UPDATED SEP 30, 2026
CVE Radar: latest vulnerabilities, exploited CVEs and patches (page 22)
A daily, analyst-curated feed of new and actively exploited CVEs, with severity, exploitation status, affected versions and remediation steps for each.
-
CVE-2026-72898
Metabase SQL injection in reset_password allows remote admin takeoverCRITICAL 10
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-15410
SMA1000 Appliances post-auth code injection allows OS command executionHIGH 7.2
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-20316
Cisco Secure Firewall Management Center hard-coded low-privileged loginMEDIUM 5.3
- CISA KEV
- EXPLOITED
-
CVE-2026-63077
TeamCity unauthenticated remote code execution via agent pollingCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-73570
Zimbra Collaboration Suite OS command injection via SMTP/SNMPHIGH 8.9
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-55040
SharePoint weak authentication pre-auth bypass vulnerabilityCRITICAL 9.1
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-58644
SharePoint deserialization remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PATCH AVAILABLE
-
CVE-2026-9198
Langflow unauthenticated remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-63030
WordPress Core REST API route confusion remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-16232
SmartConsole authentication bypass allows full admin takeoverCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-71362
Adobe Commerce and Magento incorrect authorization pre-auth privilege escalationCRITICAL 9.1
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-94127
BIG-IP APM heap buffer overflow remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-83548
SMA1000 Appliances pre-auth server-side request forgery (SSRF)CRITICAL 10
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-76460
Cisco Identity Services Engine API authentication bypassCRITICAL 10
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-75650
Adobe Commerce and Magento remote code execution via template engineCRITICAL 10
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-85706
GitLab repository commits API path traversal lets unauthenticated read filesCRITICAL 10
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-87902
Remote file inclusion via page-template resolution (get_page_template)HIGH 8.1
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-65660
code injection in SharePoint server allowing remote code executionHIGH 8.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-67279
Improper workflow enforcement in RouterOS SSH allows unauthenticated file writesMEDIUM 6.5
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-88771
Improper input validation in NetScaler ADC and Gateway allowing remote command executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
No CVEs on this page match the filters.
20 CVEs · page 22 of 23
About CVE Radar
CVE Radar tracks newly published Common Vulnerabilities and Exposures (CVEs) from NVD, the CISA Known Exploited Vulnerabilities catalog and vendor security advisories. Each entry is reviewed by Diras Labs analysts and includes affected versions, exploitation status, remediation guidance and relevance to organizations in Saudi Arabia and the GCC.