Skip to content
July 26, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
OCRFix: When Fake CAPTCHAs, AI, and Blockchains Collide to Build a Botnet OCRFix Malware Campaign ClickFix Tactic
  • Malware

OCRFix: When Fake CAPTCHAs, AI, and Blockchains Collide to Build a Botnet

Do Son March 2, 2026 0
Read More Read more about OCRFix: When Fake CAPTCHAs, AI, and Blockchains Collide to Build a Botnet
CVE-2026-27728 (CVSS 10): Critical Command Injection Flaw in OneUptime Probe Enables Full Server Takeover OneUptime RCE CVE-2026-27728
  • Vulnerability Report

CVE-2026-27728 (CVSS 10): Critical Command Injection Flaw in OneUptime Probe Enables Full Server Takeover

Do Son March 2, 2026 0
Read More Read more about CVE-2026-27728 (CVSS 10): Critical Command Injection Flaw in OneUptime Probe Enables Full Server Takeover
Critical Path Traversal Flaw in basic-ftp Exposes Node.js Apps to Arbitrary File Writes shell-quote command injection AI-Driven Vulnerabilities Q1 2026 Cyber Threats vm2 Sandbox Escape Node.js RCE upKeeper Privilege Escalation CVE-2026-2449 Pharos Controls Vulnerability Root Access Exploit Cybersecurity Vulnerability Roundup CVSS 10.0 Flaws Shadow Archives CVE-2026-0866 MS-Agent Prompt Injection CVE-2026-2256 basic-ftp Path Traversal CVE-2026-27699 telnetd Root Vulnerability CVE-1999-0073 Regression USR-W610 Vulnerabilities End-of-Life IoT Security IceWarp Security Update IceWarp Vulnerabilities Airleader Master Vulnerability CVE-2026-1358 ZLAN5143D Vulnerability CISA ICS Advisory Acronis Cyber Protect Vulnerability CVE-2025-30411 WAGO 852 Vulnerability OT Network Security SandboxJS Vulnerability Sandbox Escape (CVSS 10.0) Kubernetes Local Path Provisioner CVE-2025-62878 CISA Unresponsive Vendors Avation & RISS Vulnerabilities KiloView Vulnerability CVE-2026-1453 OpenClaw RCE vulnerability Johnson Controls Vulnerability CVE-2025-26385 SandboxJS Vulnerability CVE-2026-23830 ibaPDA Vulnerability CVE-2025-14988 Protobuf Vulnerability CVE-2026-0994 AVEVA Process Optimization Vulnerability CVE-2025-61937 ConnectWise PSA Vulnerability CVE-2026-0695 Aruba VIA Vulnerability CVE-2025-37186 aiohttp v3.13.3, Denial of Service (DoS) SmarterMail RCE, CVE-2025-52691 Airoha RACE, Headphone Jacking HPE OneView RCE CVE-2025-37164 FreePBX Auth Bypass, PBX Takeover ScreenConnect Config Flaw, Untrusted Extensions Ruby SAML Auth Bypass, XML Parser Differential Devolutions SQL Injection, Password Manager Flaw Vivotek Unauthenticated RCE, EOL IP Camera Flaw Lynx+ Critical Flaw, Unauthenticated Reset Firebox Default Credentials, CVE-2025-59396 Veeder-Root RCE, Critical ATG Flaw ArcGIS Server SQLi Watchdoc RCE, CVE-2025-58384 Delta DIALink Daikin Security Gateway, authentication bypass Frostbyte10, industrial controller security SunPower, vulnerability Ubiquiti UniFi Connect, EV Station Vulnerabilities Adobe Experience Manager, RCE Vulnerability UniFi Access, Command Injection LDAPNightmare - CVE-2025-1316
  • Vulnerability Report

Critical Path Traversal Flaw in basic-ftp Exposes Node.js Apps to Arbitrary File Writes

