{
  "id": 11350290,
  "title": "Open-Source Device CVEs: What to Patch by Vertical (September 2026)",
  "url": "https://urgent.news/2026/10/02/open-source-device-cves-what-to-patch-by-vertical-september-2026",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-02T04:05:15.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/raghu_bharadwaj_404e60eb0c/open-source-device-cves-what-to-patch-by-vertical-september-2026-o2f"
  },
  "original_language": "en",
  "account": "In September 2026, 36 open-source device CVEs were discovered across 14 packages, requiring immediate attention. These issues are spread throughout the device stack, including the bootloader, C library, TLS libraries, media pipeline, language runtimes, and container runtime. The largest groups of fixes were in U-Boot network boot code, TLS libraries, libxml2, and Python.\n\nTwo CVEs in Chromium V8 are particularly noteworthy, as both have a proof of concept published. U-Boot, OpenSSL, wolfSSL, expat, zlib, libxml2, BusyBox, Python, FFmpeg, GStreamer, WebKitGTK, Chromium, containerd, and BlueZ all have affected packages. BusyBox, however, has no upstream fix yet.\n\nTo address these CVEs, update each affected package to the fixed version, or if there is no release, cherry-pick the relevant commit and rebuild the image. The EU Cyber Resilience Act mandates manufacturers to maintain an SBOM and handle known vulnerabilities in their products. This report can be used to check against the SBOM, ensuring all necessary patches are applied.",
  "summary": "Originally published on TECH VEDA: Open-Source Device CVEs: What to Patch by Vertical (September 2026) . This is a monthly series covering the device stack beyond the Linux kernel. September 2026 brought 36 open-source device CVEs and advisories worth acting on across 14 packages: U-Boot , OpenSSL , wolfSSL , expat , zlib , libxml2 , BusyBox , Python , FFmpeg , GStreamer , WebKitGTK , Chromium ,…",
  "key_points": [
    "36 open-source device CVEs discovered in September 2026",
    "U-Boot network boot code, TLS libraries, libxml2, and Python affected most",
    "Chromium V8 CVEs with published proof of concept require immediate patching"
  ],
  "editors_take": "This development heightens urgency for device manufacturers to scrutinize their software bills of materials and patch or update vulnerable packages to comply with regulations like the EU Cyber Resilience Act.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}