Open-Source Device CVEs: What to Patch by Vertical (September 2026)
Originally published on TECH VEDA: Open-Source Device CVEs: What to Patch by Vertical (September 2026) . This is a monthly series covering the device stack beyond the Linux kernel. September 2026 brought 36 open-source device CVEs and advisories worth acting on across 14 packages: U-Boot , OpenSSL , wolfSSL , expat , zlib , libxml2 , BusyBox , Python , FFmpeg , GStreamer , WebKitGTK , Chromium ,…
In September 2026, 36 open-source device CVEs were discovered across 14 packages, requiring immediate attention. These issues are spread throughout the device stack, including the bootloader, C library, TLS libraries, media pipeline, language runtimes, and container runtime. The largest groups of fixes were in U-Boot network boot code, TLS libraries, libxml2, and Python.
Two CVEs in Chromium V8 are particularly noteworthy, as both have a proof of concept published. U-Boot, OpenSSL, wolfSSL, expat, zlib, libxml2, BusyBox, Python, FFmpeg, GStreamer, WebKitGTK, Chromium, containerd, and BlueZ all have affected packages. BusyBox, however, has no upstream fix yet.
To address these CVEs, update each affected package to the fixed version, or if there is no release, cherry-pick the relevant commit and rebuild the image. The EU Cyber Resilience Act mandates manufacturers to maintain an SBOM and handle known vulnerabilities in their products. This report can be used to check against the SBOM, ensuring all necessary patches are applied.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.