UPDATED SEP 30, 2026

CVE Radar: latest vulnerabilities, exploited CVEs and patches (page 2)

A daily, analyst-curated feed of new and actively exploited CVEs, with severity, exploitation status, affected versions and remediation steps for each.

  1. CVE-2026-85103
    Quantum Security Gateway heap buffer overflow in certificate parsing Check Point Quantum Security Gateway ·
    CRITICAL 9.8
  2. CVE-2026-84390
    FortiMonitorOnSight source-code sensitive information disclosure Fortinet FortiMonitorOnSight ·
    CRITICAL 9.8
  3. CVE-2026-20353 CRITICAL 9.8
  4. CVE-2026-76443 CRITICAL 9.8
  5. CVE-2026-76441
    Cisco Secure Email and Web Manager improper access control allows remote takeover Cisco Cisco Secure Email and Web Manager ·
    CRITICAL 9.8
  6. CVE-2026-76440 CRITICAL 9.8
  7. CVE-2026-91843
    Quantum Security Management stack overflow allows unauthenticated remote code execution Check Point Quantum Security Management ·
    • PoC PUBLIC
    CRITICAL 9.8
  8. CVE-2026-20242
    Cisco Secure Firewall Management Center insecure deserialization remote root execution Cisco Cisco Secure Firewall Management Center (FMC) ·
    CRITICAL 9.8
  9. CVE-2026-20326
    Cisco Nexus Dashboard missing authentication for critical functions Cisco Cisco Nexus Dashboard ·
    CRITICAL 9.8
  10. CVE-2026-28324
    SolarWinds Observability Self-Hosted unauthenticated remote code execution SolarWinds Observability Self-Hosted ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  11. CVE-2026-26084 CRITICAL 9.9
  12. CVE-2026-80098
    Microsoft Copilot Studio signature verification flaw allows remote privilege escalation Microsoft Microsoft Copilot Studio ·
    • PATCH AVAILABLE
    CRITICAL 10
  13. CVE-2026-83711
    Entra authorization bypass via user-controlled key Microsoft Entra ·
    • PATCH AVAILABLE
    CRITICAL 10
  14. CVE-2026-44756 CRITICAL 10
  15. CVE-2026-80462
    Chef Automate unauthenticated privilege escalation via API gateway Progress Software Chef Automate ·
    • PATCH AVAILABLE
    CRITICAL 10
  16. CVE-2026-20130
    Cisco Identity Services Engine pre-auth remote code execution Cisco Cisco Identity Services Engine Software ·
    CRITICAL 10
  17. CVE-2026-20192
    Cisco Identity Services Engine improper access control vulnerability Cisco Cisco Identity Services Engine Software ·
    CRITICAL 10
  18. CVE-2026-76423
    Cisco Identity Services Engine unauthenticated admin access via REST API Cisco Cisco Identity Services Engine Software ·
    CRITICAL 10
  19. CVE-2026-69843
    Microsoft Fabric authentication bypass by spoofing allows privilege elevation Microsoft Microsoft Fabric ·
    • PATCH AVAILABLE
    CRITICAL 10
  20. CVE-2026-75528 HIGH 7.2
20 CVEs · page 2 of 23

About CVE Radar

CVE Radar tracks newly published Common Vulnerabilities and Exposures (CVEs) from NVD, the CISA Known Exploited Vulnerabilities catalog and vendor security advisories. Each entry is reviewed by Diras Labs analysts and includes affected versions, exploitation status, remediation guidance and relevance to organizations in Saudi Arabia and the GCC.