Skip to content
July 20, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button

Weekly Recap

actively exploited vulnerabilities
  • Weekly Recap

Mid-July 2026: Weekly Threat Intelligence Report

Do Son July 20, 2026 0
weekly CVE report actively exploited vulnerabilities
  • Weekly Recap

Weekly CVE Report: 1,571 New Flaws and 6 Actively Exploited Bugs (July 6–12, 2026)

Do Son July 13, 2026 0
Weekly Threat Intelligence Active Vulnerability Report
  • Weekly Recap

Weekly Threat Intelligence: The July 2026 Breaches

Do Son July 6, 2026 0
Weekly CVE report June 2026 1909 new vulnerabilities CISA KEV CVE-2026-20230 exploited
  • Weekly Recap

Weekly CVE Report Logs 1,909 New Vulnerabilities and 6 Exploited Flaws

Do Son June 29, 2026 0
Weekly CVE report dashboard showing 2,060 new vulnerabilities and 4 actively exploited CVEs in CISA KEV
  • Weekly Recap

2,060 New CVEs and 4 Actively Exploited Flaws (June 15-21, 2026)

Do Son June 22, 2026 0

Tech News

Codex context window change: OpenAI lowers the limit to 272K and forbids rm -rf $HOME in the system prompt after deletions
  • Technology

Codex Cuts Its Context Window to 272K and Forbids rm -rf $HOME After Home-Directory Deletions

Do Son July 20, 2026 0
Mac Pro discontinuation: Apple's cheese-grater tower retired as the Mac Studio and Apple Silicon take over professional workflows
  • Technology

The Mac Pro That Never Shipped: Apple Secretly Built a New Intel Model and Killed Its “Extreme” Chips

Do Son July 20, 2026 0
DOJ lifts TikTok ban for federal workers and allows government downloads
  • Technology

US Justice Department Approves TikTok for Government Devices

Do Son July 18, 2026 0
Meta AI computing power lease and Anthropic data center negotiations
  • Technology

Meta and Anthropic Negotiate Computing Power Lease

Do Son July 18, 2026 0

Vulnerability

Gitea vulnerability CVE-2026-58443 public-only token writing to private repository
  • Vulnerability Report

CVE-2026-58443: Gitea Flaw (CVSS 9.6) Details and PoC Exploit Code Publicly Disclosed

Do Son July 20, 2026 0
Apache Doris vulnerability CVE-2026-58319 improper authentication in Frontend HTTP API
  • Vulnerability Report

Critical Apache Doris Flaw (CVE-2026-58319) Exposes Admin APIs to Unauthenticated Attackers

Do Son July 20, 2026 0
Siemens Opcenter X authentication bypass vulnerability CVE-2026-56451 JWT forgery
  • Vulnerability Report

CVE-2026-56451: CVSS 10 Siemens Opcenter X Flaw Grants Full Unauthorized Access

Do Son July 20, 2026 0
Kimai vulnerability CVE-2026-52824 account takeover via default Docker APP_SECRET
  • Vulnerability Report

CVE-2026-52824: Default Docker Secret in Kimai Enables Account Takeover of Super Admin Accounts

Do Son July 20, 2026 0

Cyber Security

United States Seizes More Than 1,000 Domains Streaming World Cup 2026 Matches Website Seizure Graphic
  • Cybercriminals

United States Seizes More Than 1,000 Domains Streaming World Cup 2026 Matches

July 20, 2026 0
OAuth Client ID Spoofing Lets Attackers Enumerate Entra ID Accounts Without a Trace OAuth client ID spoofing enabling stealthy account enumeration against Microsoft Entra ID sign-in logs
  • Cybercriminals

OAuth Client ID Spoofing Lets Attackers Enumerate Entra ID Accounts Without a Trace

July 20, 2026 0
Operation ShadowRecruit Uses Fake Government Job Ads to Plant SheetAgent RAT on Indian Systems Salt Typhoon Teleco Hack, Cisco Academy Link CVE-2025-0282 PoC exploit
  • Cybercriminals

Operation ShadowRecruit Uses Fake Government Job Ads to Plant SheetAgent RAT on Indian Systems

July 20, 2026 0
SonicWall SMA Zero-Day Chain Roots VPN Appliances and Plants Hidden Malware SonicWall SMA zero-day exploit chain compromising SMA VPN appliances to deploy malware
  • Cybercriminals

SonicWall SMA Zero-Day Chain Roots VPN Appliances and Plants Hidden Malware

July 19, 2026 0

Malware Alert

HOLLOWGRAPH Malware Hides Command-and-Control in Microsoft 365 Calendars HOLLOWGRAPH malware using Microsoft Graph API abuse to hide command-and-control inside a Microsoft 365 calendar event dated 2050
  • Malware

