UPDATED SEP 30, 2026
CVE Radar: latest vulnerabilities, exploited CVEs and patches (page 6)
A daily, analyst-curated feed of new and actively exploited CVEs, with severity, exploitation status, affected versions and remediation steps for each.
-
CVE-2026-64738
IOS and iPadOS sandbox escape allows app to break out of sandboxCRITICAL 9.8
- PATCH AVAILABLE
-
CVE-2026-64731
MacOS path handling sandbox escapeCRITICAL 9.8
- PATCH AVAILABLE
-
CVE-2026-64746
IOS and iPadOS authorization bypass lets apps add contactsCRITICAL 9.8
- PATCH AVAILABLE
-
CVE-2026-64751
IOS and iPadOS use-after-free remote code executionCRITICAL 9.8
- PATCH AVAILABLE
-
CVE-2026-64767
MacOS buffer overflow pre-auth remote code executionCRITICAL 9.8
- PATCH AVAILABLE
-
CVE-2026-64762
IOS and iPadOS out-of-bounds read may cause system terminationCRITICAL 9.8
- PATCH AVAILABLE
-
CVE-2026-64774
IOS and iPadOS integer overflow leads to remote heap corruptionCRITICAL 9.8
- PATCH AVAILABLE
- CVE-2026-64775 CRITICAL 9.8
-
CVE-2026-64770
IOS and iPadOS out-of-bounds write may allow remote impactCRITICAL 9.8
- PATCH AVAILABLE
-
CVE-2026-64772
IOS and iPadOS out-of-bounds write remote code executionCRITICAL 9.8
- PATCH AVAILABLE
-
CVE-2026-64769
IOS and iPadOS out-of-bounds write allows remote code executionCRITICAL 9.8
- PATCH AVAILABLE
-
CVE-2026-64771
IOS and iPadOS buffer overflow allows remote code executionCRITICAL 9.8
- PATCH AVAILABLE
-
CVE-2026-12940
Langflow OSS environment-variable RCE in MCP stdio launcherCRITICAL 9.8
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-68771
ComfyUI unsafe deserialization pre-auth remote code executionCRITICAL 9.8
- PoC PUBLIC
- PATCH AVAILABLE
- CVE-2026-8457 CRITICAL 9.8
- CVE-2026-0163 CRITICAL 9.8
- CVE-2026-20272 CRITICAL 9.8
-
CVE-2026-9205
Langflow OSS weak key derivation allows remote secret compromiseCRITICAL 9.8
- PATCH AVAILABLE
- CVE-2026-28005 CRITICAL 9.8
- CVE-2026-56793 CRITICAL 9.8
No CVEs on this page match the filters.
20 CVEs · page 6 of 23
About CVE Radar
CVE Radar tracks newly published Common Vulnerabilities and Exposures (CVEs) from NVD, the CISA Known Exploited Vulnerabilities catalog and vendor security advisories. Each entry is reviewed by Diras Labs analysts and includes affected versions, exploitation status, remediation guidance and relevance to organizations in Saudi Arabia and the GCC.