UPDATED SEP 30, 2026

CVE Radar: latest vulnerabilities, exploited CVEs and patches (page 16)

A daily, analyst-curated feed of new and actively exploited CVEs, with severity, exploitation status, affected versions and remediation steps for each.

  1. CVE-2026-65647
    Plesk Migrator symlink flaw allows authenticated users to run code as root WebPros Plesk Migrator ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.7
  2. CVE-2025-62593
    Ray code injection via browser leading to remote code execution Ray-Project Ray ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    HIGH 8.8
  3. CVE-2026-53266
    Linux Kernel ebtables SNAT ARP rewrite out-of-bounds write Linux Kernel ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  4. CVE-2026-14431
    Chrome V8 type confusion lets remote code execution Google Chrome ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  5. CVE-2026-50369
    Windows 10 Version 1607 Remote Desktop Services use-after-free elevation of privilege Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  6. CVE-2026-54121
    Windows 10 AD CS improper authorization privilege escalation Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  7. CVE-2026-65591
    N8n sanitizer bypass authenticated remote code execution n8n-io n8n ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  8. CVE-2026-42016
    Artifactory incorrect authorization privilege escalation JFrog Artifactory ·
    • CISA KEV
    • EXPLOITED
    • PATCH AVAILABLE
    HIGH 8.8
  9. CVE-2026-17633
    Langflow OSS code injection allows authenticated remote code execution IBM Langflow OSS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  10. CVE-2026-49179
    Windows Active Directory command injection remote code execution Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  11. CVE-2026-65640
    WordPress PostScript upload remote code execution via upload_files WordPress WordPress ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  12. CVE-2026-74939
    Firefox DOM navigation privilege escalation vulnerability Mozilla Firefox ·
    • PoC PUBLIC
    HIGH 8.8
  13. CVE-2026-10053
    GitLab package registry path traversal leads to authenticated remote code execution GitLab GitLab ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  14. CVE-2026-78905
    Chrome ANGLE type confusion allows remote code execution from a web page Google Chrome ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  15. CVE-2026-78938
    Chrome type confusion in V8 remote code execution Google Chrome ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  16. CVE-2026-79266
    Chrome DevTools use-after-free allows extension to execute code Google Chrome ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  17. CVE-2026-18729
    Langflow OSS authenticated remote code execution IBM Langflow OSS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  18. CVE-2026-65643
    CPanel eval injection authenticated code execution as root WebPros cPanel ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  19. CVE-2026-84645
    Jenkins remote code execution via crafted config.xml object injection Jenkins Project Jenkins ·
    • PoC PUBLIC
    HIGH 8.8
  20. CVE-2026-28618 HIGH 8.8
20 CVEs · page 16 of 23

About CVE Radar

CVE Radar tracks newly published Common Vulnerabilities and Exposures (CVEs) from NVD, the CISA Known Exploited Vulnerabilities catalog and vendor security advisories. Each entry is reviewed by Diras Labs analysts and includes affected versions, exploitation status, remediation guidance and relevance to organizations in Saudi Arabia and the GCC.