Skip to content
July 28, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
CISA “Must-Patch” Alert: Critical Gogs Exploit CVE-2025-8110 Active in Wild Gogs Vulnerability CVE-2025-8110 CVE-2025-64111
  • Vulnerability Report

CISA “Must-Patch” Alert: Critical Gogs Exploit CVE-2025-8110 Active in Wild

Do Son January 13, 2026 0
Read More Read more about CISA “Must-Patch” Alert: Critical Gogs Exploit CVE-2025-8110 Active in Wild
Attackers Weaponize Legitimate RMM Tools via Fake PDFs RMM Software Abuse AhnLab ASEC Report
  • Cybercriminals

Attackers Weaponize Legitimate RMM Tools via Fake PDFs

Do Son January 13, 2026 0
Read More Read more about Attackers Weaponize Legitimate RMM Tools via Fake PDFs
Angular Security Alert: High-Severity SVG Flaw CVE-2026-22610 Exposes Apps to XSS Angular hostname hijacking vulnerability Angular SSRF Origin Hijacking Angular XSS Vulnerability CVE-2026-32635 Angular i18n XSS CVE-2026-27970 Angular SSR SSRF CVE-2026-27739 Angular Vulnerability CVE-2026-22610 CVE-2025-59052 Angular security Angular XSS Bypass, SVG Injection
  • Vulnerability Report

Angular Security Alert: High-Severity SVG Flaw CVE-2026-22610 Exposes Apps to XSS

Do Son January 13, 2026 0
Read More Read more about Angular Security Alert: High-Severity SVG Flaw CVE-2026-22610 Exposes Apps to XSS
“TryCloudflare” Abuse: AsyncRAT Exploits Free Tunnels to Build Stealthy WebDAV Network AsyncRAT Malware Cloudflare Tunnel Abuse
  • Malware

“TryCloudflare” Abuse: AsyncRAT Exploits Free Tunnels to Build Stealthy WebDAV Network

Do Son January 13, 2026 0
Read More Read more about “TryCloudflare” Abuse: AsyncRAT Exploits Free Tunnels to Build Stealthy WebDAV Network
The AI Alliance: Apple Taps Google Gemini to Power the New Siri iOS 27 Apple Intelligence Apple AI Extensions bazaar Siri iOS 27 Gemini integration Apple AI server Baltra Siri AI delay iOS 26.4 Apple Google Gemini Siri partnership, Siri powered by Google Gemini 2026 Siri Gemini, Apple Intelligence Siri, Apple AI Apple "Veritas", Siri AI Siri Gemini Supercharged Siri, AI assistant Siri Integration, App Intents Apple Siri Apple AI Strategy, ChatGPT Rival
  • Technology

The AI Alliance: Apple Taps Google Gemini to Power the New Siri

Do Son January 13, 2026 0
Read More Read more about The AI Alliance: Apple Taps Google Gemini to Power the New Siri
India’s Source Code Demand Sparks Tech Revolt India smartphone source code mandate, MeitY security requirements 2026 iOS photo backup, background upload iOS crash Foldable iPhone, iPhone design
  • Technology

India’s Source Code Demand Sparks Tech Revolt

Do Son January 13, 2026 0
Read More Read more about India’s Source Code Demand Sparks Tech Revolt
Cutting the Cord: QEMU 11.0 to Expunge 32-Bit Host Support in Cloud Variant QEMU 11.0 Cloud 32-bit host deprecation, QEMU TCG code reduction
  • Linux

Cutting the Cord: QEMU 11.0 to Expunge 32-Bit Host Support in Cloud Variant

Do Son January 13, 2026 0
Read More Read more about Cutting the Cord: QEMU 11.0 to Expunge 32-Bit Host Support in Cloud Variant
Double Critical: Hardcoded Secrets Expose Ruckus IoT Controllers to Root RCE Ruckus vRIoT Vulnerability CVE-2025-69425 Ruckus Wireless, Critical Vulnerabilities
  • Vulnerability Report

Double Critical: Hardcoded Secrets Expose Ruckus IoT Controllers to Root RCE

Do Son January 13, 2026 0
Read More Read more about Double Critical: Hardcoded Secrets Expose Ruckus IoT Controllers to Root RCE
CVE-2025-52694 (CVSS 10): Critical Advantech SQL Injection Exposes IoT Devices Everon OCPP Vulnerability CVE-2026-26288 ASUSTOR ADM Vulnerability CVE-2026-24936 PrismX MX100 Vulnerability Hard-Coded Credentials Advantech Vulnerability CVE-2025-52694 Eaton UPS Companion, CVE-2025-59887 ASUS Router, Authentication Bypass ASUSTOR DLL Hijacking, Privilege Escalation OpenShift AI, Privilege Escalation GoAnywhere vulnerability CVE-2025-10035 LangChainGo, template injection DeepDiff, class pollution ToolShell Sunshine, CSRF Vulnerability KACE SMA, Critical Vulnerabilities Oracle Zero-Days - PDQ Deploy vulnerability
  • Vulnerability Report

CVE-2025-52694 (CVSS 10): Critical Advantech SQL Injection Exposes IoT Devices

Do Son January 13, 2026 0
Read More Read more about CVE-2025-52694 (CVSS 10): Critical Advantech SQL Injection Exposes IoT Devices
Critical Alert: Moxa Switches Exposed to OpenSSH Remote Code Execution (CVSS 9.8) Moxa Linux kernel vulnerabilities Moxa Vulnerability CVE-2024-12297 Moxa OpenSSH Vulnerability CVE-2023-38408 CVE-2023-5961 - CVE-2024-9138 and CVE-2024-9140
  • Vulnerability Report

