Skip to content
October 6, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button

Weekly Recap

Weekly CVE report on exploited vulnerabilities from Daily Cybersecurity and CISA KEV, September 28 to October 4, 2026
  • Weekly Recap

Weekly CVE Report Tracks 2,652 New Flaws and Seven Exploited Vulnerabilities (Sept. 28 – Oct. 4, 2026)

Do Son October 5, 2026 0
Weekly CVE report comparing exploited vulnerabilities from Daily Cybersecurity intelligence with the CISA KEV catalog for September 21-27, 2026
  • Weekly Recap

Weekly CVE Report: 2,825 New Flaws and 9 Exploited Bugs (Sept 21-27, 2026)

Do Son September 28, 2026 0
CVE-2023-50164 AEM Forms
  • Weekly Recap

Weekly CVE Report: 4,378 New Flaws and 10 Exploited Bugs

Do Son September 21, 2026 0
Weekly CVE report chart comparing Daily Cybersecurity exploited vulnerabilities against the CISA KEV catalog
  • Weekly Recap

Daily Cybersecurity Flagged 9 Exploited Flaws Before CISA KEV

Do Son September 14, 2026 0
This weekly CVE report covers 10 exploited vulnerabilities added to CISA KEV and 2,316 new CVEs from Aug 31 to Sep 6, 2026. Patch fast.
  • Weekly Recap

Weekly CVE Report: Daily Cybersecurity Beats CISA KEV on Exploited Flaws

Do Son September 7, 2026 0

Tech News

Apple Safari Chrome tracking telemetry data analysis
  • Technology

Apple Safari Chrome Tracking: A New Antitrust Defense Tool

Do Son October 6, 2026 0
Polish UOKiK officials launching a Google antitrust investigation into media copyright violations and AI search algorithm data transparency
  • Technology

Poland Launches Google Antitrust Investigation Over Media Pay

Do Son October 6, 2026 0
OpenAI text watermarking with textGrain detector for EU AI Act compliance
  • Technology

OpenAI Text Watermarking Arrives Under the EU AI Act

Do Son October 6, 2026 0
Cloudflare Clef decision models returning option probability scores for AI agents on the Workers AI platform
  • Technology

Cloudflare Clef Decision Models Speed Up AI Agents

Do Son October 5, 2026 0

Vulnerability

Veeam Backup vulnerability CVE-2025-64393 remote code execution fixed in build 12.3.2.4934
  • Vulnerability Report

Veeam Patches Critical Backup & Replication RCE Flaw CVE-2025-64393 and Two More Bugs

Do Son October 6, 2026 0
WordPress 7.1.3 security update fixing stored XSS and SQL injection in WordPress security release
  • Vulnerability Report

WordPress 7.1.3 Security Update Fixes Stored XSS, SQL Injection and Five More Flaws

Do Son October 6, 2026 0
SonicWall SMA1000 vulnerability CVE-2026-102255 pre-authentication SSRF with CVE-2026-102256 and CVE-2026-102257
  • Vulnerability Report

SonicWall Patches CVSS 10 Pre-Auth SSRF Flaw and Three More Bugs in SMA1000 Appliances

Do Son October 6, 2026 0
Progress DataDirect vulnerability CVE-2026-91140 command injection in Autonomous REST Connector AI Model Generator agents
  • Vulnerability Report

Progress Fixes Critical Command Injection Flaw CVE-2026-91140 in DataDirect AI Model Generator Agents

Do Son October 6, 2026 0

Cyber Security

ShinyHunters Hacker Arrest in Jordan Aids FBI Probe ShinyHunters hacker arrest in Jordan as an alleged member cooperates with the FBI ShinyHunters investigation
  • Cybercriminals

ShinyHunters Hacker Arrest in Jordan Aids FBI Probe

October 5, 2026 0
Warlock Ransomware Group Hits Water and Telecom Operators Through SharePoint Flaws Warlock ransomware attack chain exploiting SharePoint vulnerabilities to hit critical infrastructure
  • Cybercriminals

Warlock Ransomware Group Hits Water and Telecom Operators Through SharePoint Flaws

October 5, 2026 0
China-Aligned TA419 Credential Phishing Hits AI Experts Diagram showing China-aligned TA419 credential phishing and TA419 credential phishing attack stages
  • Cybercriminals

China-Aligned TA419 Credential Phishing Hits AI Experts

October 2, 2026 0
Phishing Abuses RMM Tools for Persistent Network Access CoreRAT malware decoy PDF used in Core Werewolf phishing attack on Russian defense targets
  • Cybercriminals

