UPDATED SEP 30, 2026

CVE Radar: latest vulnerabilities, exploited CVEs and patches

A daily, analyst-curated feed of new and actively exploited CVEs, with severity, exploitation status, affected versions and remediation steps for each.

  1. CVE-2026-67378
    Microsoft SQL Server untrusted pointer dereference leads to remote code execution Microsoft Microsoft SQL Server 2019 (CU 32) ·
    • PATCH AVAILABLE
    CRITICAL 9
  2. CVE-2026-67636
    Microsoft SQL Server out-of-bounds read leads to remote code execution Microsoft Microsoft SQL Server 2019 (CU 32) ·
    • PATCH AVAILABLE
    CRITICAL 9
  3. CVE-2026-76420
    Cisco Secure FMC AJP connector pre-auth remote root execution Cisco Cisco Secure Firewall Management Center (FMC) ·
    CRITICAL 9
  4. CVE-2026-67278
    RouterOS RSA signature verification allows TLS/SSH impersonation MikroTik RouterOS ·
    • PATCH AVAILABLE
    CRITICAL 9.1
  5. CVE-2026-86131
    WatchGuard Fireware OS BOVPN Over TLS code injection remote root execution WatchGuard Fireware OS ·
    • PATCH AVAILABLE
    CRITICAL 9.2
  6. CVE-2026-101891
    WatchGuard AP improper access control allows unauthenticated API session WatchGuard WatchGuard AP ·
    • PATCH AVAILABLE
    CRITICAL 9.3
  7. CVE-2026-86102
    WatchGuard AP OS command injection in internal API allows remote code execution WatchGuard WatchGuard AP ·
    • PATCH AVAILABLE
    CRITICAL 9.3
  8. CVE-2026-76969
    SAP Cloud Application Programming Model unauthenticated credential disclosure SAP SAP Cloud Application Programming Model (CAP) ·
    CRITICAL 9.4
  9. CVE-2026-20212
    Cisco NX-OS Silicon One integration unauthenticated remote code execution Cisco Cisco NX-OS Software ·
    • PoC PUBLIC
    CRITICAL 9.8
  10. CVE-2026-62916
    Microsoft Entra authentication bypass lets unauthenticated attacker elevate privileges Microsoft Microsoft Entra ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  11. CVE-2026-77092 CRITICAL 9.8
  12. CVE-2026-77098
    Commvault Cloud SQL injection in Private Metrics Server Commvault Commvault Cloud ·
    CRITICAL 9.8
  13. CVE-2026-77089
    Commvault Cloud Command Center pre-auth authentication bypass Commvault Commvault Cloud ·
    CRITICAL 9.8
  14. CVE-2026-12745 CRITICAL 9.8
  15. CVE-2026-12744
    Neurons for ITSM deserialization remote code execution Ivanti Neurons for ITSM ·
    CRITICAL 9.8
  16. CVE-2026-67631
    Microsoft SQL Server heap-based buffer overflow allows remote code execution Microsoft Microsoft SQL Server 2017 (CU 31) ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  17. CVE-2026-67643
    Microsoft SQL Server 2022/2025 heap buffer overflow pre-auth remote code execution Microsoft Microsoft SQL Server 2022 (CU 26) ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  18. CVE-2026-78509
    Microsoft 365 Apps heap buffer overflow remote code execution Microsoft Microsoft 365 Apps for Enterprise ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  19. CVE-2026-81352
    Web Media Extensions heap buffer overflow allows pre-auth remote code execution Microsoft Web Media Extensions ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  20. CVE-2026-66302
    Skype for Business Server remote code execution via file path control Microsoft Skype for Business Server 2015 CU13 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
20 CVEs · page 1 of 23

About CVE Radar

CVE Radar tracks newly published Common Vulnerabilities and Exposures (CVEs) from NVD, the CISA Known Exploited Vulnerabilities catalog and vendor security advisories. Each entry is reviewed by Diras Labs analysts and includes affected versions, exploitation status, remediation guidance and relevance to organizations in Saudi Arabia and the GCC.