Skip to content
October 8, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button

Weekly Recap

Weekly CVE report on exploited vulnerabilities from Daily Cybersecurity and CISA KEV, September 28 to October 4, 2026
  • Weekly Recap

Weekly CVE Report Tracks 2,652 New Flaws and Seven Exploited Vulnerabilities (Sept. 28 – Oct. 4, 2026)

Do Son October 5, 2026 0
Weekly CVE report comparing exploited vulnerabilities from Daily Cybersecurity intelligence with the CISA KEV catalog for September 21-27, 2026
  • Weekly Recap

Weekly CVE Report: 2,825 New Flaws and 9 Exploited Bugs (Sept 21-27, 2026)

Do Son September 28, 2026 0
CVE-2023-50164 AEM Forms
  • Weekly Recap

Weekly CVE Report: 4,378 New Flaws and 10 Exploited Bugs

Do Son September 21, 2026 0
Weekly CVE report chart comparing Daily Cybersecurity exploited vulnerabilities against the CISA KEV catalog
  • Weekly Recap

Daily Cybersecurity Flagged 9 Exploited Flaws Before CISA KEV

Do Son September 14, 2026 0
This weekly CVE report covers 10 exploited vulnerabilities added to CISA KEV and 2,316 new CVEs from Aug 31 to Sep 6, 2026. Patch fast.
  • Weekly Recap

Weekly CVE Report: Daily Cybersecurity Beats CISA KEV on Exploited Flaws

Do Son September 7, 2026 0

Tech News

Claude AI chat threats arrest security monitoring
  • Technology

Claude AI Chat Leads to Florida Arrest

Do Son October 8, 2026 0
Chrome JPEG XL support decoding JXL image format
  • Technology

Chrome 155 Defaults to Native JPEG XL Support

Do Son October 8, 2026 0
ICANN new domain applications and AI extensions
  • Technology

ICANN Reveals Massive Surge in AI Domain Name Applications

Do Son October 8, 2026 0
OpenAI math model breakthroughs resolving complex mathematical proofs and AI mathematical proofs
  • Technology

OpenAI Math Model Breakthroughs: AI Solves Centennial Enigmas

Do Son October 8, 2026 0

Vulnerability

IBM DataPower Gateway vulnerabilities CVE-2026-15762 and CVE-2026-16340 remote code execution and CVE-2026-14990 XSS fixed in 11.0.0.3
  • Vulnerability Report

IBM Patches 23 DataPower Gateway Flaws, Including Four Critical Remote Code Execution and XSS Bugs

Do Son October 8, 2026 0
Apache DolphinScheduler vulnerabilities CVE-2026-71896 and CVE-2026-71895 authorization bypass leaking Kubernetes credentials fixed in 3.4.3
  • Vulnerability Report

Apache DolphinScheduler 3.4.3 Fixes Six Authorization Flaws That Leak Passwords and Kubernetes Credentials

Do Son October 8, 2026 0
wolfSSH vulnerabilities CVE-2026-16516 ECDSA host key bypass and CVE-2026-83540 Windows logon token flaw fixed in wolfSSH 1.6.0
  • Vulnerability Report

wolfSSH 1.6.0 Fixes Five Flaws, Including Critical Host Key Bypass CVE-2026-16516

Do Son October 8, 2026 0
Cisco Finesse vulnerability CVE-2026-20362 unauthenticated SSRF in contact center web interface publicly disclosed
  • Vulnerability Report

Cisco Finesse SSRF Flaw CVE-2026-20362 Publicly Disclosed, With Fixes Not Due Until 2027

Do Son October 8, 2026 0

Cyber Security

Iran-Linked Hackers Pose as Dubai Airports Recruiters in Blinder Tunnel Campaign Against Iraq Blinder Tunnel campaign using a fake Dubai Airports coding test to deliver ShelbyLoader V2
  • Cybercriminals

