Skip to content
July 28, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
The June Deadline: Microsoft Issues Urgent Secure Boot Certificate Updates HTTP.sys RCE vulnerability, Windows HTTP stack exploit, CVE-2026-47291 Netlogon RCE vulnerability Exploited in the wild Secure Boot certificate renewal 2026, Windows 11 UEFI update Community-First AI Infrastructure, Microsoft self-funding energy mandate aka.ms/aoh online portal CVE-2025-55681, Windows DWM Elevation Windows Administrator Protection, CVE-2025-60718 Microsoft AI Compute, IREN Infrastructure Microsoft Japan PPA, Renewable Energy Microsoft AI Investment, Cloud Expansion Microsoft Azure, Startup Credits Infinite Workday, AI in Work Microsoft Russia, Bankruptcy AI code generation, Microsoft AI Microsoft Layoffs, Restructuring
  • Windows

The June Deadline: Microsoft Issues Urgent Secure Boot Certificate Updates

Do Son January 15, 2026 0
Read More Read more about The June Deadline: Microsoft Issues Urgent Secure Boot Certificate Updates
Collections Retired: Microsoft Edge Sunsets Research Tool Amid Data Loss Fears Microsoft Edge Google account login interface and synchronization settings Browser Choice Alliance letter Microsoft Edge cleartext credentials memory dump Microsoft Edge auto-startup Microsoft Edge Collections sunset, export Edge Collections CSV Edge IE Mode Zero-Day, Chakra Exploit Windows Search, Microsoft Edge AI video translation, Edge browser Microsoft Editor, Edge Edge Developer tools Windows 10 ESU, Microsoft Edge Microsoft Edge, FCP Optimization CVE-2023-36735 Edge, AI Search
  • Technology

Collections Retired: Microsoft Edge Sunsets Research Tool Amid Data Loss Fears

Do Son January 15, 2026 0
Read More Read more about Collections Retired: Microsoft Edge Sunsets Research Tool Amid Data Loss Fears
Powering the Boom: Microsoft Agrees to Trump’s “Self-Funding” Energy Mandate HTTP.sys RCE vulnerability, Windows HTTP stack exploit, CVE-2026-47291 Netlogon RCE vulnerability Exploited in the wild Secure Boot certificate renewal 2026, Windows 11 UEFI update Community-First AI Infrastructure, Microsoft self-funding energy mandate aka.ms/aoh online portal CVE-2025-55681, Windows DWM Elevation Windows Administrator Protection, CVE-2025-60718 Microsoft AI Compute, IREN Infrastructure Microsoft Japan PPA, Renewable Energy Microsoft AI Investment, Cloud Expansion Microsoft Azure, Startup Credits Infinite Workday, AI in Work Microsoft Russia, Bankruptcy AI code generation, Microsoft AI Microsoft Layoffs, Restructuring
  • Technology

Powering the Boom: Microsoft Agrees to Trump’s “Self-Funding” Energy Mandate

Do Son January 15, 2026 0
Read More Read more about Powering the Boom: Microsoft Agrees to Trump’s “Self-Funding” Energy Mandate
The Anonymity Trap: New Telegram Flaw Leaks Real IPs via Proxy Links Telegram IP leak proxy link, Telegram security update 2026 Amsterdam ban Telegram - Golang Backdoor Telegram backdoor France encryption
  • Data Leak

The Anonymity Trap: New Telegram Flaw Leaks Real IPs via Proxy Links

Do Son January 15, 2026 0
Read More Read more about The Anonymity Trap: New Telegram Flaw Leaks Real IPs via Proxy Links
CVE-2025-33206: High-Severity Flaw Patched in NVIDIA Nsight Graphics for Linux NVIDIA Nsight Vulnerability CVE-2025-33206 NVIDIA ConnectX Firmware - CVE-2024-0105
  • Vulnerability Report

CVE-2025-33206: High-Severity Flaw Patched in NVIDIA Nsight Graphics for Linux

Do Son January 15, 2026 0
Read More Read more about CVE-2025-33206: High-Severity Flaw Patched in NVIDIA Nsight Graphics for Linux
The $24 Criminal Tool: Microsoft & Police Shut Down RedVDS Fraud Engine RedVDS Takedown Microsoft Digital Crimes Unit
  • Cybercriminals

