UPDATED SEP 30, 2026
CVE Radar: latest vulnerabilities, exploited CVEs and patches (page 20)
A daily, analyst-curated feed of new and actively exploited CVEs, with severity, exploitation status, affected versions and remediation steps for each.
-
CVE-2026-56155
Active Directory Federation Services insufficient access control local privilege elevationHIGH 7.8
- CISA KEV
- EXPLOITED
- PATCH AVAILABLE
-
CVE-2026-83549
SMA1000 Appliances OS command injection requiring admin credentialsHIGH 7.8
- CISA KEV
- EXPLOITED
-
CVE-2019-1068
SQL Server remote code execution in internal function handlingHIGH 8.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-7273
Zyxel GS1900 Series Switches stack-based buffer overflow in CGIHIGH 8.8
- CISA KEV
- EXPLOITED
-
CVE-2026-68820
Windows Ancillary Function Driver for WinSock use-after-free local privilege escalationHIGH 7
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-81963
Windows local privilege escalation in Windows Update Stack (link following)HIGH 7.8
- CISA KEV
- EXPLOITED
- PATCH AVAILABLE
-
CVE-2026-85880
Windows ALPC heap overflow local privilege escalationHIGH 7.8
- CISA KEV
- EXPLOITED
- PATCH AVAILABLE
-
CVE-2008-4128
Cisco IOS cross-site request forgery lets remote attackers run commandsHIGH 8.1
- CISA KEV
- EXPLOITED
-
CVE-2026-55255
Langflow authorization bypass lets authenticated users run other users' flowsHIGH 8.4
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-45659
SharePoint Server deserialization flaw allows authenticated remote code executionHIGH 8.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-85046
Chromium V8 type confusion remote code executionHIGH 8.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-87491
Chromium V8 out-of-bounds write remote code executionHIGH 8.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2025-68686
FortiOS exposure of sensitive information to unauthenticated remote actorsMEDIUM 5.9
- CISA KEV
- EXPLOITED
-
CVE-2026-60137
WordPress Core SQL injection via author__not_in parameterMEDIUM 5.9
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-84869
ScreenConnect missing authorization lets active-session attacker transfer and run filesCRITICAL 9.9
- CISA KEV
- EXPLOITED
-
CVE-2026-67277
RouterOS missing-auth btest service kernel crash and memory disclosureHIGH 8.2
- CISA KEV
- EXPLOITED
- PATCH AVAILABLE
-
CVE-2026-34486
Tomcat encrypt interceptor bypass exposes sensitive dataHIGH 7.5
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2025-25249
Fortinet FortiOS and FortiSwitchManager heap buffer overflow remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
-
CVE-2026-39808
FortiSandbox OS command injection unauthenticated remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-33824
Internet Key Exchange (IKE) Service Extensions double free remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
No CVEs on this page match the filters.
20 CVEs · page 20 of 23
About CVE Radar
CVE Radar tracks newly published Common Vulnerabilities and Exposures (CVEs) from NVD, the CISA Known Exploited Vulnerabilities catalog and vendor security advisories. Each entry is reviewed by Diras Labs analysts and includes affected versions, exploitation status, remediation guidance and relevance to organizations in Saudi Arabia and the GCC.