Iran-Linked Hackers Pose as Dubai Airports Recruiters in Blinder Tunnel Campaign Against Iraq

October 8, 2026 0
ccTLD Registry Hijacks Let Attackers Mint TLS Certs ccTLD registry hijack diagram showing altered DNS records used to obtain unauthorized TLS certificates for .gh, .sl, and .as domains
  • Cybercriminals

ccTLD Registry Hijacks Let Attackers Mint TLS Certs

October 7, 2026 0
ShinyHunters Hacker Arrest in Jordan Aids FBI Probe ShinyHunters hacker arrest in Jordan as an alleged member cooperates with the FBI ShinyHunters investigation
  • Cybercriminals

ShinyHunters Hacker Arrest in Jordan Aids FBI Probe

October 5, 2026 0
Warlock Ransomware Group Hits Water and Telecom Operators Through SharePoint Flaws Warlock ransomware attack chain exploiting SharePoint vulnerabilities to hit critical infrastructure
  • Cybercriminals

Warlock Ransomware Group Hits Water and Telecom Operators Through SharePoint Flaws

October 5, 2026 0

Malware Alert

Rogue AI Agents Hijacked urlquery Scan Browsers to Reach Russian Bankruptcy Records Rogue AI agents abusing the urlquery remote browser and VNC to bypass sandbox restrictions
  • Malware

Rogue AI Agents Hijacked urlquery Scan Browsers to Reach Russian Bankruptcy Records

October 8, 2026 0
Four Attacker Clusters Exploit Citrix NetScaler Flaw CVE-2026-88771 to Plant Web Shells CVE-2026-88771 exploitation by four clusters deploying NetScaler web shells, Platypus agents, and reverse shells
  • Malware

Four Attacker Clusters Exploit Citrix NetScaler Flaw CVE-2026-88771 to Plant Web Shells

October 7, 2026 0
ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into Proxy Nodes Diagram showing the MemTensor MemOS compromise details and how the MemTensor MemOS compromise affects developers
  • Malware

ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into Proxy Nodes

October 6, 2026 0
Moroccan Intelligence Deploys Vast Surveillance Panopticon Amnesty International exposing the Moroccan DGST surveillance network and Pegasus spyware infections
  • Malware

Moroccan Intelligence Deploys Vast Surveillance Panopticon

October 5, 2026 0

Data Leak

Trump Mobile Data Breach Exposes 3,615 Customers in BYOD Leak leak
  • Data Leak

Trump Mobile Data Breach Exposes 3,615 Customers in BYOD Leak

October 6, 2026 0
Denmark CPR Data Breach Exposes CPR Numbers of 8.8 Million People Denmark CPR data breach - CPR numbers exposed for 8.8 million people in the national register
  • Data Leak

Denmark CPR Data Breach Exposes CPR Numbers of 8.8 Million People

October 5, 2026 0
AI Coding Agents Leak 13,000 Internal Screenshots to Public GitHub Repos AI agent screenshot leak in PixelLeak research showing internal images pushed to public GitHub repos
  • Data Leak

AI Coding Agents Leak 13,000 Internal Screenshots to Public GitHub Repos

September 30, 2026 0
Meta Muse Secretly Used Humans for AI Phone Calls Meta Muse AI agent phone calling feature secretly handed off to human contractors
  • Data Leak

Meta Muse Secretly Used Humans for AI Phone Calls

September 24, 2026 0
Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code insignary_logo_1791211062PNrqmaRSIt
  • Press Release

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

cybernewswire October 8, 2026 0
Read More Read more about Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code
Google Adds Native Markdown Support Google Markdown native support Drive Docs collaboration
  • Technology

Google Adds Native Markdown Support

Do Son October 8, 2026 0
Read More Read more about Google Adds Native Markdown Support
Google SynthID AI Detector Now Open to the Public Google SynthID AI detector interface scanning for deepfakes and AI-generated content
  • Technology

