Skip to content
July 31, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button

Weekly Recap

CISA flagged 6 actively exploited CVEs this week, from a SharePoint RCE to a Check Point auth bypass. See the full CISA KEV list and patch fast.
  • Weekly Recap

Weekly Threat Intelligence Briefing: Late July 2026

Do Son July 27, 2026 0
actively exploited vulnerabilities
  • Weekly Recap

Mid-July 2026: Weekly Threat Intelligence Report

Do Son July 20, 2026 0
weekly CVE report actively exploited vulnerabilities
  • Weekly Recap

Weekly CVE Report: 1,571 New Flaws and 6 Actively Exploited Bugs (July 6–12, 2026)

Do Son July 13, 2026 0
Weekly Threat Intelligence Active Vulnerability Report
  • Weekly Recap

Weekly Threat Intelligence: The July 2026 Breaches

Do Son July 6, 2026 0
Weekly CVE report June 2026 1909 new vulnerabilities CISA KEV CVE-2026-20230 exploited
  • Weekly Recap

Weekly CVE Report Logs 1,909 New Vulnerabilities and 6 Exploited Flaws

Do Son June 29, 2026 0

Tech News

Robot vacuum cleaner navigating a living room floor
  • Technology

FCC Ban Sweeps Up Foreign-Made Robot Vacuums

Do Son July 31, 2026 0
Google Earth displaying an AI generated historical rendering of Pompeii
  • Technology

Google Earth Nano Banana 2: A Dangerous Blend of Fact and Fiction?

Do Son July 31, 2026 0
Claude cybersecurity evaluations incident where an AI model reached real systems, disclosed by Anthropic
  • Technology

Claude Models Accessed Real Systems During Cybersecurity Evaluations

Do Son July 31, 2026 0
Sign in with ChatGPT single sign-on authentication feature prompt
  • Technology

OpenAI Tests ‘Sign in with ChatGPT’ Single Sign-On

Do Son July 30, 2026 0

Vulnerability

Arris BGW210-700 vulnerability CVE-2026-16771 authentication bypass in AT&T gateway
  • Vulnerability Report

Arris BGW210-700 Authentication Bypass Leaks AT&T Gateway WiFi Passwords (CVE-2026-16771)

Do Son July 31, 2026 0
OpenAM vulnerabilities CVE-2026-62379 unauthenticated remote code execution in the access management server authservice endpoint
  • Vulnerability Report

OpenAM CVE-2026-62379 (CVSS 9.8) Enables Unauthenticated Remote Code Execution, CVE-2026-62261 Scores CVSS 9.9

Do Son July 31, 2026 0
Erlang/OTP vulnerabilities including a TLS certificate bypass and BEAM VM denial-of-service crash flaws
  • Vulnerability Report

Erlang/OTP Patches Five Flaws, Including a TLS Certificate Bypass

Do Son July 31, 2026 0
CodeIgniter4 RCE vulnerability enabling remote code execution via malicious file upload
  • Vulnerability Report

CVE-2026-63223: CodeIgniter4 RCE Vulnerability Rated CVSS 9.8

Do Son July 31, 2026 0

Cyber Security

GoGRPC Backdoor Spreads Through Microsoft Teams Vishing Spirals ransomware double extortion attack chain from IIS web shell to network encryption
  • Cybercriminals

GoGRPC Backdoor Spreads Through Microsoft Teams Vishing

July 31, 2026 0
SilverFox ValleyRAT Campaign Adds Three BYOVD Drivers to Kill Security Tools SilverFox ValleyRAT infection chain using BYOVD vulnerable drivers and DLL sideloading
  • Cybercriminals

SilverFox ValleyRAT Campaign Adds Three BYOVD Drivers to Kill Security Tools

July 31, 2026 0
Attackers Poison Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts Hotel Wi-Fi DNS poisoning attack chain leading to Microsoft 365 account compromise for traveling employees
  • Cybercriminals

Attackers Poison Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts

July 30, 2026 0
BlueNoroff Phishing Kit Turns Fake Zoom and Teams Calls Into a Crypto Wallet Theft Machine BlueNoroff phishing kit fake Zoom meeting page used in a DPRK ClickFix attack targeting crypto wallets
  • Cybercriminals

BlueNoroff Phishing Kit Turns Fake Zoom and Teams Calls Into a Crypto Wallet Theft Machine

July 30, 2026 0

Malware Alert

Copybara Android RAT Spreads Through N26 Vishing Scam in Italy Copybara Android RAT delivered through N26 vishing and Fake Control 1.0 phishing panel
  • Malware