Do Son March 2, 2026 0
Read More Read more about Critical Path Traversal Flaw in basic-ftp Exposes Node.js Apps to Arbitrary File Writes
Steering the Server: Critical 9.2 Severity SSRF Flaw in Angular SSR Allows Internal Network Probing Angular hostname hijacking vulnerability Angular SSRF Origin Hijacking Angular XSS Vulnerability CVE-2026-32635 Angular i18n XSS CVE-2026-27970 Angular SSR SSRF CVE-2026-27739 Angular Vulnerability CVE-2026-22610 CVE-2025-59052 Angular security Angular XSS Bypass, SVG Injection
  • Vulnerability Report

Steering the Server: Critical 9.2 Severity SSRF Flaw in Angular SSR Allows Internal Network Probing

Do Son March 2, 2026 0
Read More Read more about Steering the Server: Critical 9.2 Severity SSRF Flaw in Angular SSR Allows Internal Network Probing
The New Voice of Fraud: Cybercrime ‘Supergroup’ Recruits Female Callers to Breach Corporate IT Help Desks CRussian Market, "Fly" (Flyded) hange Healthcare Cyberattack - CVE-2024-50603 Exploit
  • Cybercriminals

The New Voice of Fraud: Cybercrime ‘Supergroup’ Recruits Female Callers to Breach Corporate IT Help Desks

Do Son March 2, 2026 0
Read More Read more about The New Voice of Fraud: Cybercrime ‘Supergroup’ Recruits Female Callers to Breach Corporate IT Help Desks
WPA Hash Analysis: Turning Bitcoin’s 50% Drop into Cloud Mining Opportunities for Investors Screenshot_20260303_002337_Docs
  • Technique

WPA Hash Analysis: Turning Bitcoin’s 50% Drop into Cloud Mining Opportunities for Investors

Do Son March 2, 2026 0
Read More Read more about WPA Hash Analysis: Turning Bitcoin’s 50% Drop into Cloud Mining Opportunities for Investors
Google Dismantles UNC2814’s Global Espionage Network Fueled by Google Sheets UNC2814 Espionage GRIDTIDE Backdoor
  • Cybercriminals

Google Dismantles UNC2814’s Global Espionage Network Fueled by Google Sheets

Do Son March 2, 2026 0
Read More Read more about Google Dismantles UNC2814’s Global Espionage Network Fueled by Google Sheets
Critical CISA Advisory Unmasks Severe Flaws in EV2GO Charging Networks EV2GO Charging Platform ICSA-26-057-04 Lazarus Group, Crypto Hacks LazyStealer
  • Vulnerability Report

Critical CISA Advisory Unmasks Severe Flaws in EV2GO Charging Networks

Do Son February 28, 2026 0
Read More Read more about Critical CISA Advisory Unmasks Severe Flaws in EV2GO Charging Networks
Massive SonicWall Reconnaissance Campaign Signals Imminent Ransomware Strikes SonicWall Reconnaissance Akira Ransomware residential proxy malware TraderTraitor BreachForums Honeypot, French Interior Ministry Leak
  • Cybercriminals

Massive SonicWall Reconnaissance Campaign Signals Imminent Ransomware Strikes

Do Son February 28, 2026 0
Read More Read more about Massive SonicWall Reconnaissance Campaign Signals Imminent Ransomware Strikes
API-Free Autonomy: Anthropic Acquires Vercept to Give Claude “Human-Like Eyes” for Desktop Mastery Anthropic Vercept acquisition Claude AI model Anthropic ad-free Claude
  • Technology

API-Free Autonomy: Anthropic Acquires Vercept to Give Claude “Human-Like Eyes” for Desktop Mastery

