Google Security Updates - September 2026
Roundup of Google security advisories published in September 2026.
CVE search metadata
CVE search record: CVE-2026-90559. Severity: high. CVSS: 7.5. EPSS: 0.35%. KEV: no. Brief: Google Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-google-security-updates/
CVE search record: CVE-2026-93452. Severity: high. CVSS: 7.5. KEV: no. Brief: Google Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-google-security-updates/
What's new
This roundup covers 1 Google security vulnerabilities. None are reported as actively exploited at the time of release.
Summary
| CVE | Product | Severity | CVSS | EPSS | KEV | Source |
|---|---|---|---|---|---|---|
| CVE-2026-90559 | n/a | no | NVD (authoritative) |
CVE-2026-90559
The snappy-java library, specifically the Snappy.uncompress method, contains an out-of-bounds write vulnerability due to a failure to validate destination buffer capacity against the decompressed data size. An attacker can craft compressed input that results in a buffer overflow during decompression, potentially leading to JVM crashes or arbitrary code execution.