Skip to content
September 18, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Instant Hijack: Critical 10.0 CVSS File Browser Flaw Grants Automatic Admin Rights File Browser Vulnerability CVE-2026-32760
  • Vulnerability Report

Instant Hijack: Critical 10.0 CVSS File Browser Flaw Grants Automatic Admin Rights

Do Son March 17, 2026 0
Read More Read more about Instant Hijack: Critical 10.0 CVSS File Browser Flaw Grants Automatic Admin Rights
Orchid Security Recognized by Gartner® as a Representative Vendor of Guardian Agents 1200-700_1773683858Gk7gZkJgJe
  • Press Release

Orchid Security Recognized by Gartner® as a Representative Vendor of Guardian Agents

cybernewswire March 17, 2026 0
Read More Read more about Orchid Security Recognized by Gartner® as a Representative Vendor of Guardian Agents
CVE Watchtower Launches Enterprise Automation Suite Featuring 30-Day Intelligence Dashboards, Predictive EPSS Scoring, REST API, and ITSM Webhooks cve
  • Announcement

CVE Watchtower Launches Enterprise Automation Suite Featuring 30-Day Intelligence Dashboards, Predictive EPSS Scoring, REST API, and ITSM Webhooks

ddos-admin March 17, 2026 0
Read More Read more about CVE Watchtower Launches Enterprise Automation Suite Featuring 30-Day Intelligence Dashboards, Predictive EPSS Scoring, REST API, and ITSM Webhooks
Broken Keys: Critical Authlib Flaws Expose Millions to JWT Forgery and Padding Oracles Authlib Vulnerabilities CVE-2026-27962
  • Vulnerability Report

Broken Keys: Critical Authlib Flaws Expose Millions to JWT Forgery and Padding Oracles

Do Son March 17, 2026 0
Read More Read more about Broken Keys: Critical Authlib Flaws Expose Millions to JWT Forgery and Padding Oracles
GitGuardian Reports an 81% Surge of AI-Service Leaks as 29M Secrets Hit Public GitHub BLOG_State_Of_2026_1_1773309985oZJL6G80kS
  • Press Release

GitGuardian Reports an 81% Surge of AI-Service Leaks as 29M Secrets Hit Public GitHub

cybernewswire March 17, 2026 0
Read More Read more about GitGuardian Reports an 81% Surge of AI-Service Leaks as 29M Secrets Hit Public GitHub
GlassWorm Abuses VS Code Extensions to Fuel Supply Chain Attacks GlassWorm Malware Open VSX Supply Chain
  • Malware

GlassWorm Abuses VS Code Extensions to Fuel Supply Chain Attacks

Do Son March 17, 2026 0
Read More Read more about GlassWorm Abuses VS Code Extensions to Fuel Supply Chain Attacks
The “Microslop” Backlash: Is Microsoft Finally Retreating from Windows 11 AI Bloat? Windows Secure Lock Screen Clock Lag Windows 11 KB5079391 error Windows 11 Kernel Driver Trust Microslop Windows 11 Windows 11 modem driver removal 2026, CVE-2025-24052 Agere driver exploit Windows 11 Password Icon Bug Lock Screen Glitch Windows 11 26H1 ARM Snapdragon X2 Windows 11 Reboot-Free, Insider Build Windows Update Error, 0x80070103 File Explorer, NTLM leak Windows bug, WinRE Windows Update, UAC prompts Secure Boot Certificate, Windows Security Windows 11 22H2 Installation security updates Windows UEFI CA 2023 Windows 11 25H2
  • Windows

The “Microslop” Backlash: Is Microsoft Finally Retreating from Windows 11 AI Bloat?

