UPDATED SEP 30, 2026

CVE Radar: latest vulnerabilities, exploited CVEs and patches (page 6)

A daily, analyst-curated feed of new and actively exploited CVEs, with severity, exploitation status, affected versions and remediation steps for each.

  1. CVE-2026-64738
    IOS and iPadOS sandbox escape allows app to break out of sandbox Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  2. CVE-2026-64731
    MacOS path handling sandbox escape Apple macOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  3. CVE-2026-64746
    IOS and iPadOS authorization bypass lets apps add contacts Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  4. CVE-2026-64751
    IOS and iPadOS use-after-free remote code execution Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  5. CVE-2026-64767
    MacOS buffer overflow pre-auth remote code execution Apple macOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  6. CVE-2026-64762
    IOS and iPadOS out-of-bounds read may cause system termination Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  7. CVE-2026-64774
    IOS and iPadOS integer overflow leads to remote heap corruption Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  8. CVE-2026-64775
    IOS and iPadOS memory initialization flaw allows remote code execution Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  9. CVE-2026-64770
    IOS and iPadOS out-of-bounds write may allow remote impact Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  10. CVE-2026-64772
    IOS and iPadOS out-of-bounds write remote code execution Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  11. CVE-2026-64769
    IOS and iPadOS out-of-bounds write allows remote code execution Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  12. CVE-2026-64771
    IOS and iPadOS buffer overflow allows remote code execution Apple iOS and iPadOS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  13. CVE-2026-12940
    Langflow OSS environment-variable RCE in MCP stdio launcher IBM Langflow OSS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
  14. CVE-2026-68771
    ComfyUI unsafe deserialization pre-auth remote code execution Comfy-Org ComfyUI ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
  15. CVE-2026-8457 CRITICAL 9.8
  16. CVE-2026-0163 CRITICAL 9.8
  17. CVE-2026-20272 CRITICAL 9.8
  18. CVE-2026-9205
    Langflow OSS weak key derivation allows remote secret compromise IBM Langflow OSS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  19. CVE-2026-28005
    Kadence WooCommerce Email Designer unauthenticated privilege escalation Nexcess Kadence WooCommerce Email Designer ·
    CRITICAL 9.8
  20. CVE-2026-56793
    OpenManage Server Administrator improper authentication remote access Dell OpenManage Server Administrator Managed Node (Patch) for Windows ·
    • PATCH AVAILABLE
    CRITICAL 9.8
20 CVEs · page 6 of 23

About CVE Radar

CVE Radar tracks newly published Common Vulnerabilities and Exposures (CVEs) from NVD, the CISA Known Exploited Vulnerabilities catalog and vendor security advisories. Each entry is reviewed by Diras Labs analysts and includes affected versions, exploitation status, remediation guidance and relevance to organizations in Saudi Arabia and the GCC.