Skip to content
Threat Feed
high threat updated

Google Security Updates - September 2026

Roundup of Google security advisories published in September 2026.

CVE search metadata

CVE search record: CVE-2026-90559. Severity: high. CVSS: 7.5. EPSS: 0.35%. KEV: no. Brief: Google Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-google-security-updates/

CVE search record: CVE-2026-93452. Severity: high. CVSS: 7.5. KEV: no. Brief: Google Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-google-security-updates/

What's new

  • 1. added CVE-2026-93452 Sep 18, 02:01 via nvd
  • 2. posted roundup Sep 12, 21:22 via nvd

This roundup covers 1 Google security vulnerabilities. None are reported as actively exploited at the time of release.

Summary

CVEProductSeverityCVSSEPSSKEVSource
CVE-2026-90559n/anoNVD (authoritative)

CVE-2026-90559

The snappy-java library, specifically the Snappy.uncompress method, contains an out-of-bounds write vulnerability due to a failure to validate destination buffer capacity against the decompressed data size. An attacker can craft compressed input that results in a buffer overflow during decompression, potentially leading to JVM crashes or arbitrary code execution.

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-90559