UPDATED SEP 30, 2026

CVE Radar: latest vulnerabilities, exploited CVEs and patches (page 5)

A daily, analyst-curated feed of new and actively exploited CVEs, with severity, exploitation status, affected versions and remediation steps for each.

  1. CVE-2026-76183
    Apache Tomcat authentication bypass for WebSocket endpoints Apache Software Foundation Apache Tomcat ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  2. CVE-2026-86248
    Apache Tomcat CLIENT_CERT authentication bypass (pre-auth) Apache Software Foundation Apache Tomcat ·
    CRITICAL 9.8
  3. CVE-2026-83021
    Oracle WebLogic Server unauthenticated HTTP remote takeover Oracle Oracle WebLogic Server ·
    CRITICAL 10
  4. CVE-2026-96587
    Dashcam Android Application embedded cloud credentials allow full storage access Viidure Dashcam Android Application ·
    CRITICAL 10
  5. CVE-2026-92229
    Forminator Forms pre-auth shortcode execution wpmudev Forminator Forms – Contact Form, Payment Form & Custom Form Builder ·
    • PoC PUBLIC
    CRITICAL 9.1
  6. CVE-2026-93485
    WordPress DOM-based cross-site scripting vulnerability Automattic WordPress ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.1
  7. CVE-2026-89055
    Customer Reviews for WooCommerce authorization bypass deletes media ivole Customer Reviews for WooCommerce ·
    • PoC PUBLIC
    CRITICAL 9.1
  8. CVE-2026-64703
    MacOS use-after-free lets an app cause denial-of-service Apple macOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  9. CVE-2026-64695
    IOS and iPadOS kernel memory corruption over network Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  10. CVE-2026-64697
    MacOS kernel memory corruption remote code execution Apple macOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  11. CVE-2026-64704
    MacOS type confusion pre-auth remote code execution Apple macOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  12. CVE-2026-64702
    MacOS sandbox escape lets an app break out of its sandbox Apple macOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  13. CVE-2026-64700
    IOS and iPadOS use-after-free may let an app terminate the system Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  14. CVE-2026-64694
    MacOS integer overflow leads to remote code execution potential Apple macOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  15. CVE-2026-64698
    MacOS kernel memory bug lets local apps crash or read kernel memory Apple macOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  16. CVE-2026-64720
    IOS and iPadOS race condition lets remote attacker crash system Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  17. CVE-2026-64727 CRITICAL 9.8
  18. CVE-2026-64726
    IOS and iPadOS memory corruption allows remote code execution Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  19. CVE-2026-64729
    IOS and iPadOS use-after-free lets an app cause system termination Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  20. CVE-2026-64733
    IOS and iPadOS app fingerprinting information disclosure Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
20 CVEs · page 5 of 23

About CVE Radar

CVE Radar tracks newly published Common Vulnerabilities and Exposures (CVEs) from NVD, the CISA Known Exploited Vulnerabilities catalog and vendor security advisories. Each entry is reviewed by Diras Labs analysts and includes affected versions, exploitation status, remediation guidance and relevance to organizations in Saudi Arabia and the GCC.