Skip to content
July 29, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button

Weekly Recap

CISA flagged 6 actively exploited CVEs this week, from a SharePoint RCE to a Check Point auth bypass. See the full CISA KEV list and patch fast.
  • Weekly Recap

Weekly Threat Intelligence Briefing: Late July 2026

Do Son July 27, 2026 0
actively exploited vulnerabilities
  • Weekly Recap

Mid-July 2026: Weekly Threat Intelligence Report

Do Son July 20, 2026 0
weekly CVE report actively exploited vulnerabilities
  • Weekly Recap

Weekly CVE Report: 1,571 New Flaws and 6 Actively Exploited Bugs (July 6–12, 2026)

Do Son July 13, 2026 0
Weekly Threat Intelligence Active Vulnerability Report
  • Weekly Recap

Weekly Threat Intelligence: The July 2026 Breaches

Do Son July 6, 2026 0
Weekly CVE report June 2026 1909 new vulnerabilities CISA KEV CVE-2026-20230 exploited
  • Weekly Recap

Weekly CVE Report Logs 1,909 New Vulnerabilities and 6 Exploited Flaws

Do Son June 29, 2026 0

Tech News

MCP protocol update transitioning to a stateless architecture with HTTP header routing
  • Technology

MCP Protocol Embraces Stateless Architecture in Major Overhaul

Do Son July 29, 2026 0
Microsoft Project Perception agentic security system with red, blue, and green AI team agents, a security context layer, and actuators for the AI era
  • Technology

Microsoft Unveils Project Perception, an Agentic Security System

Do Son July 28, 2026 0
Moonshot AI Kimi K3 open weights release, the first 3T-class open model, with AgentENV microVM sandbox built after agents caused host kernel panics
  • Technology

Kimi K3 Opens Weights as Agents Push Past Sandbox Boundaries

Do Son July 28, 2026 0
Google native Chrome for Linux Arm64 build running on Raspberry Pi OS desktop with account sync and Widevine DRM support for streaming video
  • Technology

Google Quietly Ships Native Chrome for Linux Arm64 With DRM

Do Son July 28, 2026 0

Vulnerability

Node.js vulnerabilities patched in July 2026 including HTTP/2 use-after-free CVE-2026-56848
  • Vulnerability Report

Node.js Patches 11 Vulnerabilities in July 2026 Security Release

Do Son July 29, 2026 0
C-CURE 9000 vulnerability CVE-2026-21655 remote code execution and CVE-2026-21653 CVSS 9.6 SSRF flaw in Johnson Controls victor application server
  • Vulnerability Report

C-CURE 9000 Vulnerability CVE-2026-21655 Enables Remote Code Execution, CVE-2026-21653 Scores CVSS 9.6

Do Son July 29, 2026 0
OpenDJ vulnerabilities authorization bypass and unauthenticated SSRF in the DSMLv2 gateway of the LDAP directory server
  • Vulnerability Report

OpenDJ Vulnerabilities: Authorization Bypass (CVSS 9.6) and Unauthenticated SSRF (CVSS 9.4)

Do Son July 29, 2026 0
Certighost AD CS vulnerability CVE-2026-54121 Active Directory Certificate Services elevation of privilege chase flow diagram
  • Vulnerability Report

Certighost CVE-2026-54121 Active Directory Certificate Services Elevation of Privilege Details and PoC Exploit Code Go Public

Do Son July 29, 2026 0

Cyber Security

TA488 Uses Half-Click OWA Exploit to Deploy OWAReaper Implant TA488 half-click exploit abusing CVE-2026-42897 in Outlook Web Access to deploy OWAReaper implant
  • Cybercriminals

TA488 Uses Half-Click OWA Exploit to Deploy OWAReaper Implant

July 29, 2026 0
Insikt Group Finds Four New Golden Chickens Malware Families Golden Chickens malware chain showing ChonkyChicken malware and TinyEgg delivered through ClickFix fake verification pages
  • Cybercriminals

Insikt Group Finds Four New Golden Chickens Malware Families

July 28, 2026 0
JadeProx Used TriBack Loader Against a Vietnamese Hospital, Malaysia’s Foreign Ministry, and Hong Kong Schools ACR Stealer infection chain starting with a ClickFix lure to steal browser credentials
  • Cybercriminals

JadeProx Used TriBack Loader Against a Vietnamese Hospital, Malaysia’s Foreign Ministry, and Hong Kong Schools

July 28, 2026 0
Fake Job Interviews Deliver PylangGhost and GolangGhost RATs to Crypto Workers ClickFake Interview campaign delivering PylangGhost RAT and GolangGhost RAT to crypto professionals
  • Cybercriminals

