UPDATED SEP 30, 2026

CVE Radar: latest vulnerabilities, exploited CVEs and patches (page 15)

A daily, analyst-curated feed of new and actively exploited CVEs, with severity, exploitation status, affected versions and remediation steps for each.

  1. CVE-2026-50343
    Windows Install Service local privilege escalation Microsoft Windows 10 Version 1809 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  2. CVE-2026-50402
    Windows NTFS numeric conversion local privilege escalation Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  3. CVE-2026-28912
    MacOS local privilege escalation via logic issue Apple macOS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  4. CVE-2026-39875
    MacOS permission flaw local privilege escalation Apple macOS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  5. CVE-2026-64747
    IOS and iPadOS buffer overflow allows kernel code execution Apple iOS and iPadOS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  6. CVE-2026-14266
    7-Zip XZ heap buffer overflow remote code execution 7-Zip 7-Zip ·
    • PoC PUBLIC
    HIGH 7.8
  7. CVE-2026-54984
    Windows 10 Version 1607 heap buffer overflow local code execution Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  8. CVE-2026-62735
    Windows HTTP.sys heap buffer overflow local privilege escalation Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  9. CVE-2026-62737
    Windows 11 untrusted pointer dereference local privilege escalation Microsoft Windows 11 Version 24H2 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  10. CVE-2026-66804
    Windows 10 Version 22H2 cross-device service local privilege escalation Microsoft Windows 10 Version 22H2 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  11. CVE-2026-69328
    Windows 10 Version 1607 untrusted search path local privilege escalation Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  12. CVE-2026-49881
    Android InCallController logic error local privilege escalation Google Android ·
    • PoC PUBLIC
    HIGH 7.8
  13. CVE-2026-43783
    MacOS race condition lets low-privileged app gain root Apple macOS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  14. CVE-2026-43786
    MacOS entitlement check bypass lets local user gain root privileges Apple macOS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  15. CVE-2026-84568
    MacOS path traversal remote code execution (root) Apple macOS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  16. CVE-2026-87886
    Acronis Backup local privilege escalation via insecure permissions Acronis Backup ·
    • CISA KEV
    • EXPLOITED
    • PATCH AVAILABLE
    HIGH 7.8
  17. CVE-2026-62911
    Microsoft Exchange Server authentication bypass (capture-replay) Microsoft Microsoft Exchange Server 2016 Cumulative Update 23 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8
  18. CVE-2026-50338
    Azure Spring Apps improper authentication privilege escalation Microsoft Azure Spring Apps ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.2
  19. CVE-2026-53413
    Zoom Clients annotator buffer overwrite remote code execution Zoom Communications Zoom Clients ·
    • PoC PUBLIC
    HIGH 8.3
  20. CVE-2026-85048
    Chrome use-after-free in Compositing allows renderer escape and code execution Google Chrome ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.3
20 CVEs · page 15 of 23

About CVE Radar

CVE Radar tracks newly published Common Vulnerabilities and Exposures (CVEs) from NVD, the CISA Known Exploited Vulnerabilities catalog and vendor security advisories. Each entry is reviewed by Diras Labs analysts and includes affected versions, exploitation status, remediation guidance and relevance to organizations in Saudi Arabia and the GCC.