Skip to content
September 29, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button

Weekly Recap

Weekly CVE report comparing exploited vulnerabilities from Daily Cybersecurity intelligence with the CISA KEV catalog for September 21-27, 2026
  • Weekly Recap

Weekly CVE Report: 2,825 New Flaws and 9 Exploited Bugs (Sept 21-27, 2026)

Do Son September 28, 2026 0
CVE-2023-50164 AEM Forms
  • Weekly Recap

Weekly CVE Report: 4,378 New Flaws and 10 Exploited Bugs

Do Son September 21, 2026 0
Weekly CVE report chart comparing Daily Cybersecurity exploited vulnerabilities against the CISA KEV catalog
  • Weekly Recap

Daily Cybersecurity Flagged 9 Exploited Flaws Before CISA KEV

Do Son September 14, 2026 0
This weekly CVE report covers 10 exploited vulnerabilities added to CISA KEV and 2,316 new CVEs from Aug 31 to Sep 6, 2026. Patch fast.
  • Weekly Recap

Weekly CVE Report: Daily Cybersecurity Beats CISA KEV on Exploited Flaws

Do Son September 7, 2026 0
Weekly CVE report dashboard showing new vulnerabilities and CISA KEV exploited flaws for the week
  • Weekly Recap

Weekly CVE Report: 11 Exploited Flaws Added to KEV

Do Son August 31, 2026 0

Tech News

Codex interface displaying the new ChatGPT Pro 20x subscription tier and API pricing adjustments
  • Technology

Codex Revamps and Reopens the ChatGPT Pro 20x Tier

Do Son September 29, 2026 0
OpenAI GPT-6.1 Astra concept showing AI authorization boundaries and model safety concerns
  • Technology

OpenAI Delays GPT-6.1 Astra Release Over Safety Concerns

Do Son September 29, 2026 0
ChromeOS logo fading into the new Android-based Googlebook OS interface
  • Technology

Google Outlines ChromeOS Sunset and Transition Plan

Do Son September 29, 2026 0
Abstract visualization of a persistent AI agent operating in the background
  • Technology

OpenAI to Unveil Project ‘O’ at DevDay

Do Son September 28, 2026 0

Vulnerability

Chrome security update 154.0.8037.92 fixing 33 flaws, including critical ANGLE buffer overflow CVE-2026-102331 and V8 type confusion bugs
  • Vulnerability Report

Chrome Security Update Fixes 33 Flaws, Including Critical ANGLE Bug CVE-2026-102331

Do Son September 29, 2026 0
MikroTik RouterOS vulnerability CVE-2026-84411, an unauthenticated integer underflow in the web management service enabling root remote code execution
  • Vulnerability Report

Critical MikroTik RouterOS Flaw CVE-2026-84411 Allows Unauthenticated Root RCE

Do Son September 29, 2026 0
Toptech TMS7 vulnerabilities in the CISA ICS advisory, including CVSS 10.0 flaw CVE-2026-71379 affecting TMS7 and TopHAT terminal management systems
  • Vulnerability Report

CISA Warns of 10 Toptech TMS7 and TopHAT Vulnerabilities, One Rated CVSS 10.0

Do Son September 29, 2026 0
OpenSSL vulnerabilities fixed in the September 29, 2026 advisory, including the high-severity DTLS flaw CVE-2026-84782 and X.509 use-after-free CVE-2026-84783
  • Vulnerability Report

OpenSSL Patches 14 Vulnerabilities, Including High-Severity DTLS Memory Leak

Do Son September 29, 2026 0

Cyber Security

ShinyHunters Renews Oracle PeopleSoft Attacks With One-Character WAF Bypass North Korean hackers behind open-source supply chain attacks on axios, debug, and chalk NPM packages
  • Cybercriminals

ShinyHunters Renews Oracle PeopleSoft Attacks With One-Character WAF Bypass

September 29, 2026 0
Operation Master Turns GlobalProtect Breaches Into Brazilian Invoice Fraud Operation Master invoice fraud pipeline from GlobalProtect VPN breach to fake utility bills
  • Cybercriminals

Operation Master Turns GlobalProtect Breaches Into Brazilian Invoice Fraud

September 29, 2026 0
Konni Launches Operation Conflict Compass Against Ukraine Diagram of Konni Operation Conflict Compass showing the Operation Conflict Compass infection chain
  • Cybercriminals

