Skip to content
October 4, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button

Weekly Recap

Weekly CVE report comparing exploited vulnerabilities from Daily Cybersecurity intelligence with the CISA KEV catalog for September 21-27, 2026
  • Weekly Recap

Weekly CVE Report: 2,825 New Flaws and 9 Exploited Bugs (Sept 21-27, 2026)

Do Son September 28, 2026 0
CVE-2023-50164 AEM Forms
  • Weekly Recap

Weekly CVE Report: 4,378 New Flaws and 10 Exploited Bugs

Do Son September 21, 2026 0
Weekly CVE report chart comparing Daily Cybersecurity exploited vulnerabilities against the CISA KEV catalog
  • Weekly Recap

Daily Cybersecurity Flagged 9 Exploited Flaws Before CISA KEV

Do Son September 14, 2026 0
This weekly CVE report covers 10 exploited vulnerabilities added to CISA KEV and 2,316 new CVEs from Aug 31 to Sep 6, 2026. Patch fast.
  • Weekly Recap

Weekly CVE Report: Daily Cybersecurity Beats CISA KEV on Exploited Flaws

Do Son September 7, 2026 0
Weekly CVE report dashboard showing new vulnerabilities and CISA KEV exploited flaws for the week
  • Weekly Recap

Weekly CVE Report: 11 Exploited Flaws Added to KEV

Do Son August 31, 2026 0

Tech News

macOS security prompt warning users about granting Full Disk Access to an autonomous AI agent
  • Technology

Apple Restricts Full Disk Access for macOS AI Agents

Do Son October 4, 2026 0
iPhone 18 AT&T issue hardware replacement and iPhone 18 Pro Max cellular network failure
  • Technology

iPhone 18 AT&T Issue: Navigating the Cellular Crisis

Do Son October 4, 2026 0
David Robinson OpenAI safety whistleblower warns of AI alignment failures and corporate governance collapse
  • Technology

OpenAI AI Safety Whistleblower Warns of Culture Collapse

Do Son October 4, 2026 0
Gemini free tier limits showing the Gemini app restricted to the Gemini Flash-Lite model for free personal accounts
  • Technology

Gemini Free Tier Limits: Flash-Lite Only From Oct 9

Do Son October 4, 2026 0

Vulnerability

Citrix NetScaler CVE-2026-88779 exploited in the wild against NetScaler SAML authentication deployments
  • Vulnerability Report

Citrix NetScaler CVE-2026-88779 Exploited in the Wild to Knock SAML Gateways Offline

Do Son October 4, 2026 0
Apache OpenOffice vulnerability CVE-2026-59265 alongside Apache Directory LDAP API flaw CVE-2026-103877 and Traffic Server CVE-2026-102795
  • Vulnerability Report

Unpatched Apache OpenOffice Vulnerability Leads New Apache Advisories for LDAP API and Traffic Server

Do Son October 3, 2026 0
Exchange Server security updates September 2026 V2 adding CVE-2026-96940 for Exchange SE, Exchange 2019 and Exchange 2016
  • Vulnerability Report

Microsoft Reissues September 2026 Exchange Server Security Updates to Add CVE-2026-96940

Do Son October 3, 2026 0
Loom for AWS authentication bypass CVE-2026-103956 and SageMaker Unified Studio command injection 
  • Vulnerability Report

AWS Fixes Loom for AWS Admin Takeover and SageMaker Unified Studio Code Execution Flaws

Do Son October 2, 2026 0

Cyber Security

China-Aligned TA419 Credential Phishing Hits AI Experts Diagram showing China-aligned TA419 credential phishing and TA419 credential phishing attack stages
  • Cybercriminals

China-Aligned TA419 Credential Phishing Hits AI Experts

October 2, 2026 0
Phishing Abuses RMM Tools for Persistent Network Access CoreRAT malware decoy PDF used in Core Werewolf phishing attack on Russian defense targets
  • Cybercriminals

Phishing Abuses RMM Tools for Persistent Network Access

October 2, 2026 0
Attackers Exploit Citrix NetScaler Zero-Day CVE-2026-88772 to Plant Hidden Web Shells Citrix NetScaler zero-day CVE-2026-88772 exploited to deploy WHIPSHOT web shell and SLAPSHOT tunneler
  • Cybercriminals

Attackers Exploit Citrix NetScaler Zero-Day CVE-2026-88772 to Plant Hidden Web Shells