Phishing Abuses RMM Tools for Persistent Network Access

October 2, 2026 0

Malware Alert

ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into Proxy Nodes Diagram showing the MemTensor MemOS compromise details and how the MemTensor MemOS compromise affects developers
  • Malware

ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into Proxy Nodes

October 6, 2026 0
Moroccan Intelligence Deploys Vast Surveillance Panopticon Amnesty International exposing the Moroccan DGST surveillance network and Pegasus spyware infections
  • Malware

Moroccan Intelligence Deploys Vast Surveillance Panopticon

October 5, 2026 0
DragonForce Backdoor Adds MQTT Fallback to Microsoft Teams TURN Command Channel DragonForce backdoor using Microsoft Teams TURN relays and MQTT as a fallback command channel
  • Malware

DragonForce Backdoor Adds MQTT Fallback to Microsoft Teams TURN Command Channel

October 5, 2026 0
New 2CLoader Malware Delivers Vidar and Remus Infostealers While Dodging Sandboxes 2CLoader malware infection chain delivering Vidar and Remus infostealers with anti-VM and evasion checks
  • Malware

New 2CLoader Malware Delivers Vidar and Remus Infostealers While Dodging Sandboxes

October 5, 2026 0

Data Leak

Trump Mobile Data Breach Exposes 3,615 Customers in BYOD Leak leak
  • Data Leak

Trump Mobile Data Breach Exposes 3,615 Customers in BYOD Leak

October 6, 2026 0
Denmark CPR Data Breach Exposes CPR Numbers of 8.8 Million People Denmark CPR data breach - CPR numbers exposed for 8.8 million people in the national register
  • Data Leak

Denmark CPR Data Breach Exposes CPR Numbers of 8.8 Million People

October 5, 2026 0
AI Coding Agents Leak 13,000 Internal Screenshots to Public GitHub Repos AI agent screenshot leak in PixelLeak research showing internal images pushed to public GitHub repos
  • Data Leak

AI Coding Agents Leak 13,000 Internal Screenshots to Public GitHub Repos

September 30, 2026 0
Meta Muse Secretly Used Humans for AI Phone Calls Meta Muse AI agent phone calling feature secretly handed off to human contractors
  • Data Leak

Meta Muse Secretly Used Humans for AI Phone Calls

September 24, 2026 0
CVE Watchtower User Guide CVE Watchtower User Guide
  • How To

CVE Watchtower User Guide

Do Son October 2, 2026 0
Read More Read more about CVE Watchtower User Guide
Aembit Extends Access Controls to Personal AI Agents Aembit_Control_Plane_Video_V1_1791234426vgaCNFRKd6
  • Press Release

Aembit Extends Access Controls to Personal AI Agents

cybernewswire October 6, 2026 0
Read More Read more about Aembit Extends Access Controls to Personal AI Agents
Criminal IP Introduces AITEM as the Next Evolution of Attack Surface Management govware_001_1790666482q1kAoPtquQ
  • Press Release

Criminal IP Introduces AITEM as the Next Evolution of Attack Surface Management

cybernewswire October 6, 2026 0
Read More Read more about Criminal IP Introduces AITEM as the Next Evolution of Attack Surface Management
AppViewX Adds Shadow AI Visibility and a Runtime Kill Switch to Agent Identity Security PR_Banner_17912262302FpkG0rOrt
  • Press Release

AppViewX Adds Shadow AI Visibility and a Runtime Kill Switch to Agent Identity Security

cybernewswire October 6, 2026 0
Read More Read more about AppViewX Adds Shadow AI Visibility and a Runtime Kill Switch to Agent Identity Security
Murrelektronik Will Not Fix Critical AAS Edge Client Flaw CVE-2026-94293, Urges Removal AAS edge client vulnerability CVE-2026-94293 missing authentication in Murrelektronik aas-edge-client reference implementation
  • Vulnerability Report

Murrelektronik Will Not Fix Critical AAS Edge Client Flaw CVE-2026-94293, Urges Removal

Do Son October 6, 2026 0
Read More Read more about Murrelektronik Will Not Fix Critical AAS Edge Client Flaw CVE-2026-94293, Urges Removal
Why Emerging Tech Hubs Are Ideal for Custom Web Development Outsourcing tech-laun
  • Technique

Why Emerging Tech Hubs Are Ideal for Custom Web Development Outsourcing

Do Son October 6, 2026 0
Read More Read more about Why Emerging Tech Hubs Are Ideal for Custom Web Development Outsourcing
Researchers Publish Full Details and PoC Exploit for a WordPress libheif RCE Chain WordPress libheif RCE chain exploiting GHSA-x8r2-mggj-j6wr heap overflow via authenticated HEIC image upload
  • Vulnerability Report

