Skip to content
July 21, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button

Weekly Recap

actively exploited vulnerabilities
  • Weekly Recap

Mid-July 2026: Weekly Threat Intelligence Report

Do Son July 20, 2026 0
weekly CVE report actively exploited vulnerabilities
  • Weekly Recap

Weekly CVE Report: 1,571 New Flaws and 6 Actively Exploited Bugs (July 6–12, 2026)

Do Son July 13, 2026 0
Weekly Threat Intelligence Active Vulnerability Report
  • Weekly Recap

Weekly Threat Intelligence: The July 2026 Breaches

Do Son July 6, 2026 0
Weekly CVE report June 2026 1909 new vulnerabilities CISA KEV CVE-2026-20230 exploited
  • Weekly Recap

Weekly CVE Report Logs 1,909 New Vulnerabilities and 6 Exploited Flaws

Do Son June 29, 2026 0
Weekly CVE report dashboard showing 2,060 new vulnerabilities and 4 actively exploited CVEs in CISA KEV
  • Weekly Recap

2,060 New CVEs and 4 Actively Exploited Flaws (June 15-21, 2026)

Do Son June 22, 2026 0

Tech News

UEFI CA 2023 update migration issues, Secure Boot certificate problems, Microsoft and OEM hardware compatibility
  • Technology

Microsoft UEFI CA 2023 Certificate Update Causes Widespread Issues

Do Son July 21, 2026 0
Claude Team plan dashboard highlighting the new two-seat minimum for small teams
  • Technology

Claude Team Plan Now Starts at Just 2 Seats

Do Son July 21, 2026 0
GOLD EAGLE initiative dashboard for U.S. cybersecurity vulnerability coordination
  • Technology

White House Launches GOLD EAGLE Initiative to Speed Vulnerability Patching

Do Son July 21, 2026 0
Codex context window change: OpenAI lowers the limit to 272K and forbids rm -rf $HOME in the system prompt after deletions
  • Technology

Codex Cuts Its Context Window to 272K and Forbids rm -rf $HOME After Home-Directory Deletions

Do Son July 20, 2026 0

Vulnerability

SolarWinds Serv-U vulnerabilities enabling privilege escalation and remote code execution (CVE-2026-28307/28308/28321)
  • Vulnerability Report

SolarWinds Patches Three Critical Serv-U Vulnerabilities Enabling RCE

Do Son July 21, 2026 0
CVE-2026-8933 is a snap-confine privilege escalation flaw. It gives any user root on default Ubuntu Desktop 26.04, 25.10, and 24.04. Update snapd now. #snapconfine #CVE20268933 #Ubuntu #PrivilegeEscalation #LPE #Linux #Qualys
  • Vulnerability Report

snap-confine Flaw CVE-2026-8933 Lets Any User Get Root on Ubuntu

Do Son July 21, 2026 0
CISA KEV catalog adding four known exploited vulnerabilities including WordPress and Langflow RCE
  • Vulnerability Report

CISA Adds Four Exploited Vulnerabilities to Its KEV Catalog

Do Son July 21, 2026 0
ASUS security advisories router firmware vulnerability CVE-2026-13385 command execution
  • Vulnerability Report

ASUS Patches Router and PC Software Flaws, Including a CVSS 9.5 Command Execution Bug

Do Son July 21, 2026 0

Cyber Security

Nextcloud Website Suffers Cyberattack and Phishing Redirect Nextcloud website hacked showing unauthorized Cloudbox phishing redirect and wp2shell vulnerability.
  • Cybercriminals

Nextcloud Website Suffers Cyberattack and Phishing Redirect

July 21, 2026 0
Threat Actor Rebuilt a Live Botnet in Six Minutes Using an AI Coding Agent AccountDumpling Phishing Google AppSheet Abuse AI-Generated Malware PureRAT Campaign RondoDoX Botnet, Next.js React2Shell EchoGather, Paper Werewolf Salt Typhoon, Telecom Espionage BreachForums, Conor Fitzpatrick Ransomware Negotiation, DOJ Investigation MirrorFace group - Earth Kasha Emperor Dragonfly
  • Cybercriminals

Threat Actor Rebuilt a Live Botnet in Six Minutes Using an AI Coding Agent

July 21, 2026 0
Qilin Ransomware Deployed via Palo Alto GlobalProtect Flaw CVE-2026-0257 Qilin ransomware attack chain starting with a Palo Alto GlobalProtect CVE-2026-0257 authentication bypass
  • Cybercriminals