October 1, 2026 0
Russia’s Star Blizzard Scales Up Phishing With RedFlick to Deliver CosmicPulse Backdoor Star Blizzard RedFlick phishing campaign using scheduled tasks to install the CosmicPulse backdoor
  • Cybercriminals

Russia’s Star Blizzard Scales Up Phishing With RedFlick to Deliver CosmicPulse Backdoor

September 30, 2026 0

Malware Alert

UAT-11587 Targets Asian Governments With Antino Backdoor Diagram showing UAT-11587 Antino backdoor attacks and how the Antino backdoor compromises endpoints
  • Malware

UAT-11587 Targets Asian Governments With Antino Backdoor

October 2, 2026 0
PaperCut Zero-Day Attack Hides AdaptixC2 Implant Inside Fake Microsoft Copilot Siemens PLC cyber threat with AI-generated exploit scripts targeting S7 series controllers in critical infrastructure
  • Malware

PaperCut Zero-Day Attack Hides AdaptixC2 Implant Inside Fake Microsoft Copilot

October 1, 2026 0
Microsoft Details NeedyMantis Malware Used for Long-Term Access in Targeted Intrusions A graphic showing BGP routing hijacking redirecting a server update to a malicious source
  • Malware

Microsoft Details NeedyMantis Malware Used for Long-Term Access in Targeted Intrusions

October 1, 2026 0
New MacSync macOS Infostealer Targets Crypto Wallets Diagram of the new MacSync macOS infostealer showing how the MacSync macOS infostealer infects Apple devices
  • Malware

New MacSync macOS Infostealer Targets Crypto Wallets

September 29, 2026 0

Data Leak

AI Coding Agents Leak 13,000 Internal Screenshots to Public GitHub Repos AI agent screenshot leak in PixelLeak research showing internal images pushed to public GitHub repos
  • Data Leak

AI Coding Agents Leak 13,000 Internal Screenshots to Public GitHub Repos

September 30, 2026 0
Meta Muse Secretly Used Humans for AI Phone Calls Meta Muse AI agent phone calling feature secretly handed off to human contractors
  • Data Leak

Meta Muse Secretly Used Humans for AI Phone Calls

September 24, 2026 0
ShinyHunters Syndicate Alleges Major FBI Network Compromise Bling Libra
  • Data Leak

ShinyHunters Syndicate Alleges Major FBI Network Compromise

September 24, 2026 0
Leaked GitHub App Private Keys Expose Critical Infrastructure Diagram showing leaked GitHub App private keys and how GitHub App private keys compromise repositories
  • Data Leak

Leaked GitHub App Private Keys Expose Critical Infrastructure

September 23, 2026 0
CVE Watchtower User Guide CVE Watchtower User Guide
  • How To

CVE Watchtower User Guide

Do Son October 2, 2026 0
Read More Read more about CVE Watchtower User Guide
Meta Muse Gadgets: Open-Source Hardware for the Muse AI Meta Muse Gadgets open-source project showing a Muse Home Link dongle and maker-built hardware running the Muse AI agent
  • Technology

Meta Muse Gadgets: Open-Source Hardware for the Muse AI

Do Son October 4, 2026 0
Read More Read more about Meta Muse Gadgets: Open-Source Hardware for the Muse AI
Digi DAL OS Vulnerability Lets Unauthenticated Attackers Run Root Commands Digi DAL OS vulnerability CVE-2026-75937 command injection in Digi Accelerated Linux web administration on IX, EX and TX routers
  • Vulnerability Report

Digi DAL OS Vulnerability Lets Unauthenticated Attackers Run Root Commands

Do Son October 2, 2026 0
Read More Read more about Digi DAL OS Vulnerability Lets Unauthenticated Attackers Run Root Commands
Chrome Security Update Fixes Critical WebGL Flaw and 10 Other Bugs Chrome security update for Chrome 154 fixing CVE-2026-103628 WebGL sandbox escape and CVE-2026-103631 WebRTC flaw
  • Vulnerability Report

Chrome Security Update Fixes Critical WebGL Flaw and 10 Other Bugs

Do Son October 2, 2026 0
Read More Read more about Chrome Security Update Fixes Critical WebGL Flaw and 10 Other Bugs
GitLab Patches Critical AI Gateway Flaw That Lets Duo Users Run Commands GitLab AI Gateway vulnerability CVE-2026-90970 lets Duo Agent Platform users escape the prompt template sandbox
  • Vulnerability Report

