer 1.28.7 covers an RTSP Digest denial of service, an out-of-bounds flaw in gst-libav audio beyond 64 channels and a souphttpsrc credential leak on cross-origin redirects. WebKitGTK 2.54.0 ships advisory WSA-2026-0006. BlueZ carries two Bluetooth stack overflows in a root daemon — AVRCP (7.3) and A2DP (7.1) — fixed only by commits, with tag 5.87 affected by the AVRCP issue.
Cloud and datacenter images need three packages. OpenSSL 4.0.3, 3.6.5, 3.5.9 and 3.4.8 fix CVE-2026-84782, a DTLS retransmit bug that reads from an incorrect buffer offset and can expose heap memory or crash; the 3.0.23 fix is limited to premium support customers. Python patches a use-after-free in ssl servers switching contexts in sni_callback (9.2), a silently skipped hostname check in wrap_bio() (7.6) and a tarfile filter bypass (8.4) across the 3.10 through 3.15 branches. containerd 2.2.7 and 2.3.4 close CVE-2026-95837, a CRI checkpoint-restore flaw the project rates Critical.
Medical devices appear in ten of the fourteen rows, giving that vertical the longest checklist of all.
Caveats on the numbers
An item makes the list only if it scores 7.0 or higher, appears in the CISA KEV catalog, or is plainly reachable in an ordinary device build, and the report flags where scoring bodies disagree. U-Boot's figures come from the VulnCheck CNA, while the CERT-PL record for CVE-2026-15390 contradicts itself on the fixed version, so the report points readers to fix commit b1aec609 instead. Python's scores use CVSS 4.0 exclusively, which tends to produce higher numbers than 3.1 for the same flaw. The GStreamer score comes from Red Hat, though the GStreamer project itself says the bug cannot lead to code execution. Excluded items include a glibc strfmon flaw with no confirmed fixed release, a local-only wpa_supplicant issue and an xz advisory requiring an unusual allocation failure.
Why it matters
Device makers routinely bake these components into firmware images and then lose sight of upstream fixes. This list turns that sprawl into a concrete patch checklist keyed to verticals, and the KEV entries plus a public zlib exploit make parts of it urgent rather than routine housekeeping. With the EU Cyber Resilience Act obliging manufacturers to keep an SBOM and handle known vulnerabilities, comparing this report against that SBOM is edging from good practice toward legal duty. And for zlib, BusyBox and BlueZ, where no fixed release exists, the real work is cherry-picking commits and rebuilding images instead of waiting for a tag.
- #security
- #cve
- #embedded
- #open-source
- #firmware