UPDATED SEP 30, 2026

CVE Radar: latest vulnerabilities, exploited CVEs and patches (page 17)

A daily, analyst-curated feed of new and actively exploited CVEs, with severity, exploitation status, affected versions and remediation steps for each.

  1. CVE-2026-28609 HIGH 8.8
  2. CVE-2026-65374
    MacOS WebDAV memory corruption remote code execution Apple macOS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  3. CVE-2026-58704
    Pixel cellular modem permission bypass privilege escalation Google Pixel ·
    • CISA KEV
    • EXPLOITED
    HIGH 8.8
  4. CVE-2026-86950
    Apple CoreGraphics out-of-bounds write leads to code execution Apple Multiple Products ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  5. CVE-2026-64638
    WordPress pre-auth reflected XSS on login page WordPress WordPress ·
    • PoC PUBLIC
    HIGH 8.9
  6. CVE-2026-48710
    Starlette Host header validation bypass alters reconstructed request URL Kludex Starlette ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    MEDIUM 6.5
  7. CVE-2026-89274
    WP Recipe Maker arbitrary shortcode execution in metadata brechtvds WP Recipe Maker ·
    • PoC PUBLIC
    CRITICAL 9.1
  8. CVE-2026-93399
    Bookly Insecure direct object reference exposes order tokens ladela Online Scheduling and Appointment Booking System – Bookly ·
    • PoC PUBLIC
    CRITICAL 9.1
  9. CVE-2026-84388
    FortiPAM Chrome Extension information disclosure via UI layer restriction Fortinet FortiPAM Chrome Extension ·
    • PoC PUBLIC
    CRITICAL 9.6
  10. CVE-2026-15826
    User Profile Builder authentication bypass lets unauthenticated users become admin cozmoslabs User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor ·
    • PoC PUBLIC
    CRITICAL 9.8
  11. CVE-2026-12793
    JetFormBuilder privilege escalation lets unauthenticated attacker create admin jetmonsters JetFormBuilder — Dynamic Blocks Form Builder ·
    • PoC PUBLIC
    CRITICAL 9.8
  12. CVE-2026-82901
    Ultra Addons for Contact Form 7 arbitrary file upload (unauthenticated) themefic Ultra Addons for Contact Form 7 ·
    • PoC PUBLIC
    CRITICAL 9.8
  13. CVE-2026-20303
    Cisco Catalyst SD-WAN Controller improper input validation remote code execution Cisco Cisco Catalyst SD-WAN Controller ·
    • PoC PUBLIC
    CRITICAL 9.9
  14. CVE-2026-43825
    Apache OpenNLP LibSVM untrusted Java deserialization remote code execution Apache Software Foundation Apache OpenNLP :: Core :: ML :: LibSVM ·
    • PATCH AVAILABLE
    HIGH 7.3
  15. CVE-2026-20217
    Cisco Secure Endpoint ClamAV PESpin parser remote denial-of-service Cisco Cisco Secure Endpoint ·
    • PoC PUBLIC
    HIGH 7.5
  16. CVE-2026-13181
    Telerik UI for ASP.NET AJAX pre-auth remote code execution Progress Software Telerik UI for ASP.NET AJAX ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.1
  17. CVE-2026-67276
    RouterOS SSH RSA key validation authentication bypass MikroTik RouterOS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.1
  18. CVE-2026-19516
    Grafana MCP Server server-side request forgery (SSRF) Grafana Grafana MCP Server ·
    • PoC PUBLIC
    CRITICAL 9.1
  19. CVE-2026-82078
    PaperCut NG/MF unsafe dynamic class loading allows remote code execution PaperCut NG/MF ·
    • CISA KEV
    • EXPLOITED
    • PATCH AVAILABLE
    CRITICAL 9.1
  20. CVE-2026-48356
    Adobe Commerce unrestricted file upload leading to remote code execution Adobe Adobe Commerce ·
    • PoC PUBLIC
    CRITICAL 9.3
20 CVEs · page 17 of 23

About CVE Radar

CVE Radar tracks newly published Common Vulnerabilities and Exposures (CVEs) from NVD, the CISA Known Exploited Vulnerabilities catalog and vendor security advisories. Each entry is reviewed by Diras Labs analysts and includes affected versions, exploitation status, remediation guidance and relevance to organizations in Saudi Arabia and the GCC.