Konni Launches Operation Conflict Compass Against Ukraine

September 28, 2026 0
Kiteworks Mandates Global Precautionary Server Shutdown Kiteworks secure file transfer interface depicting a precautionary server shutdown
  • Cybercriminals

Kiteworks Mandates Global Precautionary Server Shutdown

September 28, 2026 0

Malware Alert

New MacSync macOS Infostealer Targets Crypto Wallets Diagram of the new MacSync macOS infostealer showing how the MacSync macOS infostealer infects Apple devices
  • Malware

New MacSync macOS Infostealer Targets Crypto Wallets

September 29, 2026 0
SectopRAT Malware Variant Hidden in Legitimate Software Python NodeStealer malware upgraded with keylogging, clipboard monitoring, screenshot capture, and dual Telegram bot C2 for Facebook data theft
  • Malware

SectopRAT Malware Variant Hidden in Legitimate Software

September 29, 2026 0
Android Toll Fraud Malware Found on Google Play Diagram of the Google Play Android toll fraud malware infection chain showing how Android toll fraud malware executes
  • Malware

Android Toll Fraud Malware Found on Google Play

September 29, 2026 0
PamStealer macOS Malware Spreads via Fake Wavel Crypto App Diagram of the new PamStealer macOS infostealer showing how the PamStealer macOS infostealer infects Apple devices
  • Malware

PamStealer macOS Malware Spreads via Fake Wavel Crypto App

September 28, 2026 0

Data Leak

Meta Muse Secretly Used Humans for AI Phone Calls Meta Muse AI agent phone calling feature secretly handed off to human contractors
  • Data Leak

Meta Muse Secretly Used Humans for AI Phone Calls

September 24, 2026 0
ShinyHunters Syndicate Alleges Major FBI Network Compromise Bling Libra
  • Data Leak

ShinyHunters Syndicate Alleges Major FBI Network Compromise

September 24, 2026 0
Leaked GitHub App Private Keys Expose Critical Infrastructure Diagram showing leaked GitHub App private keys and how GitHub App private keys compromise repositories
  • Data Leak

Leaked GitHub App Private Keys Expose Critical Infrastructure

September 23, 2026 0
OpenAI’s Project Lily Employs Humans to Read ChatGPT Chats Project Lily workspace illustration showing contractors reviewing ChatGPT user dialogues
  • Data Leak

OpenAI’s Project Lily Employs Humans to Read ChatGPT Chats

September 16, 2026 0
Daily CyberSecurity Launches CVE Alerts, an Automated Vulnerability Intelligence Service for IT and Security Teams Daily CyberSecurity, the team behind the CVE-Watchtower vulnerability tracking platform on securityonline.info, today announced the general availability of CVE Alerts, a subscription service
  • Announcement

Daily CyberSecurity Launches CVE Alerts, an Automated Vulnerability Intelligence Service for IT and Security Teams

ddos-admin September 29, 2026 0
Read More Read more about Daily CyberSecurity Launches CVE Alerts, an Automated Vulnerability Intelligence Service for IT and Security Teams
8 Best AI Workspace Security Tools for Hybrid Work Environments Read our weekly threat intelligence report for mid-August 2026.
  • Technique

8 Best AI Workspace Security Tools for Hybrid Work Environments

Do Son September 29, 2026 0
Read More Read more about 8 Best AI Workspace Security Tools for Hybrid Work Environments
macOS SMB Kernel Flaw CVE-2026-84543: Details and PoC Exploit Released macOS SMB kernel vulnerability CVE-2026-84543 in SMBFS, with technical details and proof-of-concept exploit released by researcher Peter Malone
  • Vulnerability Report

macOS SMB Kernel Flaw CVE-2026-84543: Details and PoC Exploit Released

Do Son September 29, 2026 0
Read More Read more about macOS SMB Kernel Flaw CVE-2026-84543: Details and PoC Exploit Released
Octopus Server Flaw CVE-2026-101169 Allows Code Execution via Insecure Deserialization Octopus Server vulnerability CVE-2026-101169 insecure JSON deserialization enabling code execution in the Octopus Deploy server process
  • Vulnerability Report

Octopus Server Flaw CVE-2026-101169 Allows Code Execution via Insecure Deserialization

