UPDATED SEP 30, 2026
CVE Radar: latest vulnerabilities, exploited CVEs and patches (page 13)
A daily, analyst-curated feed of new and actively exploited CVEs, with severity, exploitation status, affected versions and remediation steps for each.
-
CVE-2026-65667
Microsoft Teams missing authorization privilege elevationCRITICAL 10
- PATCH AVAILABLE
- CVE-2026-75874 CRITICAL 10
-
CVE-2026-65770
Azure Managed Instance for Apache Cassandra argument injection allows remote code executionCRITICAL 10
- PATCH AVAILABLE
-
CVE-2026-65816
Azure Web Apps incorrect name resolution lets unauthenticated actor elevate privilegesCRITICAL 10
- PATCH AVAILABLE
- CVE-2026-69555 CRITICAL 10
- CVE-2026-69502 CRITICAL 10
- CVE-2026-70352 CRITICAL 10
-
CVE-2026-65381
MacOS entitlement validation sandbox escapeCRITICAL 10
- PATCH AVAILABLE
- CVE-2026-69865 CRITICAL 10
- CVE-2026-62874 CRITICAL 10
- CVE-2026-88773 CRITICAL 10
- CVE-2026-6837 HIGH 7.2
-
CVE-2026-69414
Microsoft Malware Protection Engine elevation of privilegeHIGH 7.8
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-54998
Microsoft Exchange Online authorization bypass lets authorized users escalate privilegesHIGH 8.8
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-47301
Microsoft Configuration Manager privilege escalation over networkHIGH 8.8
- PoC PUBLIC
- PATCH AVAILABLE
- CVE-2026-20200 HIGH 8.8
- CVE-2026-28326 HIGH 8.8
-
CVE-2026-58480
Blocksy Companion unauthenticated arbitrary file upload leads to remote code executionCRITICAL 9.8
- PoC PUBLIC
- PATCH AVAILABLE
- CVE-2026-15158 CRITICAL 9.8
- CVE-2026-73532 CRITICAL 9.8
No CVEs on this page match the filters.
20 CVEs · page 13 of 23
About CVE Radar
CVE Radar tracks newly published Common Vulnerabilities and Exposures (CVEs) from NVD, the CISA Known Exploited Vulnerabilities catalog and vendor security advisories. Each entry is reviewed by Diras Labs analysts and includes affected versions, exploitation status, remediation guidance and relevance to organizations in Saudi Arabia and the GCC.