Qilin Ransomware Deployed via Palo Alto GlobalProtect Flaw CVE-2026-0257

July 21, 2026 0
United States Seizes More Than 1,000 Domains Streaming World Cup 2026 Matches Website Seizure Graphic
  • Cybercriminals

United States Seizes More Than 1,000 Domains Streaming World Cup 2026 Matches

July 20, 2026 0

Malware Alert

TELEPUZ Malware Spreads Through ClickFix and VIDAR Attacks TELEPUZ malware infection chain from a ClickFix attack through VIDAR to modular payload delivery
  • Malware

TELEPUZ Malware Spreads Through ClickFix and VIDAR Attacks

July 21, 2026 0
TuxBot v3 Evolution — an IoT Botnet Built With LLM Help TuxBot v3 Evolution IoT botnet C2 panel and cross-compilation build screen
  • Malware

TuxBot v3 Evolution — an IoT Botnet Built With LLM Help

July 21, 2026 0
ClickLock Stealer Locks macOS Screens Until Victims Hand Over Their Password ClickLock Stealer macOS malware fake Cloudflare ClickFix Terminal prompt stealing passwords
  • Malware

ClickLock Stealer Locks macOS Screens Until Victims Hand Over Their Password

July 21, 2026 0
LG Monitors Auto-Install Adware Through Windows Device Metadata LG monitor adware pop-up promoting McAfee on a Windows desktop via device metadata
  • Malware

LG Monitors Auto-Install Adware Through Windows Device Metadata

July 21, 2026 0

Data Leak

Hugging Face Discloses Production Breach Driven by an Autonomous AI Agent Hugging Face breach driven by an autonomous AI agent attack exposing internal datasets and credentials
  • Data Leak

Hugging Face Discloses Production Breach Driven by an Autonomous AI Agent

July 18, 2026 0
Grok Build Repository Upload Scandal: Researcher Confirms Privacy Mode Cannot Stop It Grok Build repository upload controversy, SpaceXAI privacy mode response
  • Data Leak

Grok Build Repository Upload Scandal: Researcher Confirms Privacy Mode Cannot Stop It

July 14, 2026 0
The Grok Build Privacy Controversy: Unauthorized Repository Uploads Grok Build privacy settings interface showing how to disable automated repository data uploads
  • Data Leak

The Grok Build Privacy Controversy: Unauthorized Repository Uploads

July 14, 2026 0
KDDI Data Breach: Millions of Emails and Passwords Stolen KDDI data breach illustration, KDDI email leak security concept
  • Data Leak

KDDI Data Breach: Millions of Emails and Passwords Stolen

July 9, 2026 0
Public PoC Released for CVE-2026-42980 Windows Privilege Escalation Flaw CVE-2026-42980 Windows privilege escalation flaw in kernel WMI granting SYSTEM access
  • Vulnerability Report

Public PoC Released for CVE-2026-42980 Windows Privilege Escalation Flaw

Do Son July 21, 2026 0
Read More Read more about Public PoC Released for CVE-2026-42980 Windows Privilege Escalation Flaw
Three SQL Injection Flaws Patched in Apache Fineract Core Banking Platform Apache Fineract SQL injection vulnerability affecting Office, Client, and report APIs
  • Vulnerability Report

Three SQL Injection Flaws Patched in Apache Fineract Core Banking Platform

Do Son July 21, 2026 0
Read More Read more about Three SQL Injection Flaws Patched in Apache Fineract Core Banking Platform
Zimbra 10.1.20 Patches an SNMP Command Injection Flaw and Multiple XSS Bugs Zimbra 10.1.20 security update patching Zimbra vulnerabilities including SNMP command injection and XSS
  • Vulnerability Report

Zimbra 10.1.20 Patches an SNMP Command Injection Flaw and Multiple XSS Bugs

Do Son July 21, 2026 0
Read More Read more about Zimbra 10.1.20 Patches an SNMP Command Injection Flaw and Multiple XSS Bugs
CVE-2026-50522 SharePoint RCE Flaw Exploited in the Wild With Public PoC Exploit CVE-2026-50522 SharePoint RCE vulnerability exploited in the wild with public PoC exploit
  • Vulnerability Report

CVE-2026-50522 SharePoint RCE Flaw Exploited in the Wild With Public PoC Exploit

Do Son July 21, 2026 0
Read More Read more about CVE-2026-50522 SharePoint RCE Flaw Exploited in the Wild With Public PoC Exploit
CVE-2026-49488: Arbitrary File Read Flaw in Apache OpenMeetings Exposes Server Credentials Apache OpenMeetings vulnerability CVE-2026-49488 arbitrary file read path traversal flaw
  • Vulnerability Report

CVE-2026-49488: Arbitrary File Read Flaw in Apache OpenMeetings Exposes Server Credentials