Researchers Publish Full Details and PoC Exploit for a WordPress libheif RCE Chain

Do Son October 6, 2026 0
Read More Read more about Researchers Publish Full Details and PoC Exploit for a WordPress libheif RCE Chain
PoC Exploit and Technical Details Released for LibreOffice Calc Code Execution Flaw CVE-2026-63277 LibreOffice Calc vulnerability CVE-2026-63277 code execution with public PoC, plus file read and write flaws CVE-2026-63266 and CVE-2026-63267
  • Vulnerability Report

PoC Exploit and Technical Details Released for LibreOffice Calc Code Execution Flaw CVE-2026-63277

Do Son October 6, 2026 0
Read More Read more about PoC Exploit and Technical Details Released for LibreOffice Calc Code Execution Flaw CVE-2026-63277
Critical Atlassian Flaw CVE-2026-21589 Exposes Files in Jira, Confluence, Bitbucket and Five More Products Atlassian Data Center vulnerability CVE-2026-21589 arbitrary file access in Jira, Confluence, Bitbucket, Bamboo, Crowd, Fisheye and Crucible
  • Vulnerability Report

Critical Atlassian Flaw CVE-2026-21589 Exposes Files in Jira, Confluence, Bitbucket and Five More Products

Do Son October 6, 2026 0
Read More Read more about Critical Atlassian Flaw CVE-2026-21589 Exposes Files in Jira, Confluence, Bitbucket and Five More Products
Twenty CRM Flaw CVE-2026-105763 Exposes Plaintext Email Passwords to Any Workspace Member Twenty CRM vulnerability CVE-2026-105763 exposing plaintext IMAP SMTP CalDAV passwords via GraphQL
  • Vulnerability Report

Twenty CRM Flaw CVE-2026-105763 Exposes Plaintext Email Passwords to Any Workspace Member

Do Son October 6, 2026 0
Read More Read more about Twenty CRM Flaw CVE-2026-105763 Exposes Plaintext Email Passwords to Any Workspace Member
IBM Patches 25 Langflow Vulnerabilities, Including Two Critical Remote Code Execution Flaws Langflow vulnerabilities fixed in Langflow 1.12.3 including critical CVE-2026-104334 and CVE-2026-93674 remote code execution
  • Vulnerability Report

IBM Patches 25 Langflow Vulnerabilities, Including Two Critical Remote Code Execution Flaws

Do Son October 6, 2026 0
Read More Read more about IBM Patches 25 Langflow Vulnerabilities, Including Two Critical Remote Code Execution Flaws
Apache Thrift 0.25.0 Fixes 61 Vulnerabilities, Including Two Critical Heap Overflows Apache Thrift vulnerabilities fixed in Apache Thrift 0.25.0 including CVE-2026-83632 and CVE-2026-91135
  • Vulnerability Report

Apache Thrift 0.25.0 Fixes 61 Vulnerabilities, Including Two Critical Heap Overflows

Do Son October 6, 2026 0
Read More Read more about Apache Thrift 0.25.0 Fixes 61 Vulnerabilities, Including Two Critical Heap Overflows
AMD RCCL Vulnerability Could Enable Remote Code Execution on Instinct GPU Clusters AMD RCCL vulnerability CVE-2026-43598 in the ROCm Communication Collectives Library on AMD Instinct GPUs
  • Vulnerability Report

AMD RCCL Vulnerability Could Enable Remote Code Execution on Instinct GPU Clusters

Do Son October 6, 2026 0
Read More Read more about AMD RCCL Vulnerability Could Enable Remote Code Execution on Instinct GPU Clusters
Who Can Actually Compel Your Hosting Provider: A Jurisdiction Guide for Security Teams DCMTK vulnerabilities enabling path traversal file write in the DICOM toolkit (CVE-2026-50003)
  • Technique

Who Can Actually Compel Your Hosting Provider: A Jurisdiction Guide for Security Teams

Do Son October 5, 2026 0
Read More Read more about Who Can Actually Compel Your Hosting Provider: A Jurisdiction Guide for Security Teams
Apache Struts 7.4.0 Fixes Four Vulnerabilities, Including OGNL Injection and REST Plugin DoS Apache Struts vulnerabilities fixed in Struts 7.4.0 including OGNL injection CVE-2026-104711 and REST plugin DoS CVE-2026-104713
  • Vulnerability Report

Apache Struts 7.4.0 Fixes Four Vulnerabilities, Including OGNL Injection and REST Plugin DoS