HOLLOWGRAPH Malware Hides Command-and-Control in Microsoft 365 Calendars

July 20, 2026 0
CrashStealer: New macOS Infostealer Poses as Apple Crash Reporter to Steal Wallets and Passwords CrashStealer macOS infostealer posing as Apple crash reporter to steal browser and crypto wallet data
  • Malware

CrashStealer: New macOS Infostealer Poses as Apple Crash Reporter to Steal Wallets and Passwords

July 20, 2026 0
LabubaRAT Poses as NVIDIA Software to Hand Operators Full Control of Windows Hosts Exploited VMware
  • Malware

LabubaRAT Poses as NVIDIA Software to Hand Operators Full Control of Windows Hosts

July 20, 2026 0
GoldPickaxe Banking Trojan Returns to Steal Faces and Bank Logins GoldPickaxe banking Trojan stealing biometric data and lock screen credentials from an Android phone
  • Malware

GoldPickaxe Banking Trojan Returns to Steal Faces and Bank Logins

July 17, 2026 0

Data Leak

Hugging Face Discloses Production Breach Driven by an Autonomous AI Agent Hugging Face breach driven by an autonomous AI agent attack exposing internal datasets and credentials
  • Data Leak

Hugging Face Discloses Production Breach Driven by an Autonomous AI Agent

July 18, 2026 0
Grok Build Repository Upload Scandal: Researcher Confirms Privacy Mode Cannot Stop It Grok Build repository upload controversy, SpaceXAI privacy mode response
  • Data Leak

Grok Build Repository Upload Scandal: Researcher Confirms Privacy Mode Cannot Stop It

July 14, 2026 0
The Grok Build Privacy Controversy: Unauthorized Repository Uploads Grok Build privacy settings interface showing how to disable automated repository data uploads
  • Data Leak

The Grok Build Privacy Controversy: Unauthorized Repository Uploads

July 14, 2026 0
KDDI Data Breach: Millions of Emails and Passwords Stolen KDDI data breach illustration, KDDI email leak security concept
  • Data Leak

KDDI Data Breach: Millions of Emails and Passwords Stolen

July 9, 2026 0
Microsoft Ships KB5121767 Out-of-Band Update to Fix a Dell USB-C Compatibility Fault KB5121767 out-of-band update: Microsoft fix for the Dell USB-C driver compatibility fault on affected Precision and XPS laptops
  • Windows

Microsoft Ships KB5121767 Out-of-Band Update to Fix a Dell USB-C Compatibility Fault

Do Son July 20, 2026 0
Read More Read more about Microsoft Ships KB5121767 Out-of-Band Update to Fix a Dell USB-C Compatibility Fault
Mid-July 2026: Weekly Threat Intelligence Report actively exploited vulnerabilities
  • Weekly Recap

Mid-July 2026: Weekly Threat Intelligence Report

Do Son July 20, 2026 0
Read More Read more about Mid-July 2026: Weekly Threat Intelligence Report
OpenSSL HollowByte Vulnerability Causes Memory Exhaustion Diagram explaining the OpenSSL HollowByte vulnerability and OpenSSL DoS attack mechanism
  • Vulnerability Report

OpenSSL HollowByte Vulnerability Causes Memory Exhaustion

Do Son July 20, 2026 0
Read More Read more about OpenSSL HollowByte Vulnerability Causes Memory Exhaustion
Claude Fable 5 Subscription Changes Announced Claude Fable 5 subscription updates and AI computational limitations
  • Technology

Claude Fable 5 Subscription Changes Announced

Do Son July 18, 2026 0
Read More Read more about Claude Fable 5 Subscription Changes Announced
Active Exploitation and Public PoC Disclosed for CVE-2026-6875 ServiceNow Sandbox Escape Remote Code Execution Diagram of CVE-2026-6875 ServiceNow sandbox escape RCE and pre-auth code execution
  • Vulnerability Report

Active Exploitation and Public PoC Disclosed for CVE-2026-6875 ServiceNow Sandbox Escape Remote Code Execution

Do Son July 18, 2026 0
Read More Read more about Active Exploitation and Public PoC Disclosed for CVE-2026-6875 ServiceNow Sandbox Escape Remote Code Execution
Cloudflare Blocks Critical WordPress wp2shell Vulnerability Cloudflare firewall blocking the critical WordPress wp2shell vulnerability and RCE attacks
  • Vulnerability Report