Do Son July 21, 2026 0
Read More Read more about CVE-2026-49488: Arbitrary File Read Flaw in Apache OpenMeetings Exposes Server Credentials
Project CAV3RN Hides Its C2 in Outlook Calendar Events to Spy on Israel Project CAV3RN cyberespionage framework using Outlook calendar C2 and Microsoft Graph
  • Cyber Security

Project CAV3RN Hides Its C2 in Outlook Calendar Events to Spy on Israel

Do Son July 21, 2026 0
Read More Read more about Project CAV3RN Hides Its C2 in Outlook Calendar Events to Spy on Israel
OVH Patches CVE-2026-53359 KVM Flaw Across a Million VMs OVH data center engineers patching CVE-2026-53359 KVM vulnerability across thousands of hypervisor hosts
  • Vulnerability Report

OVH Patches CVE-2026-53359 KVM Flaw Across a Million VMs

Do Son July 21, 2026 0
Read More Read more about OVH Patches CVE-2026-53359 KVM Flaw Across a Million VMs
Linux Kernel Publishes 440 CVE Advisories in 24 Hours as AI Accelerates Bug Hunting 440 Linux kernel CVEs published in 24 hours amid AI-driven vulnerability discovery
  • Linux

Linux Kernel Publishes 440 CVE Advisories in 24 Hours as AI Accelerates Bug Hunting

Do Son July 21, 2026 0
Read More Read more about Linux Kernel Publishes 440 CVE Advisories in 24 Hours as AI Accelerates Bug Hunting
wp2shell: WordPress Core RCE Exploited in the Wild as Public PoC Code Circulates wp2shell exploit chain achieving WordPress Core RCE via CVE-2026-63030 and CVE-2026-60137 batch API abuse
  • Vulnerability Report

wp2shell: WordPress Core RCE Exploited in the Wild as Public PoC Code Circulates

Do Son July 21, 2026 0
Read More Read more about wp2shell: WordPress Core RCE Exploited in the Wild as Public PoC Code Circulates
Why Smart Logistics Needs Better Technology  tech
  • Technique

Why Smart Logistics Needs Better Technology 

Do Son July 21, 2026 0
Read More Read more about Why Smart Logistics Needs Better Technology 
CVE-2026-58443: Gitea Flaw (CVSS 9.6) Details and PoC Exploit Code Publicly Disclosed Gitea vulnerability CVE-2026-58443 public-only token writing to private repository
  • Vulnerability Report

CVE-2026-58443: Gitea Flaw (CVSS 9.6) Details and PoC Exploit Code Publicly Disclosed

Do Son July 20, 2026 0
Read More Read more about CVE-2026-58443: Gitea Flaw (CVSS 9.6) Details and PoC Exploit Code Publicly Disclosed
OAuth Client ID Spoofing Lets Attackers Enumerate Entra ID Accounts Without a Trace OAuth client ID spoofing enabling stealthy account enumeration against Microsoft Entra ID sign-in logs
  • Cybercriminals

OAuth Client ID Spoofing Lets Attackers Enumerate Entra ID Accounts Without a Trace

Do Son July 20, 2026 0
Read More Read more about OAuth Client ID Spoofing Lets Attackers Enumerate Entra ID Accounts Without a Trace
Critical Apache Doris Flaw (CVE-2026-58319) Exposes Admin APIs to Unauthenticated Attackers Apache Doris vulnerability CVE-2026-58319 improper authentication in Frontend HTTP API
  • Vulnerability Report

Critical Apache Doris Flaw (CVE-2026-58319) Exposes Admin APIs to Unauthenticated Attackers

Do Son July 20, 2026 0
Read More Read more about Critical Apache Doris Flaw (CVE-2026-58319) Exposes Admin APIs to Unauthenticated Attackers
CVE-2026-56451: CVSS 10 Siemens Opcenter X Flaw Grants Full Unauthorized Access Siemens Opcenter X authentication bypass vulnerability CVE-2026-56451 JWT forgery
  • Vulnerability Report

CVE-2026-56451: CVSS 10 Siemens Opcenter X Flaw Grants Full Unauthorized Access

Do Son July 20, 2026 0
Read More Read more about CVE-2026-56451: CVSS 10 Siemens Opcenter X Flaw Grants Full Unauthorized Access
HOLLOWGRAPH Malware Hides Command-and-Control in Microsoft 365 Calendars HOLLOWGRAPH malware using Microsoft Graph API abuse to hide command-and-control inside a Microsoft 365 calendar event dated 2050
  • Malware