The $24 Criminal Tool: Microsoft & Police Shut Down RedVDS Fraud Engine

Do Son January 15, 2026 0
Read More Read more about The $24 Criminal Tool: Microsoft & Police Shut Down RedVDS Fraud Engine
Palo Alto Networks Firewalls Hit by Unauthenticated GlobalProtect DoS Flaw PAN-OS IKEv2 Buffer Overflow CVE-2026-0263 Palo Alto Cortex XDR Privilege Escalation Palo Alto Networks Vulnerability CVE-2026-0229 PAN-OS Vulnerability CVE-2026-0227 CVE-2024-5914 - Palo Alto Networks - CVE-2025-0108 & CVE-2025-0110
  • Vulnerability Report

Palo Alto Networks Firewalls Hit by Unauthenticated GlobalProtect DoS Flaw

Do Son January 15, 2026 0
Read More Read more about Palo Alto Networks Firewalls Hit by Unauthenticated GlobalProtect DoS Flaw
HPE Aruba Patches High-Severity DoS and Data Leak Flaws in Instant On Devices HPE Aruba Private 5G Vulnerability CVE-2026-23595 HPE Instant On Vulnerability CVE-2025-37166 CVE-2024-31466 & CVE-2024-31467 HPE Aruba Networking, vulnerability
  • Vulnerability Report

HPE Aruba Patches High-Severity DoS and Data Leak Flaws in Instant On Devices

Do Son January 15, 2026 0
Read More Read more about HPE Aruba Patches High-Severity DoS and Data Leak Flaws in Instant On Devices
Zoho Patches Critical “9.1” Flaw in ADSelfService Plus CVE-2025-1723 ManageEngine Vulnerability CVE-2025-11250
  • Vulnerability Report

Zoho Patches Critical “9.1” Flaw in ADSelfService Plus

Do Son January 15, 2026 0
Read More Read more about Zoho Patches Critical “9.1” Flaw in ADSelfService Plus
SHADOW#REACTOR Malware Builds Remcos RAT via Text Files TanStack Typosquatting npm Supply Chain Attack Axios Supply Chain Attack npm Poisoning eScan Supply Chain Attack Antivirus Compromise APT-36, NCERT WhatsApp Advisory FBI alert, Salesforce Salt Typhoon, APT group ConnectWise ScreenConnect hack Nation-state cyberattack FortiGate Leak - zkLend vulnerability - TRIPLESTRENGTH Threat Actor Group Dark Storm
  • Malware

SHADOW#REACTOR Malware Builds Remcos RAT via Text Files

Do Son January 15, 2026 0
Read More Read more about SHADOW#REACTOR Malware Builds Remcos RAT via Text Files
One API Call to Hijack: Critical Cal.com Flaw (CVE-2026-23478, CVSS 10) Bypasses 2FA Cal.com Vulnerability CVE-2026-23478 Cal.com Auth Bypass, TOTP Logic Flaw
  • Vulnerability Report

One API Call to Hijack: Critical Cal.com Flaw (CVE-2026-23478, CVSS 10) Bypasses 2FA

Do Son January 15, 2026 0
Read More Read more about One API Call to Hijack: Critical Cal.com Flaw (CVE-2026-23478, CVSS 10) Bypasses 2FA
“Browser-in-the-Browser” Attack Escalates: Trellix Reports Surge in Sophisticated Facebook Phishing phishing-3390518_1280
  • Cybercriminals

“Browser-in-the-Browser” Attack Escalates: Trellix Reports Surge in Sophisticated Facebook Phishing

Do Son January 15, 2026 0
Read More Read more about “Browser-in-the-Browser” Attack Escalates: Trellix Reports Surge in Sophisticated Facebook Phishing
High-Severity Flaws in HPE Aruba Networking Expose Mobility Controllers to Attack CVE-2024-54006 & CVE-2024-54007 Aruba AOS Vulnerabilities CVE-2025-37168
  • Vulnerability Report

High-Severity Flaws in HPE Aruba Networking Expose Mobility Controllers to Attack

