UPDATED SEP 30, 2026

CVE Radar: latest vulnerabilities, exploited CVEs and patches (page 7)

A daily, analyst-curated feed of new and actively exploited CVEs, with severity, exploitation status, affected versions and remediation steps for each.

  1. CVE-2026-34265
    SAP NetWeaver and ABAP Platform DIAG parsing memory corruption vulnerability SAP SAP NetWeaver and ABAP Platform ·
    CRITICAL 9.8
  2. CVE-2026-62815
    Windows 11 use-after-free in Microsoft QUIC allows remote code execution Microsoft Windows 11 version 23H2 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  3. CVE-2026-62878
    Windows Server DNS stack buffer overflow remote code execution Microsoft Windows Server 2012 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
  4. CVE-2026-62893
    Windows Server use-after-free in Windows Deployment Services allows remote code execution Microsoft Windows Server 2012 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  5. CVE-2026-65768
    Microsoft Teams for Android path traversal pre-auth remote code execution Microsoft Microsoft Teams for Android ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  6. CVE-2026-65791
    Windows iSCSI Target heap buffer overflow remote code execution Microsoft Windows 10 Version 1607 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  7. CVE-2026-26035 CRITICAL 9.8
  8. CVE-2026-19001
    MongoDB BI Connector ODBC Driver buffer overflow in metadata functions MongoDB BI Connector ODBC Driver ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  9. CVE-2026-75003
    Roundcube Webmail SVG url() bypass lets crafted images leak data Roundcube Webmail ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  10. CVE-2026-74936
    Firefox use-after-free in WebAssembly remote code execution Mozilla Firefox ·
    • PoC PUBLIC
    CRITICAL 9.8
  11. CVE-2026-74943
    Firefox use-after-free in ImageLib allows remote code execution Mozilla Firefox ·
    • PoC PUBLIC
    CRITICAL 9.8
  12. CVE-2026-74940 CRITICAL 9.8
  13. CVE-2026-74944
    Firefox use-after-free in DOM remote code execution Mozilla Firefox ·
    CRITICAL 9.8
  14. CVE-2026-74964 CRITICAL 9.8
  15. CVE-2026-74979 CRITICAL 9.8
  16. CVE-2026-74987
    Firefox memory-corruption remote attack Mozilla Firefox ·
    CRITICAL 9.8
  17. CVE-2026-74990 CRITICAL 9.8
  18. CVE-2026-74988
    Firefox pre-auth remote code execution Mozilla Firefox ·
    CRITICAL 9.8
  19. CVE-2026-74989
    Firefox memory-corruption remote code execution Mozilla Firefox ·
    CRITICAL 9.8
  20. CVE-2026-74985 CRITICAL 9.8
20 CVEs · page 7 of 23

About CVE Radar

CVE Radar tracks newly published Common Vulnerabilities and Exposures (CVEs) from NVD, the CISA Known Exploited Vulnerabilities catalog and vendor security advisories. Each entry is reviewed by Diras Labs analysts and includes affected versions, exploitation status, remediation guidance and relevance to organizations in Saudi Arabia and the GCC.