UPDATED SEP 30, 2026

CVE Radar: latest vulnerabilities, exploited CVEs and patches (page 4)

A daily, analyst-curated feed of new and actively exploited CVEs, with severity, exploitation status, affected versions and remediation steps for each.

  1. CVE-2026-43790 CRITICAL 9.1
  2. CVE-2026-84625
    IOS and iPadOS permissions issue lets an app fingerprint the user Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.1
  3. CVE-2026-86881
    IOS and iPadOS certificate validation bypass Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.1
  4. CVE-2026-92034 CRITICAL 9.1
  5. CVE-2026-92038
    Firefox mitigation bypass in Remote Settings Client Mozilla Firefox ·
    CRITICAL 9.1
  6. CVE-2026-92041 CRITICAL 9.1
  7. CVE-2026-92051 CRITICAL 9.1
  8. CVE-2026-92050
    Firefox sandbox escape via XPConnect race condition Mozilla Firefox ·
    CRITICAL 9.1
  9. CVE-2026-92057
    Firefox Enterprise Policies mitigation bypass Mozilla Firefox ·
    CRITICAL 9.1
  10. CVE-2026-92075
    Firefox mitigation bypass in Networking component Mozilla Firefox ·
    CRITICAL 9.1
  11. CVE-2026-92079
    Firefox Widget Win32 mitigation bypass Mozilla Firefox ·
    CRITICAL 9.1
  12. CVE-2026-83944
    Azure Logic Apps pre-auth privilege escalation via improper access control Microsoft Azure Logic Apps ·
    • PATCH AVAILABLE
    CRITICAL 9.1
  13. CVE-2026-93765 CRITICAL 9.1
  14. CVE-2026-89282
    Apache Lounge Windows insecure install directory permissions allow file modification Apache HTTP Server Project Apache Lounge Windows ·
    • PATCH AVAILABLE
    CRITICAL 9.1
  15. CVE-2026-86350
    Apache Tomcat HTTP/2 request smuggling regression Apache Software Foundation Apache Tomcat ·
    • PoC PUBLIC
    CRITICAL 9.1
  16. CVE-2026-86246
    Apache Tomcat Native insecure-default TLS options Apache Software Foundation Apache Tomcat Native ·
    CRITICAL 9.1
  17. CVE-2026-77987
    GitHub Enterprise Server SSRF leads to remote code execution GitHub Enterprise Server ·
    • PATCH AVAILABLE
    CRITICAL 9.3
  18. CVE-2026-70757
    Oracle WebLogic Server unauthenticated remote code execution via T3/IIOP Oracle Oracle WebLogic Server ·
    CRITICAL 9.8
  19. CVE-2026-70748
    Oracle WebLogic Server unauthenticated remote takeover via T3/IIOP Oracle Oracle WebLogic Server ·
    CRITICAL 9.8
  20. CVE-2026-70756
    Oracle WebLogic Server unauthenticated remote takeover via T3/IIOP Oracle Oracle WebLogic Server ·
    CRITICAL 9.8
20 CVEs · page 4 of 23

About CVE Radar

CVE Radar tracks newly published Common Vulnerabilities and Exposures (CVEs) from NVD, the CISA Known Exploited Vulnerabilities catalog and vendor security advisories. Each entry is reviewed by Diras Labs analysts and includes affected versions, exploitation status, remediation guidance and relevance to organizations in Saudi Arabia and the GCC.