Google SynthID AI Detector Now Open to the Public

Do Son October 8, 2026 0
Read More Read more about Google SynthID AI Detector Now Open to the Public
Windows Hybrid Intelligence and the New AI Search Menu Microsoft Windows 11 search menu integrating local AI agents
  • Windows

Windows Hybrid Intelligence and the New AI Search Menu

Do Son October 8, 2026 0
Read More Read more about Windows Hybrid Intelligence and the New AI Search Menu
Google Playground AI Platform: The Future of Game Creation Google Home MCP support letting AI agents like Claude control Nest and Matter smart home devices
  • Technology

Google Playground AI Platform: The Future of Game Creation

Do Son October 8, 2026 0
Read More Read more about Google Playground AI Platform: The Future of Game Creation
VMware Workstation and Fusion VMXNET3 Flaw CVE-2026-59346 Detailed With Public PoC Exploit VMware VMXNET3 vulnerability CVE-2026-59346 integer overflow guest-to-host escape in Workstation and Fusion with public PoC exploit
  • Vulnerability Report

VMware Workstation and Fusion VMXNET3 Flaw CVE-2026-59346 Detailed With Public PoC Exploit

Do Son October 8, 2026 0
Read More Read more about VMware Workstation and Fusion VMXNET3 Flaw CVE-2026-59346 Detailed With Public PoC Exploit
Splunk Patches 22 Flaws in Splunk Enterprise, Including Critical Patroni API Command Execution Bug Splunk Enterprise vulnerabilities CVE-2026-76268 Patroni REST API command execution and CVE-2026-76281 fixed in 10.4.3 and 10.2.7
  • Vulnerability Report

Splunk Patches 22 Flaws in Splunk Enterprise, Including Critical Patroni API Command Execution Bug

Do Son October 8, 2026 0
Read More Read more about Splunk Patches 22 Flaws in Splunk Enterprise, Including Critical Patroni API Command Execution Bug
Top Industrial IoT & Embedded Firmware Development Partners ISO 27001
  • Technique

Top Industrial IoT & Embedded Firmware Development Partners

Do Son October 8, 2026 0
Read More Read more about Top Industrial IoT & Embedded Firmware Development Partners
Hackers Exploit Ninja Forms and WPC Product Bundles XSS Flaws to Plant Hidden WordPress Admins WordPress XSS campaign exploiting Ninja Forms CVE-2026-94504 and WPC Product Bundles CVE-2026-93836 to create hidden admin accounts
  • Vulnerability Report

Hackers Exploit Ninja Forms and WPC Product Bundles XSS Flaws to Plant Hidden WordPress Admins

Do Son October 8, 2026 0
Read More Read more about Hackers Exploit Ninja Forms and WPC Product Bundles XSS Flaws to Plant Hidden WordPress Admins
Cisco Fixes CVSS 10 License On-Prem Flaw and Ships Hardening Releases for APIC and Meraki Cisco License On-Prem vulnerabilities CVE-2026-76482 and CVE-2026-20328 plus APIC CVE-2026-76498 and Meraki hardening release fixes
  • Vulnerability Report

Cisco Fixes CVSS 10 License On-Prem Flaw and Ships Hardening Releases for APIC and Meraki

Do Son October 7, 2026 0
Read More Read more about Cisco Fixes CVSS 10 License On-Prem Flaw and Ships Hardening Releases for APIC and Meraki
Cisco Fixes Critical NX-API Flaw CVE-2026-76471 and Ships NX-OS Hardening Release for Six Bug Classes Cisco NX-OS vulnerabilities CVE-2026-76471 NX-API remote code execution and CVE-2026-76455 fixed in October 2026 hardening release
  • Vulnerability Report

Cisco Fixes Critical NX-API Flaw CVE-2026-76471 and Ships NX-OS Hardening Release for Six Bug Classes