Fake Job Interviews Deliver PylangGhost and GolangGhost RATs to Crypto Workers

July 28, 2026 0

Malware Alert

TrickBot Variant Hides C2 Traffic Inside Malformed DNS Queries FSB Center 16 targeting vulnerable routers across critical infrastructure via weak SNMP
  • Malware

TrickBot Variant Hides C2 Traffic Inside Malformed DNS Queries

July 29, 2026 0
Lampion Malware Campaign Targets Portugal With Fake Payment Receipts malware-code
  • Malware

Lampion Malware Campaign Targets Portugal With Fake Payment Receipts

July 29, 2026 0
Chaos Ransomware Uses msaRAT to Hide C2 Traffic Inside Chrome msaRAT malware used by the Chaos ransomware group to route C2 traffic through a headless Chrome browser session
  • Malware

Chaos Ransomware Uses msaRAT to Hide C2 Traffic Inside Chrome

July 29, 2026 0
RenPy Loader Spreads Amatera Stealer Through Fake Game Downloads RenPy Loader infection chain in fake game installers using MSBuild and EtherHiding to deploy Amatera Stealer
  • Malware

RenPy Loader Spreads Amatera Stealer Through Fake Game Downloads

July 27, 2026 0

Data Leak

Claude AI Shared Chats Surfaced in Google Over a Config Error Claude AI shared conversation links indexed in Google search due to a robots.txt and X-Robots-Tag misconfiguration exposing private chat content
  • Data Leak

Claude AI Shared Chats Surfaced in Google Over a Config Error

July 27, 2026 0
Hugging Face Discloses Production Breach Driven by an Autonomous AI Agent Hugging Face breach driven by an autonomous AI agent attack exposing internal datasets and credentials
  • Data Leak

Hugging Face Discloses Production Breach Driven by an Autonomous AI Agent

July 18, 2026 0
Grok Build Repository Upload Scandal: Researcher Confirms Privacy Mode Cannot Stop It Grok Build repository upload controversy, SpaceXAI privacy mode response
  • Data Leak

Grok Build Repository Upload Scandal: Researcher Confirms Privacy Mode Cannot Stop It

July 14, 2026 0
The Grok Build Privacy Controversy: Unauthorized Repository Uploads Grok Build privacy settings interface showing how to disable automated repository data uploads
  • Data Leak

The Grok Build Privacy Controversy: Unauthorized Repository Uploads

July 14, 2026 0
CVE-2026-50502: Public PoC Exploit Details Windows Event Log Remote Code Execution CVE-2026-50502 Windows Event Log RCE proof-of-concept exploit dropping an HTA file into a victim Startup folder over SMB
  • Vulnerability Report

CVE-2026-50502: Public PoC Exploit Details Windows Event Log Remote Code Execution

Do Son July 29, 2026 0
Read More Read more about CVE-2026-50502: Public PoC Exploit Details Windows Event Log Remote Code Execution
Sweet Security Brings Autonomous Protection to the AI Enterprise with New Blocking Capabilities Sweet_Prompt_Injection_Blocking_1785262689BnfYB2zAi6
  • Press Release

Sweet Security Brings Autonomous Protection to the AI Enterprise with New Blocking Capabilities

cybernewswire July 29, 2026 0
Read More Read more about Sweet Security Brings Autonomous Protection to the AI Enterprise with New Blocking Capabilities
Broadcom Patches CVE-2026-59309 & CVE-2026-59310 (CVSS 9.8) in VMware VMware authentication bypass advisory CVE-2026-59309 directory traversal
  • Vulnerability Report

Broadcom Patches CVE-2026-59309 & CVE-2026-59310 (CVSS 9.8) in VMware

Do Son July 29, 2026 0
Read More Read more about Broadcom Patches CVE-2026-59309 & CVE-2026-59310 (CVSS 9.8) in VMware
Gitea RCE Flaw CVE-2026-60004 (CVSS 9.8): Details and PoC Exploit Publicly Disclosed Gitea RCE vulnerability CVE-2026-60004 via diffpatch Git hook installation rated CVSS 9.8
  • Vulnerability Report

Gitea RCE Flaw CVE-2026-60004 (CVSS 9.8): Details and PoC Exploit Publicly Disclosed

Do Son July 29, 2026 0
Read More Read more about Gitea RCE Flaw CVE-2026-60004 (CVSS 9.8): Details and PoC Exploit Publicly Disclosed
Exploited in the Wild: CVE-2026-18072 (CVSS 9.8) Grants Full Administrative Control to 20,000 WordPress Sites CVE-2026-18072 video embedder backdoor authentication bypass
  • Vulnerability Report

Exploited in the Wild: CVE-2026-18072 (CVSS 9.8) Grants Full Administrative Control to 20,000 WordPress Sites