Cloudflare Blocks Critical WordPress wp2shell Vulnerability

Do Son July 18, 2026 0
Read More Read more about Cloudflare Blocks Critical WordPress wp2shell Vulnerability
Microsoft Ends OneDrive Support for Windows 10 Microsoft ending OneDrive updates and support for Windows 10 lifecycle
  • Technology

Microsoft Ends OneDrive Support for Windows 10

Do Son July 18, 2026 0
Read More Read more about Microsoft Ends OneDrive Support for Windows 10
Ubuntu Pro Client Flaw CVE-2026-11386 Allows Arbitrary Code Execution With Root Privileges Ubuntu Pro Client vulnerability CVE-2026-11386 APT source injection arbitrary code execution root privileges
  • Vulnerability Report

Ubuntu Pro Client Flaw CVE-2026-11386 Allows Arbitrary Code Execution With Root Privileges

Do Son July 18, 2026 0
Read More Read more about Ubuntu Pro Client Flaw CVE-2026-11386 Allows Arbitrary Code Execution With Root Privileges
WordPress Pre-Auth RCE CVE-2026-63030: Vulnerability Details and PoC Exploit Code Now Public WordPress pre-auth RCE CVE-2026-63030 REST batch route confusion SQL injection public PoC
  • Vulnerability Report

WordPress Pre-Auth RCE CVE-2026-63030: Vulnerability Details and PoC Exploit Code Now Public

Do Son July 18, 2026 0
Read More Read more about WordPress Pre-Auth RCE CVE-2026-63030: Vulnerability Details and PoC Exploit Code Now Public
APT-C-60 Attacks Target Japan With SpyGlace Malware APT-C-60 attacks on Japan using LNK files and legitimate services to deploy SpyGlace malware
  • Cybercriminals

APT-C-60 Attacks Target Japan With SpyGlace Malware

Do Son July 18, 2026 0
Read More Read more about APT-C-60 Attacks Target Japan With SpyGlace Malware
CheapSSLWEB Review: Best Place to Buy Cheap SSL Certificates with SSL Automation cheapsslweb-ssl-provider
  • Technique

CheapSSLWEB Review: Best Place to Buy Cheap SSL Certificates with SSL Automation

Do Son July 18, 2026 0
Read More Read more about CheapSSLWEB Review: Best Place to Buy Cheap SSL Certificates with SSL Automation
Certera Review: A Trusted Leader in SSL Certificates, PKI, and Digital Trust Solutions certera-ssl-provider
  • Technique

Certera Review: A Trusted Leader in SSL Certificates, PKI, and Digital Trust Solutions

Do Son July 18, 2026 0
Read More Read more about Certera Review: A Trusted Leader in SSL Certificates, PKI, and Digital Trust Solutions
RokRAT Malware Hides in Fake PDF Files to Spy on Academics APT37 RokRAT malware delivered via fake PDF in Operation Capsule Vault spear-phishing
  • Malware

RokRAT Malware Hides in Fake PDF Files to Spy on Academics

Do Son July 17, 2026 0
Read More Read more about RokRAT Malware Hides in Fake PDF Files to Spy on Academics
CVE-2026-54523 (CVSS 9.6): Public PoC Exploit Enables Kyverno Privilege Escalation to Admin in Any Namespace Kyverno vulnerability CVE-2026-54523 privilege escalation to admin in any namespace including kube-system
  • Vulnerability Report

CVE-2026-54523 (CVSS 9.6): Public PoC Exploit Enables Kyverno Privilege Escalation to Admin in Any Namespace

Do Son July 17, 2026 0
Read More Read more about CVE-2026-54523 (CVSS 9.6): Public PoC Exploit Enables Kyverno Privilege Escalation to Admin in Any Namespace
Citrix Secure Access Vulnerability Lets Local Users Gain SYSTEM Privileges Citrix Secure Access vulnerability CVE-2026-53565 privilege escalation illustration
  • Vulnerability Report

Citrix Secure Access Vulnerability Lets Local Users Gain SYSTEM Privileges

Do Son July 17, 2026 0
Read More Read more about Citrix Secure Access Vulnerability Lets Local Users Gain SYSTEM Privileges
Misconfigured Server Exposes Three AiTM Phishing Operators Open directory exposing three AiTM phishing operators using Evilginx MFA bypass tooling
  • Cybercriminals

Misconfigured Server Exposes Three AiTM Phishing Operators

Do Son July 17, 2026 0
Read More Read more about Misconfigured Server Exposes Three AiTM Phishing Operators
292 Fake GitHub Repositories Deliver BoryptGrab Infostealer to Windows Users Fake GitHub repositories BoryptGrab infostealer attack chain diagram
  • Malware