Do Son October 5, 2026 0
Read More Read more about Apache Struts 7.4.0 Fixes Four Vulnerabilities, Including OGNL Injection and REST Plugin DoS
Google Fortifies Android Advanced Protection Google Android Advanced Protection shield icon over smartphone interface showing security updates
  • Android

Google Fortifies Android Advanced Protection

Do Son October 5, 2026 0
Read More Read more about Google Fortifies Android Advanced Protection
8 Top Tools to Discover Shadow Agents Diagram illustrating Langflow OSS vulnerabilities and CVE-2026-10134 execution paths
  • Technique

8 Top Tools to Discover Shadow Agents

Do Son October 5, 2026 0
Read More Read more about 8 Top Tools to Discover Shadow Agents
Perforce Fixes Six P4 Search Vulnerabilities, Including a CVSS 10 Default Token Flaw Perforce P4 Search vulnerabilities CVE-2026-100103 default token and CVE-2026-100102 exposed Java debug interface in P4 Search
  • Vulnerability Report

Perforce Fixes Six P4 Search Vulnerabilities, Including a CVSS 10 Default Token Flaw

Do Son October 5, 2026 0
Read More Read more about Perforce Fixes Six P4 Search Vulnerabilities, Including a CVSS 10 Default Token Flaw
Windows 11 26H2 Update Arrives With a Single Restart Windows 11 26H2 update installing through Windows Update with an enablement package, the Windows 11 2026 Update
  • Windows

Windows 11 26H2 Update Arrives With a Single Restart

Do Son October 5, 2026 0
Read More Read more about Windows 11 26H2 Update Arrives With a Single Restart
MediaTek October 2026 Security Bulletin Fixes 31 Flaws, Including Two Critical Modem Bugs MediaTek security bulletin October 2026 MediaTek modem vulnerability CVE-2026-20519 CVE-2026-20520 rogue base station
  • Vulnerability Report

MediaTek October 2026 Security Bulletin Fixes 31 Flaws, Including Two Critical Modem Bugs

Do Son October 5, 2026 0
Read More Read more about MediaTek October 2026 Security Bulletin Fixes 31 Flaws, Including Two Critical Modem Bugs
OpenAI Rogue AI Agents May Have Hit 100+ Organizations OpenAI rogue AI agents reaching beyond their sandbox into third-party systems, part of a wave of AI agent misalignment incidents
  • Technology

OpenAI Rogue AI Agents May Have Hit 100+ Organizations

Do Son October 5, 2026 0
Read More Read more about OpenAI Rogue AI Agents May Have Hit 100+ Organizations
Ubuntu 26.04 Upgrade Now Open to 24.04 LTS Users Ubuntu 26.04 upgrade offered in Update Manager to Ubuntu 24.04 LTS users, showing the Resolute Raccoon desktop
  • Linux

Ubuntu 26.04 Upgrade Now Open to 24.04 LTS Users

Do Son October 5, 2026 0
Read More Read more about Ubuntu 26.04 Upgrade Now Open to 24.04 LTS Users
BPFDoor Backdoor and New AVERAT Implant Hide in SMTP Traffic on Telecom Edge Devices BPFDoor backdoor and AVERAT implant disguised as mail traffic on telecom and network edge appliances
  • Malware

BPFDoor Backdoor and New AVERAT Implant Hide in SMTP Traffic on Telecom Edge Devices

Do Son October 5, 2026 0
Read More Read more about BPFDoor Backdoor and New AVERAT Implant Hide in SMTP Traffic on Telecom Edge Devices
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-104286CVSS 9.8
    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
    CISA KEV📅 Added to KEV: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-104019CVSS 9.3
    OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x...
    📅 Updated: Oct 6, 2026
  • CVE-2026-105778CVSS 9.4
    A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this issue is some unknown functionality of...
    📅 Updated: Oct 6, 2026
  • CVE-2026-105794CVSS 9.1
    MsQuic is a cross-platform C implementation of the IETF QUIC protocol exposed to C, C++, C#, and Rust....
    📅 Updated: Oct 6, 2026
  • CVE-2026-105851CVSS 9.3
    Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and...
    📅 Updated: Oct 6, 2026
  • CVE-2026-87830CVSS 9.1
    In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that...
    📅 Updated: Oct 6, 2026
  • CVE-2026-89238CVSS 9.1
    WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality...
    📅 Updated: Oct 6, 2026
  • CVE-2026-94293CVSS 9.3
    An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all...
    📅 Updated: Oct 6, 2026
  • CVE-2026-88424CVSS 9.8
    FineAdmin v1.0 was discovered to contain a SQL injection vulnerability via the field/order parameter at ButtonService.GetListByFilter(). This vulnerability...
    📅 Updated: Oct 6, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.