Do Son July 29, 2026 0
Read More Read more about Exploited in the Wild: CVE-2026-18072 (CVSS 9.8) Grants Full Administrative Control to 20,000 WordPress Sites
Check Point SmartConsole Authentication Bypass CVE-2026-16232 Exploited as Zero-Day, PoC and Details Public SmartConsole authentication bypass CVE-2026-16232 in Check Point Security Management Server
  • Vulnerability Report

Check Point SmartConsole Authentication Bypass CVE-2026-16232 Exploited as Zero-Day, PoC and Details Public

Do Son July 29, 2026 0
Read More Read more about Check Point SmartConsole Authentication Bypass CVE-2026-16232 Exploited as Zero-Day, PoC and Details Public
NVIDIA BlueField Flaw CVE-2026-65094 Allows Code Execution (CVSS 9.0) NVIDIA BlueField VIRTIO-Net vulnerability CVE-2026-65094 leading to code execution
  • Vulnerability Report

NVIDIA BlueField Flaw CVE-2026-65094 Allows Code Execution (CVSS 9.0)

Do Son July 29, 2026 0
Read More Read more about NVIDIA BlueField Flaw CVE-2026-65094 Allows Code Execution (CVSS 9.0)
IBM Aspera Vulnerabilities Patched in Faspex 5 and Desktop App IBM Aspera vulnerabilities in Faspex 5 and Desktop App including CVE-2026-14973
  • Vulnerability Report

IBM Aspera Vulnerabilities Patched in Faspex 5 and Desktop App

Do Son July 29, 2026 0
Read More Read more about IBM Aspera Vulnerabilities Patched in Faspex 5 and Desktop App
CVE-2026-45293: Arbitrary Code Execution in WordPress Coding Standards, a Tool With 49M+ Installs CVE-2026-45293 arbitrary code execution flaw in WordPress Coding Standards linting tool rated CVSS 8.6
  • Vulnerability Report

CVE-2026-45293: Arbitrary Code Execution in WordPress Coding Standards, a Tool With 49M+ Installs

Do Son July 29, 2026 0
Read More Read more about CVE-2026-45293: Arbitrary Code Execution in WordPress Coding Standards, a Tool With 49M+ Installs
Aembit Joins Snowflake to Tackle AI’s Next Security Frontier: Trusted Agent Interoperability result_Aembit-Snowflake-Revised_1785251578w6w40xbGlY
  • Press Release

Aembit Joins Snowflake to Tackle AI’s Next Security Frontier: Trusted Agent Interoperability

cybernewswire July 28, 2026 0
Read More Read more about Aembit Joins Snowflake to Tackle AI’s Next Security Frontier: Trusted Agent Interoperability
Mitel Patches MiCollab Command Injection Flaw (CVSS 9.8) That Lets Attackers Gain Control of the System MiCollab command injection and OpenScape UC vulnerability advisories from Mitel showing CVSS 9.8 and CVSS 8.0 severity ratings
  • Vulnerability Report

Mitel Patches MiCollab Command Injection Flaw (CVSS 9.8) That Lets Attackers Gain Control of the System

Do Son July 28, 2026 0
Read More Read more about Mitel Patches MiCollab Command Injection Flaw (CVSS 9.8) That Lets Attackers Gain Control of the System
Panduit IntraVUE Vulnerability CVE-2026-42933 (CVSS 10) Bypasses OT Segmentation Panduit IntraVUE vulnerability CVE-2026-42933 CVSS 10 rating enabling OT segmentation bypass in industrial networks
  • Vulnerability Report

Panduit IntraVUE Vulnerability CVE-2026-42933 (CVSS 10) Bypasses OT Segmentation

Do Son July 28, 2026 0
Read More Read more about Panduit IntraVUE Vulnerability CVE-2026-42933 (CVSS 10) Bypasses OT Segmentation
TeamCity RCE Flaw CVE-2026-63077 (CVSS 9.8) Enables Unauthenticated Command Execution TeamCity RCE vulnerability CVE-2026-63077 in TeamCity On-Premises rated CVSS 9.8
  • Vulnerability Report

TeamCity RCE Flaw CVE-2026-63077 (CVSS 9.8) Enables Unauthenticated Command Execution

Do Son July 28, 2026 0
Read More Read more about TeamCity RCE Flaw CVE-2026-63077 (CVSS 9.8) Enables Unauthenticated Command Execution
CVE-2026-42533: NGINX Heap Overflow Enables RCE and ASLR Bypass, Public PoC Released CVE-2026-42533 NGINX heap overflow proof-of-concept enabling an ASLR bypass and RCE
  • Vulnerability Report

CVE-2026-42533: NGINX Heap Overflow Enables RCE and ASLR Bypass, Public PoC Released