292 Fake GitHub Repositories Deliver BoryptGrab Infostealer to Windows Users

Do Son July 17, 2026 0
Read More Read more about 292 Fake GitHub Repositories Deliver BoryptGrab Infostealer to Windows Users
EU Orders Google to Open Android to Rival AI Assistants and Share Search Data Under the DMA Google DMA ruling opening Android to third-party AI assistants and search data sharing
  • Technology

EU Orders Google to Open Android to Rival AI Assistants and Share Search Data Under the DMA

Do Son July 17, 2026 0
Read More Read more about EU Orders Google to Open Android to Rival AI Assistants and Share Search Data Under the DMA
Farewell NotebookLM: Google Rebrands Its AI Research Tool as Gemini Notebook, Adds Native Code Execution Gemini Notebook rebrand of NotebookLM with native code execution
  • Technology

Farewell NotebookLM: Google Rebrands Its AI Research Tool as Gemini Notebook, Adds Native Code Execution

Do Son July 17, 2026 0
Read More Read more about Farewell NotebookLM: Google Rebrands Its AI Research Tool as Gemini Notebook, Adds Native Code Execution
Chrome Security Update Patches Three Critical Use-After-Free Flaws in CameraCapture, GPU, and Network Chrome security update 150.0.7871.128 critical use-after-free vulnerabilities CameraCapture GPU Network
  • Vulnerability Report

Chrome Security Update Patches Three Critical Use-After-Free Flaws in CameraCapture, GPU, and Network

Do Son July 17, 2026 0
Read More Read more about Chrome Security Update Patches Three Critical Use-After-Free Flaws in CameraCapture, GPU, and Network
Supply Chain Trojan Targets Software Developers Through Project Files Seedworm Espionage Campaign 2026 ChromElevator Stealer DLL Sideloading SIM Swapping Crypto Theft Lazarus Comebacker, Aerospace Espionage Delete PlugX Malware
  • Malware

Supply Chain Trojan Targets Software Developers Through Project Files

Do Son July 17, 2026 0
Read More Read more about Supply Chain Trojan Targets Software Developers Through Project Files
CVE-2026-9770: Information Disclosure Vulnerability Exposes Admin Credentials on TP-Link Kasa Cameras TP-Link Kasa vulnerability CVE-2026-9770 information disclosure flaw on EC70 and EC71 cameras
  • Vulnerability Report

CVE-2026-9770: Information Disclosure Vulnerability Exposes Admin Credentials on TP-Link Kasa Cameras

Do Son July 17, 2026 0
Read More Read more about CVE-2026-9770: Information Disclosure Vulnerability Exposes Admin Credentials on TP-Link Kasa Cameras
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-6875CVSS 9.5
    ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability...
    Admin intel📅 Updated: Jul 18, 2026
  • CVE-2026-39808CVSS 9.8
    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox...
    CISA KEV📅 Added to KEV: Jul 16, 2026
  • CVE-2026-25089CVSS 9.8
    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox...
    CISA KEV📅 Added to KEV: Jul 16, 2026
  • CVE-2026-58644CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    CISA KEV📅 Added to KEV: Jul 16, 2026
  • CVE-2023-4346CVSS 7.5
    KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to...
    CISA KEV📅 Added to KEV: Jul 15, 2026
  • CVE-2026-53362
    In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation...
    Admin intel📅 Updated: Jul 14, 2026
  • CVE-2026-46242CVSS 7.8
    In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file...
    Admin intel📅 Updated: Jul 14, 2026
  • CVE-2026-56155CVSS 7.8
    Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate...
    CISA KEV📅 Added to KEV: Jul 14, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-12701CVSS 9.0
    A path traversal vulnerability was found in pulpcore. The relative_path_validator function only...
  • CVE-2026-64620CVSS 9.8
    FreeRDP before 3.28.0 (affected
  • CVE-2026-16242CVSS 9.4
    A flaw was found in the Konnectivity proxy-server configuration for hosted control...
  • CVE-2026-16235CVSS 9.8
    Crypt::Password versions through 0.28 for Perl generate insecure random values for salts....
  • CVE-2026-13147CVSS 9.1
    The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL...
  • CVE-2026-44359CVSS 10.0
    Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23,...
  • CVE-2026-64162CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: idpf: fix...
  • CVE-2026-64160CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: netfs: Fix...
  • CVE-2026-64150CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner:...
  • CVE-2026-64142CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: ksmbd: close...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.