HOLLOWGRAPH Malware Hides Command-and-Control in Microsoft 365 Calendars

Do Son July 20, 2026 0
Read More Read more about HOLLOWGRAPH Malware Hides Command-and-Control in Microsoft 365 Calendars
CrashStealer: New macOS Infostealer Poses as Apple Crash Reporter to Steal Wallets and Passwords CrashStealer macOS infostealer posing as Apple crash reporter to steal browser and crypto wallet data
  • Malware

CrashStealer: New macOS Infostealer Poses as Apple Crash Reporter to Steal Wallets and Passwords

Do Son July 20, 2026 0
Read More Read more about CrashStealer: New macOS Infostealer Poses as Apple Crash Reporter to Steal Wallets and Passwords
Operation ShadowRecruit Uses Fake Government Job Ads to Plant SheetAgent RAT on Indian Systems Salt Typhoon Teleco Hack, Cisco Academy Link CVE-2025-0282 PoC exploit
  • Cybercriminals

Operation ShadowRecruit Uses Fake Government Job Ads to Plant SheetAgent RAT on Indian Systems

Do Son July 20, 2026 0
Read More Read more about Operation ShadowRecruit Uses Fake Government Job Ads to Plant SheetAgent RAT on Indian Systems
LabubaRAT Poses as NVIDIA Software to Hand Operators Full Control of Windows Hosts Exploited VMware
  • Malware

LabubaRAT Poses as NVIDIA Software to Hand Operators Full Control of Windows Hosts

Do Son July 20, 2026 0
Read More Read more about LabubaRAT Poses as NVIDIA Software to Hand Operators Full Control of Windows Hosts
Microsoft Ships KB5121767 Out-of-Band Update to Fix a Dell USB-C Compatibility Fault KB5121767 out-of-band update: Microsoft fix for the Dell USB-C driver compatibility fault on affected Precision and XPS laptops
  • Windows

Microsoft Ships KB5121767 Out-of-Band Update to Fix a Dell USB-C Compatibility Fault

Do Son July 20, 2026 0
Read More Read more about Microsoft Ships KB5121767 Out-of-Band Update to Fix a Dell USB-C Compatibility Fault
The Mac Pro That Never Shipped: Apple Secretly Built a New Intel Model and Killed Its “Extreme” Chips Mac Pro discontinuation: Apple's cheese-grater tower retired as the Mac Studio and Apple Silicon take over professional workflows
  • Technology

The Mac Pro That Never Shipped: Apple Secretly Built a New Intel Model and Killed Its “Extreme” Chips

Do Son July 20, 2026 0
Read More Read more about The Mac Pro That Never Shipped: Apple Secretly Built a New Intel Model and Killed Its “Extreme” Chips
Mid-July 2026: Weekly Threat Intelligence Report actively exploited vulnerabilities
  • Weekly Recap

Mid-July 2026: Weekly Threat Intelligence Report

Do Son July 20, 2026 0
Read More Read more about Mid-July 2026: Weekly Threat Intelligence Report
CVE-2026-52824: Default Docker Secret in Kimai Enables Account Takeover of Super Admin Accounts Kimai vulnerability CVE-2026-52824 account takeover via default Docker APP_SECRET
  • Vulnerability Report

CVE-2026-52824: Default Docker Secret in Kimai Enables Account Takeover of Super Admin Accounts

Do Son July 20, 2026 0
Read More Read more about CVE-2026-52824: Default Docker Secret in Kimai Enables Account Takeover of Super Admin Accounts
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intel📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-0770CVSS 9.8
    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2021-27137CVSS 8.1
    An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2026-6875CVSS 9.5
    ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability...
    Admin intel📅 Updated: Jul 18, 2026
  • CVE-2026-39808CVSS 9.8
    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox...
    CISA KEV📅 Added to KEV: Jul 16, 2026
  • CVE-2026-25089CVSS 9.8
    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox...
    CISA KEV📅 Added to KEV: Jul 16, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-47396CVSS 9.8
    PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's call...
  • CVE-2026-47393CVSS 9.8
    PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships...
  • CVE-2026-47392CVSS 9.9
    PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI,...
  • CVE-2026-47391CVSS 9.8
    PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party...
  • CVE-2026-28321CVSS 9.1
    SolarWinds Serv-U is affected by a broken access control vulnerability that could...
  • CVE-2026-28317CVSS 9.1
    SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability...
  • CVE-2026-28316CVSS 9.1
    SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability...
  • CVE-2026-28314CVSS 9.1
    SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that...
  • CVE-2026-28313CVSS 9.1
    SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability...
  • CVE-2026-28312CVSS 9.1
    SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.