UPDATED SEP 30, 2026
CVE Radar: latest vulnerabilities, exploited CVEs and patches (page 17)
A daily, analyst-curated feed of new and actively exploited CVEs, with severity, exploitation status, affected versions and remediation steps for each.
- CVE-2026-28609 HIGH 8.8
-
CVE-2026-65374
MacOS WebDAV memory corruption remote code executionHIGH 8.8
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-58704
Pixel cellular modem permission bypass privilege escalationHIGH 8.8
- CISA KEV
- EXPLOITED
-
CVE-2026-86950
Apple CoreGraphics out-of-bounds write leads to code executionHIGH 8.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
- CVE-2026-64638 HIGH 8.9
-
CVE-2026-48710
Starlette Host header validation bypass alters reconstructed request URLMEDIUM 6.5
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- CVE-2026-89274 CRITICAL 9.1
- CVE-2026-93399 CRITICAL 9.1
- CVE-2026-84388 CRITICAL 9.6
- CVE-2026-15826 CRITICAL 9.8
- CVE-2026-12793 CRITICAL 9.8
- CVE-2026-82901 CRITICAL 9.8
- CVE-2026-20303 CRITICAL 9.9
- CVE-2026-43825 HIGH 7.3
- CVE-2026-20217 HIGH 7.5
-
CVE-2026-13181
Telerik UI for ASP.NET AJAX pre-auth remote code executionHIGH 8.1
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-67276
RouterOS SSH RSA key validation authentication bypassHIGH 8.1
- PoC PUBLIC
- PATCH AVAILABLE
- CVE-2026-19516 CRITICAL 9.1
-
CVE-2026-82078
PaperCut NG/MF unsafe dynamic class loading allows remote code executionCRITICAL 9.1
- CISA KEV
- EXPLOITED
- PATCH AVAILABLE
- CVE-2026-48356 CRITICAL 9.3
No CVEs on this page match the filters.
20 CVEs · page 17 of 23
About CVE Radar
CVE Radar tracks newly published Common Vulnerabilities and Exposures (CVEs) from NVD, the CISA Known Exploited Vulnerabilities catalog and vendor security advisories. Each entry is reviewed by Diras Labs analysts and includes affected versions, exploitation status, remediation guidance and relevance to organizations in Saudi Arabia and the GCC.