Do Son September 29, 2026 0
Read More Read more about Octopus Server Flaw CVE-2026-101169 Allows Code Execution via Insecure Deserialization
Exploited Citrix NetScaler Flaw CVE-2026-88771: Details and PoC Now Public Citrix NetScaler CVE-2026-88771 pre-auth command injection exploited in the wild, with technical details and a proof-of-concept detection tool released by watchTowr
  • Vulnerability Report

Exploited Citrix NetScaler Flaw CVE-2026-88771: Details and PoC Now Public

Do Son September 29, 2026 0
Read More Read more about Exploited Citrix NetScaler Flaw CVE-2026-88771: Details and PoC Now Public
Apache Karaf Vulnerabilities Let Low-Privilege Users Reach Admin and Code Execution Apache Karaf vulnerabilities CVE-2026-92142, CVE-2026-91012 and CVE-2026-91048 allowing privilege escalation and remote code execution, fixed in Karaf 4.4.12
  • Vulnerability Report

Apache Karaf Vulnerabilities Let Low-Privilege Users Reach Admin and Code Execution

Do Son September 29, 2026 0
Read More Read more about Apache Karaf Vulnerabilities Let Low-Privilege Users Reach Admin and Code Execution
wolfSSL 5.9.4 Fixes 10 Vulnerabilities, Including TLS Authentication Bypass Flaws wolfSSL vulnerabilities fixed in release 5.9.4, including TLS authentication bypass flaws CVE-2026-93302, CVE-2026-89102 and CVE-2026-89136
  • Vulnerability Report

wolfSSL 5.9.4 Fixes 10 Vulnerabilities, Including TLS Authentication Bypass Flaws

Do Son September 29, 2026 0
Read More Read more about wolfSSL 5.9.4 Fixes 10 Vulnerabilities, Including TLS Authentication Bypass Flaws
Critical LXD Vulnerabilities Let Container Users Write Files as Root on the Host Critical LXD vulnerabilities CVE-2026-87799, CVE-2026-85185 and CVE-2026-85526 enabling root file writes on the host through migration and btrfs backup restore
  • Vulnerability Report

Critical LXD Vulnerabilities Let Container Users Write Files as Root on the Host

Do Son September 29, 2026 0
Read More Read more about Critical LXD Vulnerabilities Let Container Users Write Files as Root on the Host
Authlib Signature Bypass Vulnerability Exposes Apps Diagram showing the Authlib signature bypass vulnerability attack path and CVE-2026-96760 forge process
  • Vulnerability Report

Authlib Signature Bypass Vulnerability Exposes Apps

Do Son September 29, 2026 0
Read More Read more about Authlib Signature Bypass Vulnerability Exposes Apps
Critical WatchGuard AP Vulnerabilities Patched in Version 3.4.8 Diagram showing the WatchGuard AP vulnerabilities and OS command injection attack chain
  • Vulnerability Report

Critical WatchGuard AP Vulnerabilities Patched in Version 3.4.8

Do Son September 29, 2026 0
Read More Read more about Critical WatchGuard AP Vulnerabilities Patched in Version 3.4.8
Portal for ArcGIS Vulnerabilities Fixed in September Update Diagram illustrating Portal for ArcGIS vulnerabilities and CVE-2026-69227 attack paths
  • Vulnerability Report

Portal for ArcGIS Vulnerabilities Fixed in September Update

Do Son September 29, 2026 0
Read More Read more about Portal for ArcGIS Vulnerabilities Fixed in September Update
Exploited Apple Zero-Day Vulnerability Patched Diagram showing the exploited Apple zero-day vulnerability and CVE-2026-86950 attack path
  • Vulnerability Report

Exploited Apple Zero-Day Vulnerability Patched

Do Son September 29, 2026 0
Read More Read more about Exploited Apple Zero-Day Vulnerability Patched
PostgreSQL RCE Vulnerability Details and PoC Disclosed Diagram explaining the critical PostgreSQL RCE vulnerability and CVE-2026-15742 attack path
  • Vulnerability Report

PostgreSQL RCE Vulnerability Details and PoC Disclosed

Do Son September 29, 2026 0
Read More Read more about PostgreSQL RCE Vulnerability Details and PoC Disclosed
Linux Container Escape Flaw Details and PoC Disclosed Diagram of a critical Linux container escape flaw and CVE-2026-80521 attack path
  • Vulnerability Report