Copybara Android RAT Spreads Through N26 Vishing Scam in Italy

July 30, 2026 0
TrickBot Variant Hides C2 Traffic Inside Malformed DNS Queries FSB Center 16 targeting vulnerable routers across critical infrastructure via weak SNMP
  • Malware

TrickBot Variant Hides C2 Traffic Inside Malformed DNS Queries

July 29, 2026 0
Lampion Malware Campaign Targets Portugal With Fake Payment Receipts malware-code
  • Malware

Lampion Malware Campaign Targets Portugal With Fake Payment Receipts

July 29, 2026 0
Chaos Ransomware Uses msaRAT to Hide C2 Traffic Inside Chrome msaRAT malware used by the Chaos ransomware group to route C2 traffic through a headless Chrome browser session
  • Malware

Chaos Ransomware Uses msaRAT to Hide C2 Traffic Inside Chrome

July 29, 2026 0

Data Leak

The Rise of AI Driven Cyberattacks in 2026 AI driven cyberattacks and data breach costs illustration
  • Data Leak

The Rise of AI Driven Cyberattacks in 2026

July 31, 2026 0
Claude AI Shared Chats Surfaced in Google Over a Config Error Claude AI shared conversation links indexed in Google search due to a robots.txt and X-Robots-Tag misconfiguration exposing private chat content
  • Data Leak

Claude AI Shared Chats Surfaced in Google Over a Config Error

July 27, 2026 0
Hugging Face Discloses Production Breach Driven by an Autonomous AI Agent Hugging Face breach driven by an autonomous AI agent attack exposing internal datasets and credentials
  • Data Leak

Hugging Face Discloses Production Breach Driven by an Autonomous AI Agent

July 18, 2026 0
Grok Build Repository Upload Scandal: Researcher Confirms Privacy Mode Cannot Stop It Grok Build repository upload controversy, SpaceXAI privacy mode response
  • Data Leak

Grok Build Repository Upload Scandal: Researcher Confirms Privacy Mode Cannot Stop It

July 14, 2026 0
Public PoC Exploits GitLab RCE via Two Oj Memory Corruption Bugs GitLab RCE proof-of-concept exploiting two Oj memory corruption bugs in the notebook diff renderer
  • Vulnerability Report

Public PoC Exploits GitLab RCE via Two Oj Memory Corruption Bugs

Do Son July 31, 2026 0
Read More Read more about Public PoC Exploits GitLab RCE via Two Oj Memory Corruption Bugs
SolarWinds Web Help Desk SAML Bypass CVE-2026-28323 Scores CVSS 9.8 SolarWinds Web Help Desk SAML authentication bypass CVE-2026-28323
  • Vulnerability Report

SolarWinds Web Help Desk SAML Bypass CVE-2026-28323 Scores CVSS 9.8

Do Son July 31, 2026 0
Read More Read more about SolarWinds Web Help Desk SAML Bypass CVE-2026-28323 Scores CVSS 9.8
Adobe Campaign Classic CVE-2026-48449 Enables Code Execution at CVSS 10.0 Adobe Campaign Classic CVE-2026-48449 arbitrary code execution vulnerability
  • Vulnerability Report

Adobe Campaign Classic CVE-2026-48449 Enables Code Execution at CVSS 10.0

Do Son July 31, 2026 0
Read More Read more about Adobe Campaign Classic CVE-2026-48449 Enables Code Execution at CVSS 10.0
MicroLogix 1400 Attacks Lock Operators Out of Water Utility PLCs MicroLogix 1400 attacks on internet-exposed PLCs at water utilities
  • Vulnerability Report

MicroLogix 1400 Attacks Lock Operators Out of Water Utility PLCs

Do Son July 31, 2026 0
Read More Read more about MicroLogix 1400 Attacks Lock Operators Out of Water Utility PLCs
PHP SQL Injection Flaw CVE-2026-17543 Patched in Latest Release PHP SQL injection vulnerability CVE-2026-17543 in the pgsql extension patched in PHP 8.5.9
  • Vulnerability Report

PHP SQL Injection Flaw CVE-2026-17543 Patched in Latest Release

Do Son July 31, 2026 0
Read More Read more about PHP SQL Injection Flaw CVE-2026-17543 Patched in Latest Release
OpenRemote CVE-2026-66013 (CVSS 9.3): Unauthenticated Asset Takeover Details Disclosed OpenRemote vulnerability CVE-2026-66013 unauthenticated asset takeover via console registration API in IoT platform
  • Vulnerability Report

OpenRemote CVE-2026-66013 (CVSS 9.3): Unauthenticated Asset Takeover Details Disclosed