Do Son October 7, 2026 0
Read More Read more about Cisco Fixes Critical NX-API Flaw CVE-2026-76471 and Ships NX-OS Hardening Release for Six Bug Classes
Cisco Patches Four Critical Nexus Switch Flaws That Allow Root-Level Remote Code Execution Cisco Nexus vulnerabilities CVE-2026-76485 and CVE-2026-76465 NGOAM and MPLS OAM remote code execution on Nexus 3000 and 9000 switches
  • Vulnerability Report

Cisco Patches Four Critical Nexus Switch Flaws That Allow Root-Level Remote Code Execution

Do Son October 7, 2026 0
Read More Read more about Cisco Patches Four Critical Nexus Switch Flaws That Allow Root-Level Remote Code Execution
Argo CD Patches Four Critical CVSS 9.9 Flaws Affecting the Repo-Server and AppProject Controls Argo CD vulnerabilities CVE-2026-77459 AppProject bypass and repo-server command execution flaws fixed in v3.5.4
  • Vulnerability Report

Argo CD Patches Four Critical CVSS 9.9 Flaws Affecting the Repo-Server and AppProject Controls

Do Son October 7, 2026 0
Read More Read more about Argo CD Patches Four Critical CVSS 9.9 Flaws Affecting the Repo-Server and AppProject Controls
Apache Jackrabbit Fixes Critical WebDAV Session Hijack Flaw CVE-2026-92414 Apache Jackrabbit vulnerabilities CVE-2026-92414 WebDAV session hijack and CVE-2026-92415 unsafe reflection fixed in 2.23.6
  • Vulnerability Report

Apache Jackrabbit Fixes Critical WebDAV Session Hijack Flaw CVE-2026-92414

Do Son October 7, 2026 0
Read More Read more about Apache Jackrabbit Fixes Critical WebDAV Session Hijack Flaw CVE-2026-92414
Gitea Fixes 27 Security Flaws Across 28.0.0 and 28.1.0, Including SSRF and Account Takeover Bugs Gitea security update 28.0.0 and 28.1.0 fixes SSRF flaw CVE-2026-101027 installer takeover CVE-2026-96404 and SSH key bug CVE-2026-103059
  • Vulnerability Report

Gitea Fixes 27 Security Flaws Across 28.0.0 and 28.1.0, Including SSRF and Account Takeover Bugs

Do Son October 7, 2026 0
Read More Read more about Gitea Fixes 27 Security Flaws Across 28.0.0 and 28.1.0, Including SSRF and Account Takeover Bugs
CVE-2026-21589 Exploited in the Wild as Atlassian File Read Flaw Details and PoC Go Public CVE-2026-21589 exploitation in the wild targets Atlassian Jira Confluence and Bitbucket arbitrary file read vulnerability with public PoC
  • Vulnerability Report

CVE-2026-21589 Exploited in the Wild as Atlassian File Read Flaw Details and PoC Go Public

Do Son October 7, 2026 0
Read More Read more about CVE-2026-21589 Exploited in the Wild as Atlassian File Read Flaw Details and PoC Go Public
Anthropic IPO Filing Reveals Amodei’s $18M Pay Anthropic IPO draft prospectus revealing executive pay and Dario Amodei compensation ahead of a possible listing
  • Technology

Anthropic IPO Filing Reveals Amodei’s $18M Pay

Do Son October 7, 2026 0
Read More Read more about Anthropic IPO Filing Reveals Amodei’s $18M Pay
Elastic Patches 14 Flaws in Elasticsearch, Kibana and Elastic Defend Elastic Stack vulnerabilities CVE-2026-102406 and CVE-2026-103007 in Kibana and Elasticsearch fixed in 8.19.23, 9.4.8 and 9.5.5
  • Vulnerability Report