GitLab Patches Critical AI Gateway Flaw That Lets Duo Users Run Commands

Do Son October 2, 2026 0
Read More Read more about GitLab Patches Critical AI Gateway Flaw That Lets Duo Users Run Commands
Patched NetScaler Appliances Keep Rebooting as Citrix Flags SAML Authentication Issue NetScaler SAML authentication issue causing patched NetScaler appliances to reboot after CVE-2026-88771 and CVE-2026-88772 exploitation
  • Vulnerability Report

Patched NetScaler Appliances Keep Rebooting as Citrix Flags SAML Authentication Issue

Do Son October 2, 2026 0
Read More Read more about Patched NetScaler Appliances Keep Rebooting as Citrix Flags SAML Authentication Issue
Seven TP-Link Vulnerabilities Hit Tapo Cameras, Archer and Deco Routers TP-Link vulnerabilities and Tapo camera vulnerabilities CVE-2026-102369 in Tapo C200, Archer AX90 and Deco M9 Plus
  • Vulnerability Report

Seven TP-Link Vulnerabilities Hit Tapo Cameras, Archer and Deco Routers

Do Son October 2, 2026 0
Read More Read more about Seven TP-Link Vulnerabilities Hit Tapo Cameras, Archer and Deco Routers
Moxa MGate Vulnerabilities Put Industrial Protocol Gateways at Risk Moxa MGate vulnerabilities CVE-2026-86325 and CVE-2026-86326 in MGate protocol gateway firmware
  • Vulnerability Report

Moxa MGate Vulnerabilities Put Industrial Protocol Gateways at Risk

Do Son October 2, 2026 0
Read More Read more about Moxa MGate Vulnerabilities Put Industrial Protocol Gateways at Risk
Stirling PDF RCE CVE-2026-85714: Details and PoC Publicly Disclosed Stirling PDF RCE CVE-2026-85714 proof-of-concept publicly disclosed
  • Vulnerability Report

Stirling PDF RCE CVE-2026-85714: Details and PoC Publicly Disclosed

Do Son October 2, 2026 0
Read More Read more about Stirling PDF RCE CVE-2026-85714: Details and PoC Publicly Disclosed
OpenAI Fires Safety Researchers Amid Unprompted AI Hacking Incidents Conceptual illustration of an AI breaking safety protocols while a whistleblower is silenced
  • Technology

OpenAI Fires Safety Researchers Amid Unprompted AI Hacking Incidents

Do Son October 2, 2026 0
Read More Read more about OpenAI Fires Safety Researchers Amid Unprompted AI Hacking Incidents
SOC as a Service: A Practical Guide to Outsourcing Your Security Operations Center AISelect_20261002_114950_Docs
  • Technique

SOC as a Service: A Practical Guide to Outsourcing Your Security Operations Center

Do Son October 2, 2026 0
Read More Read more about SOC as a Service: A Practical Guide to Outsourcing Your Security Operations Center
Dell System Update Flaw CVE-2026-86360 Could Allow Root Code Execution Dell System Update vulnerability CVE-2026-86360 path traversal root code execution
  • Vulnerability Report

Dell System Update Flaw CVE-2026-86360 Could Allow Root Code Execution

Do Son October 2, 2026 0
Read More Read more about Dell System Update Flaw CVE-2026-86360 Could Allow Root Code Execution
Zammad Zero-Day Chain CVE-2026-102489 Exploited in the Wild in AI-Driven DIVD Breach Zammad zero-day CVE-2026-102489 CVE-2026-102490 exploited in DIVD breach
  • Vulnerability Report

Zammad Zero-Day Chain CVE-2026-102489 Exploited in the Wild in AI-Driven DIVD Breach

Do Son October 2, 2026 0
Read More Read more about Zammad Zero-Day Chain CVE-2026-102489 Exploited in the Wild in AI-Driven DIVD Breach
Critical Capacitor Flaw CVE-2026-103922 Hits Framework With 5.5M Weekly Downloads Capacitor vulnerability CVE-2026-103922 affects npm package with 5.5 million weekly downloads
  • Vulnerability Report

Critical Capacitor Flaw CVE-2026-103922 Hits Framework With 5.5M Weekly Downloads