Do Son July 31, 2026 0
Read More Read more about OpenRemote CVE-2026-66013 (CVSS 9.3): Unauthenticated Asset Takeover Details Disclosed
IBM WebSphere Vulnerabilities (CVSS 9.8) Enable RCE, Privilege Escalation, and SSRF IBM WebSphere vulnerabilities including CVE-2026-14512 RCE and CVE-2026-14529 SSRF patched by IBM
  • Vulnerability Report

IBM WebSphere Vulnerabilities (CVSS 9.8) Enable RCE, Privilege Escalation, and SSRF

Do Son July 31, 2026 0
Read More Read more about IBM WebSphere Vulnerabilities (CVSS 9.8) Enable RCE, Privilege Escalation, and SSRF
OpenMatter Network Calls on Enterprise Leaders to Rethink AI Security Before the Next Rogue AI Crisis Untitled_design_1_1785345577GFlH2l3KbJ
  • Press Release

OpenMatter Network Calls on Enterprise Leaders to Rethink AI Security Before the Next Rogue AI Crisis

cybernewswire July 30, 2026 0
Read More Read more about OpenMatter Network Calls on Enterprise Leaders to Rethink AI Security Before the Next Rogue AI Crisis
MongoDB Patches 27 Vulnerabilities, Including Memory Corruption, RBAC Bypass, and a Compass Command Injection MongoDB vulnerabilities dashboard showing memory corruption and denial of service flaws across MongoDB Server and Compass
  • Vulnerability Report

MongoDB Patches 27 Vulnerabilities, Including Memory Corruption, RBAC Bypass, and a Compass Command Injection

Do Son July 30, 2026 0
Read More Read more about MongoDB Patches 27 Vulnerabilities, Including Memory Corruption, RBAC Bypass, and a Compass Command Injection
CVE-2026-42530: NGINX HTTP/3 RCE Proof-of-Concept Publicly Disclosed CVE-2026-42530 NGINX HTTP/3 RCE proof-of-concept exploiting a QPACK use-after-free
  • Vulnerability Report

CVE-2026-42530: NGINX HTTP/3 RCE Proof-of-Concept Publicly Disclosed

Do Son July 30, 2026 0
Read More Read more about CVE-2026-42530: NGINX HTTP/3 RCE Proof-of-Concept Publicly Disclosed
CVE-2026-66373: Redis RCE Proof-of-Concept Publicly Disclosed CVE-2026-66373 Redis RCE double-free proof-of-concept via the RESTORE command
  • Vulnerability Report

CVE-2026-66373: Redis RCE Proof-of-Concept Publicly Disclosed

Do Son July 30, 2026 0
Read More Read more about CVE-2026-66373: Redis RCE Proof-of-Concept Publicly Disclosed
Google Pixel 11 Pro Teaser Reveals Mysterious Spinning Light Google Pixel 11 Pro mysterious spinning colored light indicator next to camera
  • Android

Google Pixel 11 Pro Teaser Reveals Mysterious Spinning Light

Do Son July 30, 2026 0
Read More Read more about Google Pixel 11 Pro Teaser Reveals Mysterious Spinning Light
GitLab Patch Release Fixes 13 Security Vulnerabilities GitLab patch release 19.2.1 fixing 13 vulnerabilities including CVE-2026-6267 data exposure flaw
  • Vulnerability Report

GitLab Patch Release Fixes 13 Security Vulnerabilities

Do Son July 30, 2026 0
Read More Read more about GitLab Patch Release Fixes 13 Security Vulnerabilities
Rails Active Storage Flaw CVE-2026-66066 Enables Remote Code Execution Rails Active Storage flaw CVE-2026-66066 arbitrary file read and remote code execution via libvips
  • Vulnerability Report

Rails Active Storage Flaw CVE-2026-66066 Enables Remote Code Execution

Do Son July 30, 2026 0
Read More Read more about Rails Active Storage Flaw CVE-2026-66066 Enables Remote Code Execution
Chrome 151 Update Patches 370 Security Vulnerabilities Chrome security update patching 370 vulnerabilities including critical use-after-free CVE-2026-17650
  • Vulnerability Report

Chrome 151 Update Patches 370 Security Vulnerabilities

Do Son July 30, 2026 0
Read More Read more about Chrome 151 Update Patches 370 Security Vulnerabilities
Gemini macOS App Upgrade: Wake AI with the Fn Key Gemini macOS app screen aware reasoning and fn key voice commands
  • Technology

Gemini macOS App Upgrade: Wake AI with the Fn Key

Do Son July 30, 2026 0
Read More Read more about Gemini macOS App Upgrade: Wake AI with the Fn Key
Cisco FMC Flaw CVE-2026-20316 Exploited in the Wild Cisco FMC vulnerability CVE-2026-20316 static credentials exploited in the wild
  • Vulnerability Report