Linux Container Escape Flaw Details and PoC Disclosed

Do Son September 28, 2026 0
Read More Read more about Linux Container Escape Flaw Details and PoC Disclosed
RemControl Android Banking Trojan Steals Bank PINs RemControl Android banking trojan blocking Play Protect, RemControl malware fake TVTap app delivery
  • Malware

RemControl Android Banking Trojan Steals Bank PINs

Do Son September 28, 2026 0
Read More Read more about RemControl Android Banking Trojan Steals Bank PINs
Optimizing Windows 11 by Disabling 8.3 Short File Names Windows 11 File Explorer interface demonstrating optimized file operation performance
  • Windows

Optimizing Windows 11 by Disabling 8.3 Short File Names

Do Son September 28, 2026 0
Read More Read more about Optimizing Windows 11 by Disabling 8.3 Short File Names
GitHub Blocks New Outlook and Hotmail Sign-Ups GitHub login screen displaying an email verification error for an Outlook address
  • Technology

GitHub Blocks New Outlook and Hotmail Sign-Ups

Do Son September 28, 2026 0
Read More Read more about GitHub Blocks New Outlook and Hotmail Sign-Ups
Windows 11 Enhances Mouse Visibility and Customization Windows11-hover
  • Windows

Windows 11 Enhances Mouse Visibility and Customization

Do Son September 28, 2026 0
Read More Read more about Windows 11 Enhances Mouse Visibility and Customization
Canonical Overhauls Ubuntu Kernel Release Cycle Ubuntu Linux kernel update pipeline demonstrating the new overlapping two-week cycle
  • Linux

Canonical Overhauls Ubuntu Kernel Release Cycle

Do Son September 28, 2026 0
Read More Read more about Canonical Overhauls Ubuntu Kernel Release Cycle
Weekly CVE Report: 2,825 New Flaws and 9 Exploited Bugs (Sept 21-27, 2026) Weekly CVE report comparing exploited vulnerabilities from Daily Cybersecurity intelligence with the CISA KEV catalog for September 21-27, 2026
  • Weekly Recap

Weekly CVE Report: 2,825 New Flaws and 9 Exploited Bugs (Sept 21-27, 2026)

Do Son September 28, 2026 0
Read More Read more about Weekly CVE Report: 2,825 New Flaws and 9 Exploited Bugs (Sept 21-27, 2026)
TraderTraitor macOS Backdoors Target IT Service Firms CloudComputating - QSC framework
  • Cybercriminals

TraderTraitor macOS Backdoors Target IT Service Firms

Do Son September 28, 2026 0
Read More Read more about TraderTraitor macOS Backdoors Target IT Service Firms
CVE-2026-43786: macOS CoreServices Vulnerability PoC Disclosed Diagram showing the exploited macOS CoreServices vulnerability attack path
  • Vulnerability Report

CVE-2026-43786: macOS CoreServices Vulnerability PoC Disclosed

Do Son September 28, 2026 0
Read More Read more about CVE-2026-43786: macOS CoreServices Vulnerability PoC Disclosed
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-88771
    Remote code execution due to improper input validation that can allow an unauthenticated attacker to execute arbitrary commands.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 23, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-84411CVSS 9.8
    The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling...
    Admin intel📅 Updated: Sep 29, 2026
  • CVE-2026-69854CVSS 9.0
    Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a network.
    📅 Updated: Sep 29, 2026
  • CVE-2026-102334CVSS 9.1
    Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses...
    📅 Updated: Sep 29, 2026
  • CVE-2026-101260CVSS 9.4
    A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. Affected by this issue is some unknown functionality of...
    📅 Updated: Sep 29, 2026
  • CVE-2026-68954CVSS 9.0
    The "pattern" parameter used in search function in the home page of the TMS application is vulnerable to...
    Admin intel📅 Updated: Sep 29, 2026
  • CVE-2026-68068CVSS 9.0
    The "screenID" parameter in the electronic transaction queue viewer feature within the manual transactions section is susceptible to...
    Admin intel📅 Updated: Sep 29, 2026
  • CVE-2026-72507CVSS 9.0
    The "reportType" parameter in the product summary report feature within the balancing reports section is susceptible to a...
    Admin intel📅 Updated: Sep 29, 2026
  • CVE-2026-71379CVSS 10.0
    The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POST...
    Admin intel📅 Updated: Sep 29, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.