UPDATED SEP 30, 2026
CVE Radar: latest vulnerabilities, exploited CVEs and patches (page 16)
A daily, analyst-curated feed of new and actively exploited CVEs, with severity, exploitation status, affected versions and remediation steps for each.
-
CVE-2026-65647
Plesk Migrator symlink flaw allows authenticated users to run code as rootHIGH 8.7
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2025-62593
Ray code injection via browser leading to remote code executionHIGH 8.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-53266
Linux Kernel ebtables SNAT ARP rewrite out-of-bounds writeHIGH 8.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-14431
Chrome V8 type confusion lets remote code executionHIGH 8.8
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-50369
Windows 10 Version 1607 Remote Desktop Services use-after-free elevation of privilegeHIGH 8.8
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-54121
Windows 10 AD CS improper authorization privilege escalationHIGH 8.8
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-65591
N8n sanitizer bypass authenticated remote code executionHIGH 8.8
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-42016
Artifactory incorrect authorization privilege escalationHIGH 8.8
- CISA KEV
- EXPLOITED
- PATCH AVAILABLE
-
CVE-2026-17633
Langflow OSS code injection allows authenticated remote code executionHIGH 8.8
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-49179
Windows Active Directory command injection remote code executionHIGH 8.8
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-65640
WordPress PostScript upload remote code execution via upload_filesHIGH 8.8
- PoC PUBLIC
- PATCH AVAILABLE
- CVE-2026-74939 HIGH 8.8
-
CVE-2026-10053
GitLab package registry path traversal leads to authenticated remote code executionHIGH 8.8
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-78905
Chrome ANGLE type confusion allows remote code execution from a web pageHIGH 8.8
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-78938
Chrome type confusion in V8 remote code executionHIGH 8.8
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-79266
Chrome DevTools use-after-free allows extension to execute codeHIGH 8.8
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-18729
Langflow OSS authenticated remote code executionHIGH 8.8
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-65643
CPanel eval injection authenticated code execution as rootHIGH 8.8
- PoC PUBLIC
- PATCH AVAILABLE
- CVE-2026-84645 HIGH 8.8
- CVE-2026-28618 HIGH 8.8
No CVEs on this page match the filters.
20 CVEs · page 16 of 23
About CVE Radar
CVE Radar tracks newly published Common Vulnerabilities and Exposures (CVEs) from NVD, the CISA Known Exploited Vulnerabilities catalog and vendor security advisories. Each entry is reviewed by Diras Labs analysts and includes affected versions, exploitation status, remediation guidance and relevance to organizations in Saudi Arabia and the GCC.