Cisco FMC Flaw CVE-2026-20316 Exploited in the Wild

Do Son July 29, 2026 0
Read More Read more about Cisco FMC Flaw CVE-2026-20316 Exploited in the Wild
Node.js Patches 11 Vulnerabilities in July 2026 Security Release Node.js vulnerabilities patched in July 2026 including HTTP/2 use-after-free CVE-2026-56848
  • Vulnerability Report

Node.js Patches 11 Vulnerabilities in July 2026 Security Release

Do Son July 29, 2026 0
Read More Read more about Node.js Patches 11 Vulnerabilities in July 2026 Security Release
C-CURE 9000 Vulnerability CVE-2026-21655 Enables Remote Code Execution, CVE-2026-21653 Scores CVSS 9.6 C-CURE 9000 vulnerability CVE-2026-21655 remote code execution and CVE-2026-21653 CVSS 9.6 SSRF flaw in Johnson Controls victor application server
  • Vulnerability Report

C-CURE 9000 Vulnerability CVE-2026-21655 Enables Remote Code Execution, CVE-2026-21653 Scores CVSS 9.6

Do Son July 29, 2026 0
Read More Read more about C-CURE 9000 Vulnerability CVE-2026-21655 Enables Remote Code Execution, CVE-2026-21653 Scores CVSS 9.6
OpenDJ Vulnerabilities: Authorization Bypass (CVSS 9.6) and Unauthenticated SSRF (CVSS 9.4) OpenDJ vulnerabilities authorization bypass and unauthenticated SSRF in the DSMLv2 gateway of the LDAP directory server
  • Vulnerability Report

OpenDJ Vulnerabilities: Authorization Bypass (CVSS 9.6) and Unauthenticated SSRF (CVSS 9.4)

Do Son July 29, 2026 0
Read More Read more about OpenDJ Vulnerabilities: Authorization Bypass (CVSS 9.6) and Unauthenticated SSRF (CVSS 9.4)
Certighost CVE-2026-54121 Active Directory Certificate Services Elevation of Privilege Details and PoC Exploit Code Go Public Certighost AD CS vulnerability CVE-2026-54121 Active Directory Certificate Services elevation of privilege chase flow diagram
  • Vulnerability Report

Certighost CVE-2026-54121 Active Directory Certificate Services Elevation of Privilege Details and PoC Exploit Code Go Public

Do Son July 29, 2026 0
Read More Read more about Certighost CVE-2026-54121 Active Directory Certificate Services Elevation of Privilege Details and PoC Exploit Code Go Public
CVE-2026-50502: Public PoC Exploit Details Windows Event Log Remote Code Execution CVE-2026-50502 Windows Event Log RCE proof-of-concept exploit dropping an HTA file into a victim Startup folder over SMB
  • Vulnerability Report

CVE-2026-50502: Public PoC Exploit Details Windows Event Log Remote Code Execution

Do Son July 29, 2026 0
Read More Read more about CVE-2026-50502: Public PoC Exploit Details Windows Event Log Remote Code Execution
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-18072CVSS 9.8
    The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to...
    Admin intel📅 Updated: Jul 29, 2026
  • CVE-2026-20316CVSS 5.3
    A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated,...
    CISA KEV📅 Added to KEV: Jul 29, 2026
  • CVE-2026-16812CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access...
    Admin intelCISA KEV📅 Added to KEV: Jul 27, 2026📅 Updated: Jul 27, 2026
  • CVE-2025-68686CVSS 5.9
    An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1,...
    CISA KEV📅 Added to KEV: Jul 27, 2026
  • CVE-2026-16723CVSS 9.0
    A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson\'s stock...
    Admin intel📅 Updated: Jul 25, 2026
  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-54725CVSS 9.6
    ## Summary The vault-secrets-webhook reads the `vault.security.banzaicloud.io/vault-addr` annotation from any ConfigMap or...
  • CVE-2026-52855CVSS 9.9
    Wings is the server control plane for Pterodactyl, a free, open-source game...
  • CVE-2026-17566CVSS 9.9
    pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line...
  • CVE-2026-17351CVSS 9.0
    The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query...
  • CVE-2026-17349CVSS 9.6
    /misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when...
  • CVE-2026-17561CVSS 9.8
    Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software,...
  • CVE-2026-14919CVSS 9.8
    The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting...
  • CVE-2026-14483CVSS 9.8
    The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress...
  • CVE-2026-63223CVSS 9.8
    CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image...
  • CVE-2026-63221CVSS 9.4
    CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.