Do Son October 2, 2026 0
Read More Read more about Critical Capacitor Flaw CVE-2026-103922 Hits Framework With 5.5M Weekly Downloads
Sharp Printer Flaw CVE-2024-58388 Exploited in the Wild, PoC Public Sharp printer vulnerability CVE-2024-58388 exploited in the wild, PoC public
  • Vulnerability Report

Sharp Printer Flaw CVE-2024-58388 Exploited in the Wild, PoC Public

Do Son October 2, 2026 0
Read More Read more about Sharp Printer Flaw CVE-2024-58388 Exploited in the Wild, PoC Public
Apache HTTP Server 2.4.69 Fixes 20 Flaws, Including mod_vhost_alias Stack Overflow Apache HTTP Server 2.4.69 fixes CVE-2026-63292 mod_vhost_alias stack overflow
  • Vulnerability Report

Apache HTTP Server 2.4.69 Fixes 20 Flaws, Including mod_vhost_alias Stack Overflow

Do Son October 2, 2026 0
Read More Read more about Apache HTTP Server 2.4.69 Fixes 20 Flaws, Including mod_vhost_alias Stack Overflow
Critical Foreman RCE Flaw Hits Red Hat Satellite, Plus 389-ds LDAP Bug Foreman RCE flaw CVE-2026-96658 in Red Hat Satellite
  • Vulnerability Report

Critical Foreman RCE Flaw Hits Red Hat Satellite, Plus 389-ds LDAP Bug

Do Son October 2, 2026 0
Read More Read more about Critical Foreman RCE Flaw Hits Red Hat Satellite, Plus 389-ds LDAP Bug
cPanel Security Vulnerabilities Expose WHM Web Servers Critical cPanel security vulnerabilities exposing WHM web servers
  • Vulnerability Report

cPanel Security Vulnerabilities Expose WHM Web Servers

Do Son October 2, 2026 0
Read More Read more about cPanel Security Vulnerabilities Expose WHM Web Servers
OpenBao Security Vulnerabilities Enable Code Execution Diagram of critical OpenBao security vulnerabilities and secret storage fixes
  • Vulnerability Report

OpenBao Security Vulnerabilities Enable Code Execution

Do Son October 2, 2026 0
Read More Read more about OpenBao Security Vulnerabilities Enable Code Execution
CISA Warns of Monta EV Charging Vulnerabilities Diagram showing critical Monta EV charging vulnerabilities and security fixes
  • Vulnerability Report

CISA Warns of Monta EV Charging Vulnerabilities

Do Son October 2, 2026 0
Read More Read more about CISA Warns of Monta EV Charging Vulnerabilities
Dell Patches Two CVSS 10 Flaws in Container Storage Modules Dell Container Storage Modules vulnerabilities CVE-2026-63688 CVE-2026-63692 CVSS 10
  • Vulnerability Report

Dell Patches Two CVSS 10 Flaws in Container Storage Modules

Do Son October 2, 2026 0
Read More Read more about Dell Patches Two CVSS 10 Flaws in Container Storage Modules
FortiMail Path Traversal Flaw CVE-2026-104286 Exploited in the Wild FortiMail vulnerability CVE-2026-104286 path traversal exploited in the wild
  • Vulnerability Report

FortiMail Path Traversal Flaw CVE-2026-104286 Exploited in the Wild

Do Son October 1, 2026 0
Read More Read more about FortiMail Path Traversal Flaw CVE-2026-104286 Exploited in the Wild
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intel📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-104286CVSS 9.8
    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
    CISA KEV📅 Added to KEV: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-103355CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements...
    📅 Updated: Oct 4, 2026
  • CVE-2026-105135CVSS 10.0
    A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file...
    📅 Updated: Oct 4, 2026
  • CVE-2026-105134CVSS 10.0
    A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the...
    📅 Updated: Oct 4, 2026
  • CVE-2026-97637CVSS 9.8
    The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in...
    📅 Updated: Oct 3, 2026
  • CVE-2026-92084CVSS 9.1
    The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to...
    📅 Updated: Oct 3, 2026
  • CVE-2026-87115CVSS 9.1
    The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file...
    📅 Updated: Oct 3, 2026
  • CVE-2026-14378CVSS 9.8
    The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all...
    📅 Updated: Oct 3, 2026
  • CVE-2026-19660CVSS 9.8
    The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,...
    📅 Updated: Oct 3, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.