UPDATED SEP 30, 2026

CVE Radar: latest vulnerabilities, exploited CVEs and patches (page 12)

A daily, analyst-curated feed of new and actively exploited CVEs, with severity, exploitation status, affected versions and remediation steps for each.

  1. CVE-2026-70009
    Azure ARC path traversal privilege elevation Microsoft Azure ARC ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  2. CVE-2026-70200
    Azure Logic Apps path traversal allows remote privilege escalation Microsoft Azure Logic Apps ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  3. CVE-2026-85889
    Azure AI Foundry missing authentication privilege elevation Microsoft Azure AI Foundry ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  4. CVE-2026-93762 CRITICAL 9.8
  5. CVE-2026-93643
    Zimbra Collaboration Suite path-traversal pre-auth remote code execution Zimbra Zimbra Collaboration Suite (ZCS) ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  6. CVE-2026-18143
    Request a Quote for WooCommerce arbitrary file upload via popup handler Addify Request a Quote for WooCommerce ·
    • PoC PUBLIC
    CRITICAL 9.8
  7. CVE-2026-88775 CRITICAL 9.8
  8. CVE-2026-88777 CRITICAL 9.8
  9. CVE-2026-88776
    Citrix ADC memory overflow can cause service disruption Citrix ADC ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  10. CVE-2026-57983
    Microsoft Edge security feature bypass over network (pre-auth authorization bypass) Microsoft Microsoft Edge (Chromium-based) ·
    • PATCH AVAILABLE
    CRITICAL 10
  11. CVE-2026-62643
    Roundcube Webmail CSS sanitization SSRF and information disclosure Roundcube Webmail ·
    • PATCH AVAILABLE
    CRITICAL 10
  12. CVE-2026-54433
    Roundcube Webmail stored XSS zero-click via crafted email Roundcube Webmail ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 10
  13. CVE-2026-54159 CRITICAL 10
  14. CVE-2026-16367 CRITICAL 10
  15. CVE-2026-56163
    Azure Kubernetes Service missing authentication allows pre-auth privilege escalation Microsoft Azure Kubernetes Service ·
    • PATCH AVAILABLE
    CRITICAL 10
  16. CVE-2026-65880
    Balbooa Forms for Joomla unauthenticated remote code execution balbooa.com Balbooa Forms component for Joomla ·
    CRITICAL 10
  17. CVE-2026-66803
    Azure Cosmos DB improper access control pre-auth remote code execution Microsoft Azure Cosmos DB ·
    • PATCH AVAILABLE
    CRITICAL 10
  18. CVE-2026-64633
    Veeam ONE unauthenticated remote code execution Veeam ONE ·
    • PoC PUBLIC
    CRITICAL 10
  19. CVE-2026-56162
    Azure SQL Database improper authentication privilege elevation Microsoft Azure SQL Database ·
    • PATCH AVAILABLE
    CRITICAL 10
  20. CVE-2026-62836
    Azure SQL Managed Instance privilege elevation via communication channel flaw Microsoft Azure SQL Managed Instance ·
    • PATCH AVAILABLE
    CRITICAL 10
20 CVEs · page 12 of 23

About CVE Radar

CVE Radar tracks newly published Common Vulnerabilities and Exposures (CVEs) from NVD, the CISA Known Exploited Vulnerabilities catalog and vendor security advisories. Each entry is reviewed by Diras Labs analysts and includes affected versions, exploitation status, remediation guidance and relevance to organizations in Saudi Arabia and the GCC.