Do Son February 27, 2026 0
Read More Read more about API-Free Autonomy: Anthropic Acquires Vercept to Give Claude “Human-Like Eyes” for Desktop Mastery
Standard Hardware, Military Guard: NATO Certifies Retail iPhones for Restricted State Intelligence FCC Chinese lab ban iPhone NATO certification iPhone 18 Pro Deep Red iOS 27 Snow Leopard update 2026 smartphone memory shortage, IDC mobile market forecast iPhone Satellite Natural Usage iPhone 17 Speaker Issue, USB-C Static iPhone 17 Pro, MagSafe Scratches iPhone 17 Pro, professional filmmaking
  • Technology

Standard Hardware, Military Guard: NATO Certifies Retail iPhones for Restricted State Intelligence

Do Son February 27, 2026 0
Read More Read more about Standard Hardware, Military Guard: NATO Certifies Retail iPhones for Restricted State Intelligence
Google Unveils Nano Banana 2 to Standardize 4K AI Imaging Across Gemini Nano Banana 2
  • Technology

Google Unveils Nano Banana 2 to Standardize 4K AI Imaging Across Gemini

Do Son February 27, 2026 0
Read More Read more about Google Unveils Nano Banana 2 to Standardize 4K AI Imaging Across Gemini
Tim Cook’s “Big Week”: Apple Prepares to Unleash M5 MacBooks and the Disruptive iPhone 17e Apple Experience March 4 Apple Spring Event 2026
  • Technology

Tim Cook’s “Big Week”: Apple Prepares to Unleash M5 MacBooks and the Disruptive iPhone 17e

Do Son February 27, 2026 0
Read More Read more about Tim Cook’s “Big Week”: Apple Prepares to Unleash M5 MacBooks and the Disruptive iPhone 17e
Apple Releases Xcode 26.3 with Native Claude and Codex AI Agents Xcode 26.3 Agentic Coding
  • Technology

Apple Releases Xcode 26.3 with Native Claude and Codex AI Agents

Do Son February 27, 2026 0
Read More Read more about Apple Releases Xcode 26.3 with Native Claude and Codex AI Agents
Clockwork Twitch: Amazon’s New Policy Freezes Ad Timers if You Mute, Minimize, or Look Away Twitch ad attention mandate
  • Technology

Clockwork Twitch: Amazon’s New Policy Freezes Ad Timers if You Mute, Minimize, or Look Away

Do Son February 27, 2026 0
Read More Read more about Clockwork Twitch: Amazon’s New Policy Freezes Ad Timers if You Mute, Minimize, or Look Away
Powering the Core: Anthropic Offers 10,000 Free “Claude Max 20x” Subscriptions to Open-Source Heroes Anthropic confidential IPO filing Anthropic Google $200 billion deal Anthropic Mythos Preview Anthropic Pentagon blacklist Claude Max 20x open-source Model Distillation Anthropic vs DeepSeek Claude Free tier update 2026
  • Technology

Powering the Core: Anthropic Offers 10,000 Free “Claude Max 20x” Subscriptions to Open-Source Heroes

Do Son February 27, 2026 0
Read More Read more about Powering the Core: Anthropic Offers 10,000 Free “Claude Max 20x” Subscriptions to Open-Source Heroes
Hackers Impersonate Stripe.net to Hijack the Global Payment Supply Chain Stripe.net Typosquatting NuGet Supply Chain Attack
  • Cybercriminals

Hackers Impersonate Stripe.net to Hijack the Global Payment Supply Chain

Do Son February 27, 2026 0
Read More Read more about Hackers Impersonate Stripe.net to Hijack the Global Payment Supply Chain
The Explorer Trap: How Hackers Turn Windows File Explorer into a Silent Portal for Remote Access Trojans Seedworm Espionage Campaign 2026 ChromElevator Stealer DLL Sideloading SIM Swapping Crypto Theft Lazarus Comebacker, Aerospace Espionage Delete PlugX Malware
  • Cybercriminals

The Explorer Trap: How Hackers Turn Windows File Explorer into a Silent Portal for Remote Access Trojans