Do Son March 17, 2026 0
Read More Read more about The “Microslop” Backlash: Is Microsoft Finally Retreating from Windows 11 AI Bloat?
Weaponized Browsers: How the ‘DRILLAPP’ Backdoor Turns Microsoft Edge into an Espionage Tool DRILLAPP Backdoor Browser Exploitation
  • Malware

Weaponized Browsers: How the ‘DRILLAPP’ Backdoor Turns Microsoft Edge into an Espionage Tool

Do Son March 17, 2026 0
Read More Read more about Weaponized Browsers: How the ‘DRILLAPP’ Backdoor Turns Microsoft Edge into an Espionage Tool
High-Severity Angular XSS Flaw Bypasses Built-In Sanitization Angular hostname hijacking vulnerability Angular SSRF Origin Hijacking Angular XSS Vulnerability CVE-2026-32635 Angular i18n XSS CVE-2026-27970 Angular SSR SSRF CVE-2026-27739 Angular Vulnerability CVE-2026-22610 CVE-2025-59052 Angular security Angular XSS Bypass, SVG Injection
  • Vulnerability Report

High-Severity Angular XSS Flaw Bypasses Built-In Sanitization

Do Son March 17, 2026 0
Read More Read more about High-Severity Angular XSS Flaw Bypasses Built-In Sanitization
Operation CamelClone: New Global Espionage Campaign Hijacks Public Cloud Tools Operation CamelClone Cloud Storage Abuse
  • Cybercriminals

Operation CamelClone: New Global Espionage Campaign Hijacks Public Cloud Tools

Do Son March 17, 2026 0
Read More Read more about Operation CamelClone: New Global Espionage Campaign Hijacks Public Cloud Tools
The Fake VPN Trap: Microsoft Warns of Storm-2561 SEO Poisoning Campaigns Stealing Corporate Credentials Storm-2561 SEO Poisoning
  • Cybercriminals

The Fake VPN Trap: Microsoft Warns of Storm-2561 SEO Poisoning Campaigns Stealing Corporate Credentials

Do Son March 17, 2026 0
Read More Read more about The Fake VPN Trap: Microsoft Warns of Storm-2561 SEO Poisoning Campaigns Stealing Corporate Credentials
Malicious Packagist Themes Target Vietnamese OphimCMS Sites with Trojanized JS OphimCMS Malware Packagist Supply Chain Attack
  • Malware

Malicious Packagist Themes Target Vietnamese OphimCMS Sites with Trojanized JS

Do Son March 17, 2026 0
Read More Read more about Malicious Packagist Themes Target Vietnamese OphimCMS Sites with Trojanized JS
CISA Flags Actively Exploited Wing FTP Server Flaw Wing FTP Server CVE-2025-47813
  • Vulnerability Report

CISA Flags Actively Exploited Wing FTP Server Flaw

Do Son March 16, 2026 0
Read More Read more about CISA Flags Actively Exploited Wing FTP Server Flaw
Backdoored React Native Packages Target Developers with Crypto-Stealing Malware PAN-OS Root RCE CL-STA-1132 Exploitation Tianxin RCE CVE-2021-4473 React Native Supply Chain Attack AstrOOnauta Malware Gladinet Zero-Day, LFI RCE Chain WordPress Theme, Account Takeover CVE-2024-50623 - European Space Agency cyberattack
  • Malware

Backdoored React Native Packages Target Developers with Crypto-Stealing Malware

Do Son March 16, 2026 0
Read More Read more about Backdoored React Native Packages Target Developers with Crypto-Stealing Malware
The Poisoned Pickle: Critical Unpatched RCE Flaws Expose SGLang AI Infrastructure SGLang Vulnerability Pickle Deserialization
  • Vulnerability Report

The Poisoned Pickle: Critical Unpatched RCE Flaws Expose SGLang AI Infrastructure

Do Son March 16, 2026 0
Read More Read more about The Poisoned Pickle: Critical Unpatched RCE Flaws Expose SGLang AI Infrastructure
Critical 9.7 CVSS TinaCMS Flaw Exposes Local Developer Machines TinaCMS Vulnerability CVE-2026-28792
  • Vulnerability Report

Critical 9.7 CVSS TinaCMS Flaw Exposes Local Developer Machines

Do Son March 16, 2026 0
Read More Read more about Critical 9.7 CVSS TinaCMS Flaw Exposes Local Developer Machines
Root of the Problem: Sudo Flaw Exposes Linux Systems to Local Privilege Escalation Sudo Vulnerability Local Privilege Escalation
  • Vulnerability

Root of the Problem: Sudo Flaw Exposes Linux Systems to Local Privilege Escalation

Do Son March 16, 2026 0
Read More Read more about Root of the Problem: Sudo Flaw Exposes Linux Systems to Local Privilege Escalation
High-Severity Flaw Exposes LiteSpeed Web Servers to OS Command Injection LiteSpeed Vulnerability CVE-2026-31386
  • Vulnerability Report

