UPDATED SEP 30, 2026
CVE Radar: latest vulnerabilities, exploited CVEs and patches (page 21)
A daily, analyst-curated feed of new and actively exploited CVEs, with severity, exploitation status, affected versions and remediation steps for each.
-
CVE-2026-8037
LoadMaster command injection pre-auth remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-25089
FortiSandbox OS command injection unauthenticated remote command executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-86060
RouterOS SSH login username handling lets unauthenticated users escalate privilegesCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-85102
Quantum Security Gateway improper certificate validation lets unauthenticated attacker run codeCRITICAL 9.8
- CISA KEV
- EXPLOITED
-
CVE-2026-76461
Cisco Secure Email Gateway SQL injection leads to pre-auth remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-93616
Quantum Security Management directory traversal allows unauthenticated code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-20079
Cisco Secure Firewall Management Center authentication bypass and RCECRITICAL 10
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-15409
SonicWall SMA1000 SSRF allows unauthenticated request forgingCRITICAL 10
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-0770
Langflow exec_globals pre-auth remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-8452
Citrix NetScaler ADC and Gateway memory overflow pre-auth remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-50522
SharePoint deserialization pre-auth remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-56164
SharePoint Server missing authentication allows privilege elevationCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-59310
VMware vCenter directory traversal lets network attacker execute codeCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-65400
MacOS Screen Sharing improper authentication lets network attacker bypass credentialsCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-19478
GitLab GraphQL directive lets unauthenticated users modify public projectsCRITICAL 9.1
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-18577
N-central authentication bypass that can enable account takeoverHIGH 8.1
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-56291
Balbooa Forms unauthenticated file upload remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-9586
Switchvox SQL injection allows unauthenticated remote SQL executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-60004
Gitea code injection via diffpatch API remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-82329
Artifactory authentication weakness allows pre-auth admin takeoverCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
No CVEs on this page match the filters.
20 CVEs · page 21 of 23
About CVE Radar
CVE Radar tracks newly published Common Vulnerabilities and Exposures (CVEs) from NVD, the CISA Known Exploited Vulnerabilities catalog and vendor security advisories. Each entry is reviewed by Diras Labs analysts and includes affected versions, exploitation status, remediation guidance and relevance to organizations in Saudi Arabia and the GCC.