UPDATED SEP 30, 2026

CVE Radar: latest vulnerabilities, exploited CVEs and patches (page 9)

A daily, analyst-curated feed of new and actively exploited CVEs, with severity, exploitation status, affected versions and remediation steps for each.

  1. CVE-2026-84140 CRITICAL 9.8
  2. CVE-2026-84141
    Firefox integer overflow in ImageLib component Mozilla Firefox ·
    CRITICAL 9.8
  3. CVE-2026-84143
    Firefox memory-corruption remote code execution Mozilla Firefox ·
    CRITICAL 9.8
  4. CVE-2026-84325
    Chrome DataTransfer input validation bypass allows system-access bypass Google Chrome ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  5. CVE-2026-20274
    Cisco IOS XR Software improper resource control vulnerability Cisco Cisco IOS XR Software ·
    CRITICAL 9.8
  6. CVE-2026-20279 CRITICAL 9.8
  7. CVE-2026-84238
    YITH Request a Quote for WooCommerce Premium unauthenticated broken access control YITH YITH Request a Quote for WooCommerce Premium ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  8. CVE-2026-58240 CRITICAL 9.8
  9. CVE-2026-68839
    Windows USB Mass Storage heap overflow remote code execution Microsoft Windows 10 Version 1607 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  10. CVE-2026-69276
    Windows UxTheme integer underflow remote code execution Microsoft Windows 10 Version 1607 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  11. CVE-2026-69408
    Windows 10 Version 1607 integer overflow in Media Foundation allows remote code execution Microsoft Windows 10 Version 1607 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  12. CVE-2026-69431
    Windows Telnet Client heap-based buffer overflow remote code execution Microsoft Windows 10 Version 1607 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  13. CVE-2026-69463
    Windows NTFS heap overflow remote code execution Microsoft Windows 10 Version 1607 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  14. CVE-2026-69491
    Windows 10 Version 1607 heap buffer overflow in DirectMusic allows remote code execution Microsoft Windows 10 Version 1607 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  15. CVE-2026-69493
    Windows 10 Event Logging out-of-bounds remote code execution Microsoft Windows 10 Version 1607 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  16. CVE-2026-69496
    Windows Compressed Folder heap overflow remote code execution Microsoft Windows 10 Version 1607 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  17. CVE-2026-69525
    Windows Remote Desktop Services use-after-free remote code execution Microsoft Windows 10 Version 1607 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  18. CVE-2026-69579
    Windows Message Queuing use-after-free remote code execution Microsoft Windows 10 Version 1607 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  19. CVE-2026-69586
    Windows 10 Version 1607 integer overflow remote code execution Microsoft Windows 10 Version 1607 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  20. CVE-2026-69590
    Windows 10 Version 1607 RRAS remote code execution Microsoft Windows 10 Version 1607 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
20 CVEs · page 9 of 23

About CVE Radar

CVE Radar tracks newly published Common Vulnerabilities and Exposures (CVEs) from NVD, the CISA Known Exploited Vulnerabilities catalog and vendor security advisories. Each entry is reviewed by Diras Labs analysts and includes affected versions, exploitation status, remediation guidance and relevance to organizations in Saudi Arabia and the GCC.