Do Son July 28, 2026 0
Read More Read more about CVE-2026-42533: NGINX Heap Overflow Enables RCE and ASLR Bypass, Public PoC Released
Fraggap Linux Kernel Vulnerability: Full Details and PoC Exploit Code Now Public Fraggap Linux kernel vulnerability CVE-2026-53362 enabling local privilege escalation through a UDPv6 out-of-bounds write
  • Vulnerability Report

Fraggap Linux Kernel Vulnerability: Full Details and PoC Exploit Code Now Public

Do Son July 28, 2026 0
Read More Read more about Fraggap Linux Kernel Vulnerability: Full Details and PoC Exploit Code Now Public
OVSwrap Local Root Vulnerability (CVE-2026-64531): Exploit Details and PoC Publicly Disclosed OVSwrap local root vulnerability CVE-2026-64531 in the Linux kernel Open vSwitch datapath
  • Vulnerability Report

OVSwrap Local Root Vulnerability (CVE-2026-64531): Exploit Details and PoC Publicly Disclosed

Do Son July 28, 2026 0
Read More Read more about OVSwrap Local Root Vulnerability (CVE-2026-64531): Exploit Details and PoC Publicly Disclosed
Windows 11 Experimental Builds Face a Time Bomb on August 11 Windows 11 Experimental Future Platforms time bomb expiring on August 11 with forced full-screen expiration popups, fixed by updating to Build 29634.1000
  • Windows

Windows 11 Experimental Builds Face a Time Bomb on August 11

Do Son July 28, 2026 0
Read More Read more about Windows 11 Experimental Builds Face a Time Bomb on August 11
Debian Debates Whether to Allow AI-Assisted Code Contributions Debian AI contribution vote debating four proposals on generative AI assisted code, from an outright ban to allowing AI with disclosure requirements
  • Linux

Debian Debates Whether to Allow AI-Assisted Code Contributions

Do Son July 28, 2026 0
Read More Read more about Debian Debates Whether to Allow AI-Assisted Code Contributions
NVIDIA and Microsoft Launch Open Secure AI Alliance After Hack NVIDIA and Microsoft launch the Open Secure AI Alliance with 27 founding members to strengthen cybersecurity defense after the Hugging Face AI attack
  • Technology

NVIDIA and Microsoft Launch Open Secure AI Alliance After Hack

Do Son July 28, 2026 0
Read More Read more about NVIDIA and Microsoft Launch Open Secure AI Alliance After Hack
libssh2 Flaws Let Malicious SSH Servers Corrupt Client Memory libssh2 vulnerabilities let a malicious SSH server corrupt heap memory in SSH and SFTP clients
  • Vulnerability Report

libssh2 Flaws Let Malicious SSH Servers Corrupt Client Memory

Do Son July 28, 2026 0
Read More Read more about libssh2 Flaws Let Malicious SSH Servers Corrupt Client Memory
Progress Patches Five Kemp LoadMaster Vulnerabilities Kemp LoadMaster vulnerabilities warning covering OS command injection and privilege escalation flaws
  • Vulnerability Report

Progress Patches Five Kemp LoadMaster Vulnerabilities

Do Son July 28, 2026 0
Read More Read more about Progress Patches Five Kemp LoadMaster Vulnerabilities
Apache ActiveMQ Patches Authorization Bypass and DoS Flaws Apache ActiveMQ vulnerability alert covering authorization bypass and AMQP denial-of-service flaws
  • Vulnerability Report

Apache ActiveMQ Patches Authorization Bypass and DoS Flaws

Do Son July 28, 2026 0
Read More Read more about Apache ActiveMQ Patches Authorization Bypass and DoS Flaws
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-18072CVSS 9.8
    The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to...
    Admin intel📅 Updated: Jul 29, 2026
  • CVE-2026-16812CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access...
    Admin intelCISA KEV📅 Added to KEV: Jul 27, 2026📅 Updated: Jul 27, 2026
  • CVE-2025-68686CVSS 5.9
    An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1,...
    CISA KEV📅 Added to KEV: Jul 27, 2026
  • CVE-2026-16723CVSS 9.0
    A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson\'s stock...
    Admin intel📅 Updated: Jul 25, 2026
  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-14900CVSS 9.8
    The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote...
  • CVE-2026-14488CVSS 9.1
    The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization...
  • CVE-2025-10656CVSS 9.8
    The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin...
  • CVE-2026-58162CVSS 10.0
    The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client...
  • CVE-2026-58155CVSS 9.3
    Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling,...
  • CVE-2026-58150CVSS 10.0
    Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade...
  • CVE-2026-57834CVSS 10.0
    Apache Traffic Server allows request smuggling if chunked messages are malformed. This...
  • CVE-2026-33267CVSS 10.0
    Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache...
  • CVE-2026-41920CVSS 9.3
    Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache...
  • CVE-2026-63234CVSS 9.9
    A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.