High-Severity Flaw Exposes LiteSpeed Web Servers to OS Command Injection

Do Son March 16, 2026 0
Read More Read more about High-Severity Flaw Exposes LiteSpeed Web Servers to OS Command Injection
Critical 10.0 CVSS SandboxJS Flaw Grants Complete Remote Code Execution SandboxJS Escape Host Object Poisoning SandboxJS Vulnerability CVE-2026-26954
  • Vulnerability Report

Critical 10.0 CVSS SandboxJS Flaw Grants Complete Remote Code Execution

Do Son March 16, 2026 0
Read More Read more about Critical 10.0 CVSS SandboxJS Flaw Grants Complete Remote Code Execution
The $800M Inside Job: OFAC Sanctions North Korean IT Network Defrauding U.S. Businesses NATS-as-C2 Sysdig CVE-2026-33017 Langflow RCE Microsoft Phone Link Hijack CloudZ Pheno Plugin Insider Threat BlackCat (ALPHV) OFAC Sanctions DPRK IT Workers Transparent Tribe APT36 React2Shell, EtherRAT SideWinder Espionage, Netlify Phishing DDNS Abuse, C2 Infrastructure Hacking Health Club
  • Cybercriminals

The $800M Inside Job: OFAC Sanctions North Korean IT Network Defrauding U.S. Businesses

Do Son March 16, 2026 0
Read More Read more about The $800M Inside Job: OFAC Sanctions North Korean IT Network Defrauding U.S. Businesses
Beyond the Wrapper: Google and Accel Select 5 Indian Startups to Native-Code the Future of AI Google Atoms AI accelerator
  • Technology

Beyond the Wrapper: Google and Accel Select 5 Indian Startups to Native-Code the Future of AI

Do Son March 16, 2026 0
Read More Read more about Beyond the Wrapper: Google and Accel Select 5 Indian Startups to Native-Code the Future of AI
The Moral Surge: Anthropic Doubles Claude Quotas as Users Flee OpenAI for Ethical High Ground Claude quota doubling
  • Technology

The Moral Surge: Anthropic Doubles Claude Quotas as Users Flee OpenAI for Ethical High Ground

Do Son March 16, 2026 0
Read More Read more about The Moral Surge: Anthropic Doubles Claude Quotas as Users Flee OpenAI for Ethical High Ground
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-76460CVSS 10.0
    A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to...
    Admin intelCISA KEV📅 Added to KEV: Sep 16, 2026📅 Updated: Sep 16, 2026
  • CVE-2026-89026CVSS 9.8
    The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT...
    Admin intel📅 Updated: Sep 16, 2026
  • CVE-2026-58704
    In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This...
    Admin intelCISA KEV📅 Added to KEV: Sep 16, 2026📅 Updated: Sep 16, 2026
  • CVE-2026-87886
    Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin...
    Admin intelCISA KEV📅 Added to KEV: Sep 16, 2026📅 Updated: Sep 16, 2026
  • CVE-2026-87827CVSS 10.0
    Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-78006CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-39364
    Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-27540CVSS 9.0
    Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture...
    Admin intel📅 Updated: Sep 15, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-76461CVSS 9.8
    A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an...
    CISA KEV📅 Added to KEV: Sep 14, 2026📅 Updated: Sep 18, 2026
  • CVE-2026-13639CVSS 9.8
    An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075...
    📅 Updated: Sep 18, 2026
  • CVE-2026-13684CVSS 9.8
    An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9,...
    📅 Updated: Sep 18, 2026
  • CVE-2026-67100CVSS 9.8
    HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which...
    📅 Updated: Sep 18, 2026
  • CVE-2026-67101CVSS 9.3
    HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which...
    📅 Updated: Sep 18, 2026
  • CVE-2026-20341CVSS 9.1
    A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software could allow an authenticated, remote...
    📅 Updated: Sep 18, 2026
  • CVE-2026-20242CVSS 9.8
    A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow...
    📅 Updated: Sep 18, 2026
  • CVE-2026-20237CVSS 9.1
    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE)...
    📅 Updated: Sep 18, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.