Elastic Patches 14 Flaws in Elasticsearch, Kibana and Elastic Defend

Do Son October 7, 2026 0
Read More Read more about Elastic Patches 14 Flaws in Elasticsearch, Kibana and Elastic Defend
ASUS Patches Four Router Firmware Flaws, Including Two Critical Bugs Rated CVSS 9.3 ASUS router vulnerabilities CVE-2026-14911 and CVE-2026-19386 critical cross-site scripting and code execution flaws fixed in firmware update
  • Vulnerability Report

ASUS Patches Four Router Firmware Flaws, Including Two Critical Bugs Rated CVSS 9.3

Do Son October 7, 2026 0
Read More Read more about ASUS Patches Four Router Firmware Flaws, Including Two Critical Bugs Rated CVSS 9.3
ASUSTOR Fixes Critical ADM Flaw CVE-2026-105324 That Lets Attackers Read NAS Files Without Login ASUSTOR ADM vulnerability CVE-2026-105324 unauthenticated arbitrary file read on NAS fixed in ADM 5.1.4.RM62 and 4.3.3.RY62
  • Vulnerability Report

ASUSTOR Fixes Critical ADM Flaw CVE-2026-105324 That Lets Attackers Read NAS Files Without Login

Do Son October 7, 2026 0
Read More Read more about ASUSTOR Fixes Critical ADM Flaw CVE-2026-105324 That Lets Attackers Read NAS Files Without Login
HPE Fixes Six Critical AOS-Switch Flaws Enabling Unauthenticated RCE and Admin Access HPE AOS-Switch vulnerabilities CVE-2026-76744 and CVE-2026-76742 unauthenticated remote code execution and authentication bypass fixed in AOS-S 16.11.0032
  • Vulnerability Report

HPE Fixes Six Critical AOS-Switch Flaws Enabling Unauthenticated RCE and Admin Access

Do Son October 7, 2026 0
Read More Read more about HPE Fixes Six Critical AOS-Switch Flaws Enabling Unauthenticated RCE and Admin Access
Handlebars.js RCE Flaws Disclosed With Public PoC, Threatening 172 Million Monthly Downloads Handlebars.js vulnerability CVE-2026-106445 and CVE-2026-106446 remote code execution flaws with public PoC fixed in version 4.7.10
  • Vulnerability Report

Handlebars.js RCE Flaws Disclosed With Public PoC, Threatening 172 Million Monthly Downloads

Do Son October 7, 2026 0
Read More Read more about Handlebars.js RCE Flaws Disclosed With Public PoC, Threatening 172 Million Monthly Downloads
Next Page ❯

Search

Translation

CVE ALERTS
πŸ“ˆ

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

πŸ›‘οΈ

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

πŸ™

GitHub Issues
Auto-create alert tickets without duplication.

πŸ“¬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

πŸ”€

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days β†’

🚨 Active Exploits in the Wild

  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-93836CVSS 7.2
    The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \'qty\'...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-21589CVSS 9.3
    This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-107459CVSS 9.3
    The SecuShare Pro developed by Openfind has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary...
    📅 Updated: Oct 8, 2026
  • CVE-2026-14990CVSS 9.3
    IBM DataPower Gateway 10.6.0.0 through 10.6.0.10Β is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed...
    📅 Updated: Oct 8, 2026
  • CVE-2026-14991CVSS 9.8
    IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable...
    📅 Updated: Oct 8, 2026
  • CVE-2026-17635CVSS 9.1
    IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due...
    📅 Updated: Oct 8, 2026
  • CVE-2026-102106CVSS 9.1
    Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative service in Kiteworks Email Protection Gateway...
    📅 Updated: Oct 8, 2026
  • CVE-2026-102105CVSS 9.1
    Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery...
    📅 Updated: Oct 8, 2026
  • CVE-2026-102104CVSS 9.1
    Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery...
    📅 Updated: Oct 8, 2026
  • CVE-2026-102103CVSS 9.1
    Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery...
    📅 Updated: Oct 8, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
Β© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.