Do Son February 27, 2026 0
Read More Read more about The Explorer Trap: How Hackers Turn Windows File Explorer into a Silent Portal for Remote Access Trojans
Critical XSS Flaw in RustFS Exposes S3 Storage to Total Admin Account Takeovers RustFS XSS Vulnerability CVE-2026-27822
  • Vulnerability Report

Critical XSS Flaw in RustFS Exposes S3 Storage to Total Admin Account Takeovers

Do Son February 27, 2026 0
Read More Read more about Critical XSS Flaw in RustFS Exposes S3 Storage to Total Admin Account Takeovers
Beyond Ukraine: Mercenary Akula Spearphishing Hits European Finance with Russian Remote Admin Tools Mercenary Akula European Financial Targeting AI-Generated Malware React2Shell Exploit UAT-8837 Critical Infrastructure Attack APT36, BOSS Linux BRICKSTORM Malware, China Espionage Curly COMrades, MucorAgent Chinese APT - HTTP Client Tools Shuckworm Cyber Espionage
  • Cybercriminals

Beyond Ukraine: Mercenary Akula Spearphishing Hits European Finance with Russian Remote Admin Tools

Do Son February 27, 2026 0
Read More Read more about Beyond Ukraine: Mercenary Akula Spearphishing Hits European Finance with Russian Remote Admin Tools
Unmasking 1Campaign: The Professionalized ‘Cloaking’ Service Powering Global Malvertising Scams 1Campaign Cloaking Platform Google Ads Malvertising
  • Cybercriminals

Unmasking 1Campaign: The Professionalized ‘Cloaking’ Service Powering Global Malvertising Scams

Do Son February 27, 2026 0
Read More Read more about Unmasking 1Campaign: The Professionalized ‘Cloaking’ Service Powering Global Malvertising Scams
The 50,000-Download Trap: How ‘ambar-src’ Typosquatting Compromised Windows, Linux, and macOS Devs OSX/Amos Stealer Electron ASAR Trojan MioLab Malware macOS Security MacSync Stealer macOS Malware ambar-src npm Malware Supply Chain Typosquatting Matryoshka Mac Malware ClickFix Crypto Scam Infostealer Evolution macOS Malware Predator Spyware Intellexa Anti-Analysis XCSSET macOS Malware, Xcode Supply Chain
  • Malware

The 50,000-Download Trap: How ‘ambar-src’ Typosquatting Compromised Windows, Linux, and macOS Devs

Do Son February 27, 2026 0
Read More Read more about The 50,000-Download Trap: How ‘ambar-src’ Typosquatting Compromised Windows, Linux, and macOS Devs
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-16723CVSS 9.0
    A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson\'s stock...
    Admin intel📅 Updated: Jul 25, 2026
  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-0770CVSS 9.8
    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2021-27137CVSS 8.1
    An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2026-6875CVSS 9.5
    ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability...
    Admin intel📅 Updated: Jul 18, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-66013CVSS 9.3
    OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration...
  • CVE-2026-66012CVSS 10.0
    SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp...
  • CVE-2026-61884CVSS 9.8
    The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation...
  • CVE-2026-62379CVSS 9.8
    ## Summary A pre-authentication remote code execution vulnerability affects OpenAM. The remote...
  • CVE-2026-62263
    ### Summary The GHSA-6c99-87fr-6q7r fix wrapped WebAuthn authenticator deserialization in an `ObjectInputFilter`...
  • CVE-2026-62835CVSS 9.3
    Improper authorization in Azure Portal allows an unauthorized attacker to disclose information...
  • CVE-2026-48021CVSS 9.1
    In epa4all, prior to version 2026-05-20, an attacker who can intercept the...
  • CVE-2026-59940CVSS 9.8
    ## Summary A type confusion issue in `seroval.fromJSON()` allowed attacker-controlled JSON input...
  • CVE-2026-58630CVSS 10.0
    Improper access control in Azure App Service allows an unauthorized attacker to...
  • CVE-2026-57106CVSS 10.0
    Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.