UPDATED SEP 30, 2026

CVE Radar: latest vulnerabilities, exploited CVEs and patches (page 13)

A daily, analyst-curated feed of new and actively exploited CVEs, with severity, exploitation status, affected versions and remediation steps for each.

  1. CVE-2026-65667
    Microsoft Teams missing authorization privilege elevation Microsoft Microsoft Teams ·
    • PATCH AVAILABLE
    CRITICAL 10
  2. CVE-2026-75874
    Firefox sandbox escape in Remote Settings Client Mozilla Firefox ·
    CRITICAL 10
  3. CVE-2026-65770
    Azure Managed Instance for Apache Cassandra argument injection allows remote code execution Microsoft Azure Managed Instance for Apache Cassandra ·
    • PATCH AVAILABLE
    CRITICAL 10
  4. CVE-2026-65816
    Azure Web Apps incorrect name resolution lets unauthenticated actor elevate privileges Microsoft Azure Web Apps ·
    • PATCH AVAILABLE
    CRITICAL 10
  5. CVE-2026-69555
    Azure ARC incorrect authorization lets remote attacker escalate privileges Microsoft Azure ARC ·
    • PATCH AVAILABLE
    CRITICAL 10
  6. CVE-2026-69502
    Azure SQL Database server-side request forgery privilege elevation Microsoft Azure SQL Database ·
    • PATCH AVAILABLE
    CRITICAL 10
  7. CVE-2026-70352
    Azure AI Language Authoring missing authentication allows privilege elevation Microsoft Azure AI Language Authoring ·
    • PATCH AVAILABLE
    CRITICAL 10
  8. CVE-2026-65381
    MacOS entitlement validation sandbox escape Apple macOS ·
    • PATCH AVAILABLE
    CRITICAL 10
  9. CVE-2026-69865
    Azure Container Registry authorization bypass via user-controlled key Microsoft Azure Container Registry ·
    • PATCH AVAILABLE
    CRITICAL 10
  10. CVE-2026-62874
    Azure Billing insufficient data authenticity privilege escalation Microsoft Azure Billing ·
    • PATCH AVAILABLE
    CRITICAL 10
  11. CVE-2026-88773
    Citrix ADC HTTP request/response smuggling allows pre-auth breach Citrix ADC ·
    • PATCH AVAILABLE
    CRITICAL 10
  12. CVE-2026-6837
    Zyxel WAX650S firmware command injection post-auth (administrator) Zyxel WAX650S firmware ·
    • PoC PUBLIC
    HIGH 7.2
  13. CVE-2026-69414
    Microsoft Malware Protection Engine elevation of privilege Microsoft Microsoft Malware Protection Engine ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  14. CVE-2026-54998
    Microsoft Exchange Online authorization bypass lets authorized users escalate privileges Microsoft Microsoft Exchange Online ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  15. CVE-2026-47301
    Microsoft Configuration Manager privilege escalation over network Microsoft Microsoft Configuration Manager ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  16. CVE-2026-20200
    Cisco Unified Computing System (Standalone) authenticated remote code execution Cisco Cisco Unified Computing System (Standalone) ·
    • PoC PUBLIC
    HIGH 8.8
  17. CVE-2026-28326
    Access Rights Manager unauthenticated remote code execution SolarWinds Access Rights Manager ·
    • PoC PUBLIC
    HIGH 8.8
  18. CVE-2026-58480
    Blocksy Companion unauthenticated arbitrary file upload leads to remote code execution Creative Themes Blocksy Companion ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
  19. CVE-2026-15158
    Blocksy Companion arbitrary file upload leading to remote code execution creativethemeshq Blocksy Companion ·
    CRITICAL 9.8
  20. CVE-2026-73532
    Fluent Forms Pro embedded malicious code in tampered 6.2.7 build WPManageNinja Fluent Forms Pro ·
    CRITICAL 9.8
20 CVEs · page 13 of 23

About CVE Radar

CVE Radar tracks newly published Common Vulnerabilities and Exposures (CVEs) from NVD, the CISA Known Exploited Vulnerabilities catalog and vendor security advisories. Each entry is reviewed by Diras Labs analysts and includes affected versions, exploitation status, remediation guidance and relevance to organizations in Saudi Arabia and the GCC.