UPDATED SEP 30, 2026

CVE Radar: latest vulnerabilities, exploited CVEs and patches (page 8)

A daily, analyst-curated feed of new and actively exploited CVEs, with severity, exploitation status, affected versions and remediation steps for each.

  1. CVE-2026-73373
    Joomla! CMS unrestricted SHTML upload allows remote code execution Joomla! Project Joomla! CMS ·
    CRITICAL 9.8
  2. CVE-2026-66682
    Abandoned Cart Pro for WooCommerce unauthenticated privilege escalation Tyche Softwares Abandoned Cart Pro for WooCommerce ·
    CRITICAL 9.8
  3. CVE-2026-77070 CRITICAL 9.8
  4. CVE-2026-62834
    Azure Data Factory improper signature verification allows privilege elevation Microsoft Azure Data Factory ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  5. CVE-2026-32558
    Affiliate Pro unauthenticated privilege escalation RedefiningTheWeb Affiliate Pro - Affiliate Program for WooCommerce & WordPress ·
    CRITICAL 9.8
  6. CVE-2026-63073
    OpenSSL CMP format-string denial of service OpenSSL OpenSSL ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  7. CVE-2026-79090
    Chrome improper privilege management lets remote attacker bypass access Google Chrome ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  8. CVE-2026-79152
    Chrome CustomTabs authorization bypass via co-installed app Google Chrome ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  9. CVE-2026-65637
    Apache Tomcat improper input validation allows remote code execution Apache Software Foundation Apache Tomcat ·
    CRITICAL 9.8
  10. CVE-2026-16639
    Internationalization Single Sign-On authentication bypass Drupal Internationalization Single Sign-On ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  11. CVE-2026-16641 CRITICAL 9.8
  12. CVE-2026-47890
    Spring Framework SSE stream corruption Spring Spring Framework ·
    CRITICAL 9.8
  13. CVE-2026-47891
    Spring Framework Aalto XML maxInMemorySize bypass Spring Spring Framework ·
    CRITICAL 9.8
  14. CVE-2026-59313
    Spring Framework stream corruption in SSE Spring Spring Framework ·
    CRITICAL 9.8
  15. CVE-2026-19286
    Langflow OSS A2A endpoint remote code execution IBM Langflow OSS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
  16. CVE-2026-84129 CRITICAL 9.8
  17. CVE-2026-84135 CRITICAL 9.8
  18. CVE-2026-84134 CRITICAL 9.8
  19. CVE-2026-84133 CRITICAL 9.8
  20. CVE-2026-84142 CRITICAL 9.8
20 CVEs · page 8 of 23

About CVE Radar

CVE Radar tracks newly published Common Vulnerabilities and Exposures (CVEs) from NVD, the CISA Known Exploited Vulnerabilities catalog and vendor security advisories. Each entry is reviewed by Diras Labs analysts and includes affected versions, exploitation status, remediation guidance and relevance to organizations in Saudi Arabia and the GCC.