Do Son January 15, 2026 0
Read More Read more about High-Severity Flaws in HPE Aruba Networking Expose Mobility Controllers to Attack
“Magecart” Strikes Again: Long-Running Web Skimming Campaign Targets Global Payment Networks Magecart Campaign Fake Stripe Payment Form
  • Cybercriminals

“Magecart” Strikes Again: Long-Running Web Skimming Campaign Targets Global Payment Networks

Do Son January 15, 2026 0
Read More Read more about “Magecart” Strikes Again: Long-Running Web Skimming Campaign Targets Global Payment Networks
Command Injection Alert: High-Severity Flaws Hit LoadMaster & MOVEit WAF CVE-2024-1212 LoadMaster Vulnerability CVE-2025-13444
  • Vulnerability Report

Command Injection Alert: High-Severity Flaws Hit LoadMaster & MOVEit WAF

Do Son January 15, 2026 0
Read More Read more about Command Injection Alert: High-Severity Flaws Hit LoadMaster & MOVEit WAF
2026 Study from Panorays: 85% of CISOs Can’t See Third-Party Threats Amid Increasing Supply Chain Attacks image1_1768153342Bp17a2duod
  • Press Release

2026 Study from Panorays: 85% of CISOs Can’t See Third-Party Threats Amid Increasing Supply Chain Attacks

cybernewswire January 14, 2026 0
Read More Read more about 2026 Study from Panorays: 85% of CISOs Can’t See Third-Party Threats Amid Increasing Supply Chain Attacks
SpyCloud Launches Supply Chain Solution to Combat Rising Third-Party Identity Threats SpyCloud_wordmark_square_1767997486T87CfpS8Sn
  • Press Release

SpyCloud Launches Supply Chain Solution to Combat Rising Third-Party Identity Threats

cybernewswire January 14, 2026 0
Read More Read more about SpyCloud Launches Supply Chain Solution to Combat Rising Third-Party Identity Threats
GitGuardian Closes 2025 with Strong Enterprise Momentum, Protecting Millions of Developers Worldwide 17_1768326569OIahvBG1Dm
  • Press Release

GitGuardian Closes 2025 with Strong Enterprise Momentum, Protecting Millions of Developers Worldwide

cybernewswire January 14, 2026 0
Read More Read more about GitGuardian Closes 2025 with Strong Enterprise Momentum, Protecting Millions of Developers Worldwide
Exploit Code Published: Critical FortiSIEM Flaw Grants Unauthenticated Root Access FortiSIEM PoC Exploit CVE-2025-64155
  • Vulnerability

Exploit Code Published: Critical FortiSIEM Flaw Grants Unauthenticated Root Access

Do Son January 14, 2026 0
Read More Read more about Exploit Code Published: Critical FortiSIEM Flaw Grants Unauthenticated Root Access
Details Exposed: High-Severity Aruba VIA Root Flaw Publicly Disclosed shell-quote command injection AI-Driven Vulnerabilities Q1 2026 Cyber Threats vm2 Sandbox Escape Node.js RCE upKeeper Privilege Escalation CVE-2026-2449 Pharos Controls Vulnerability Root Access Exploit Cybersecurity Vulnerability Roundup CVSS 10.0 Flaws Shadow Archives CVE-2026-0866 MS-Agent Prompt Injection CVE-2026-2256 basic-ftp Path Traversal CVE-2026-27699 telnetd Root Vulnerability CVE-1999-0073 Regression USR-W610 Vulnerabilities End-of-Life IoT Security IceWarp Security Update IceWarp Vulnerabilities Airleader Master Vulnerability CVE-2026-1358 ZLAN5143D Vulnerability CISA ICS Advisory Acronis Cyber Protect Vulnerability CVE-2025-30411 WAGO 852 Vulnerability OT Network Security SandboxJS Vulnerability Sandbox Escape (CVSS 10.0) Kubernetes Local Path Provisioner CVE-2025-62878 CISA Unresponsive Vendors Avation & RISS Vulnerabilities KiloView Vulnerability CVE-2026-1453 OpenClaw RCE vulnerability Johnson Controls Vulnerability CVE-2025-26385 SandboxJS Vulnerability CVE-2026-23830 ibaPDA Vulnerability CVE-2025-14988 Protobuf Vulnerability CVE-2026-0994 AVEVA Process Optimization Vulnerability CVE-2025-61937 ConnectWise PSA Vulnerability CVE-2026-0695 Aruba VIA Vulnerability CVE-2025-37186 aiohttp v3.13.3, Denial of Service (DoS) SmarterMail RCE, CVE-2025-52691 Airoha RACE, Headphone Jacking HPE OneView RCE CVE-2025-37164 FreePBX Auth Bypass, PBX Takeover ScreenConnect Config Flaw, Untrusted Extensions Ruby SAML Auth Bypass, XML Parser Differential Devolutions SQL Injection, Password Manager Flaw Vivotek Unauthenticated RCE, EOL IP Camera Flaw Lynx+ Critical Flaw, Unauthenticated Reset Firebox Default Credentials, CVE-2025-59396 Veeder-Root RCE, Critical ATG Flaw ArcGIS Server SQLi Watchdoc RCE, CVE-2025-58384 Delta DIALink Daikin Security Gateway, authentication bypass Frostbyte10, industrial controller security SunPower, vulnerability Ubiquiti UniFi Connect, EV Station Vulnerabilities Adobe Experience Manager, RCE Vulnerability UniFi Access, Command Injection LDAPNightmare - CVE-2025-1316
  • Vulnerability

Details Exposed: High-Severity Aruba VIA Root Flaw Publicly Disclosed

Do Son January 14, 2026 0
Read More Read more about Details Exposed: High-Severity Aruba VIA Root Flaw Publicly Disclosed
The Invisible Brain: Inside Apple’s Secret Deal to “Apple-ify” Google Gemini Google licenses app code Gemini API Prepaid Billing Gemini macOS Desktop Intelligence Gemini API Tier 2 upgrade Google Workspace CLI AI Google Gemini Import AI Chats Google AI Plus subscription 2026, Gemini 3 Pro vs AI Pro cost Apple, Google Gemini, Siri, Apple Intelligence, iOS 26, The Information, Fine-tuning, Private Cloud Compute, AI Partnership, Tech News 2026 Gemini Assistant transition 2026, Google Assistant sunset delay Nano Banana Pro AI Image Text Gemini Deep Research, Workspace Integration Gemini Canvas, presentation generation
  • Technology

The Invisible Brain: Inside Apple’s Secret Deal to “Apple-ify” Google Gemini

Do Son January 14, 2026 0
Read More Read more about The Invisible Brain: Inside Apple’s Secret Deal to “Apple-ify” Google Gemini
Meet Your New Coworker: Anthropic’s Claude Now Controls Your Mac Claude Cowork automation, Anthropic agentic AI
  • Technology

Meet Your New Coworker: Anthropic’s Claude Now Controls Your Mac

Do Son January 14, 2026 0
Read More Read more about Meet Your New Coworker: Anthropic’s Claude Now Controls Your Mac
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-16812CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access...
    Admin intelCISA KEV📅 Added to KEV: Jul 27, 2026📅 Updated: Jul 27, 2026
  • CVE-2025-68686CVSS 5.9
    An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1,...
    CISA KEV📅 Added to KEV: Jul 27, 2026
  • CVE-2026-16723CVSS 9.0
    A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson\'s stock...
    Admin intel📅 Updated: Jul 25, 2026
  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-0770CVSS 9.8
    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers...
    CISA KEV📅 Added to KEV: Jul 21, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-55579CVSS 9.8
    Pheditor is a single-file editor and file manager written in PHP. From...
  • CVE-2026-48030CVSS 9.9
    Pheditor is a single-file editor and file manager written in PHP. From...
  • CVE-2026-63077CVSS 9.8
    In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible...
  • CVE-2026-17191CVSS 9.1
    An input validation vulnerability exists in an API component of the orchestrator....
  • CVE-2026-51303CVSS 9.8
    A use-after-free (UAF) vulnerability was discovered in the core parsing component of...
  • CVE-2025-50455CVSS 9.1
    SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint...
  • CVE-2026-16812CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may...
  • CVE-2026-66395CVSS 9.6
    SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the...
  • CVE-2026-59550CVSS 9.3
    Unauthenticated SQL Injection in AWP Classifieds
  • CVE-2026-59549CVSS 9.3
    Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.