Critical Alert: Moxa Switches Exposed to OpenSSH Remote Code Execution (CVSS 9.8)

Do Son January 13, 2026 0
Read More Read more about Critical Alert: Moxa Switches Exposed to OpenSSH Remote Code Execution (CVSS 9.8)
Tearing Down the Wall: Google Brings AirDrop Support to the Pixel 9 Google Quick Share AirDrop Google Quick Share AirDrop interoperability, Pixel 9 AirDrop support 2026 Snapdragon AirDrop Quick Share Interoperability Quick Share AirDrop Cross-Platform File Transfer
  • Android

Tearing Down the Wall: Google Brings AirDrop Support to the Pixel 9

Do Son January 13, 2026 0
Read More Read more about Tearing Down the Wall: Google Brings AirDrop Support to the Pixel 9
The End of the Shopping Tab: Google Unveils “Agentic Commerce” and UCP Google Agentic Commerce UCP, Universal Commerce Protocol retail partners
  • Technology

The End of the Shopping Tab: Google Unveils “Agentic Commerce” and UCP

Do Son January 13, 2026 0
Read More Read more about The End of the Shopping Tab: Google Unveils “Agentic Commerce” and UCP
Everything to Know about Staying Safe While Reconnecting With Old Friends Online bored man with laptop working at home office
  • Technique

Everything to Know about Staying Safe While Reconnecting With Old Friends Online

Do Son January 12, 2026 0
Read More Read more about Everything to Know about Staying Safe While Reconnecting With Old Friends Online
The Hype Hangover: Dell Admits Consumers Aren’t Buying the “AI PC” Narrative Dell AI PC marketing pivot, XPS 2026 brand revival, NPU, Tech Industry News CVE-2023-32484 PowerScale OneFS, CVE-2024-53298
  • Technology

The Hype Hangover: Dell Admits Consumers Aren’t Buying the “AI PC” Narrative

Do Son January 12, 2026 0
Read More Read more about The Hype Hangover: Dell Admits Consumers Aren’t Buying the “AI PC” Narrative
The 2nm Reunion: Qualcomm Confirms Samsung Foundry Talks at CES 2026 Qualcomm Samsung 2nm foundry deal, Snapdragon 8 Elite 2nm refresh Qualcomm Ventana Acquisition, RISC-V Strategy Qualcomm Autotalks, China Antitrust Qualcomm Antitrust, Which? Lawsuit Qualcomm GPU driver, CVE-2024-38399 Qualcomm's March 2025 Security Bulletin
  • Technology

The 2nm Reunion: Qualcomm Confirms Samsung Foundry Talks at CES 2026

Do Son January 12, 2026 0
Read More Read more about The 2nm Reunion: Qualcomm Confirms Samsung Foundry Talks at CES 2026
The Glass Box: Musk Pledges Full X Algorithm & Ad Transparency in 7 Days Elon Musk SEC settlement X bootloader verification X Creator Revenue Sharing suspension X Platform, AI Training X open-source algorithm 2026, Elon Musk ad transparency
  • Technology

The Glass Box: Musk Pledges Full X Algorithm & Ad Transparency in 7 Days

Do Son January 12, 2026 0
Read More Read more about The Glass Box: Musk Pledges Full X Algorithm & Ad Transparency in 7 Days
The Solonik Leak: 17.5 Million Instagram Profiles Exposed on Dark Web Instagram 3 Billion, Reels Focus
  • Data Leak

The Solonik Leak: 17.5 Million Instagram Profiles Exposed on Dark Web

Do Son January 12, 2026 0
Read More Read more about The Solonik Leak: 17.5 Million Instagram Profiles Exposed on Dark Web
WAFs Wide Open: Critical OWASP CRS Flaw Bypasses Filters Radware WAF, WAF bypass OWASP CRS Vulnerability CVE-2026-21876
  • Vulnerability

WAFs Wide Open: Critical OWASP CRS Flaw Bypasses Filters

Do Son January 12, 2026 0
Read More Read more about WAFs Wide Open: Critical OWASP CRS Flaw Bypasses Filters
Critical React Router Flaws: CVE-2025-61686 Exposes Server Files React Router vulnerabilities patch React Router Vulnerabilities CVE-2025-61686
  • Vulnerability Report

Critical React Router Flaws: CVE-2025-61686 Exposes Server Files

Do Son January 12, 2026 0
Read More Read more about Critical React Router Flaws: CVE-2025-61686 Exposes Server Files
The Soviet Ghost: How Carding Markets Survive on Legacy Domains BlueNoroff macOS Attack GhostCall Campaign Carding Underground Bulletproof Hosting DPRK Contagious Interview, npm Flood Stonefly group -HiatusRAT Actors
  • Cybercriminals

The Soviet Ghost: How Carding Markets Survive on Legacy Domains

Do Son January 12, 2026 0
Read More Read more about The Soviet Ghost: How Carding Markets Survive on Legacy Domains
The XML Trap: Critical Struts 2 Flaw CVE-2025-68493 Exposes Data Apache Struts 2 Vulnerability CVE-2025-68493 CVE-2021-31805 Struts DoS, File Upload Leak
  • Vulnerability Report

The XML Trap: Critical Struts 2 Flaw CVE-2025-68493 Exposes Data

Do Son January 12, 2026 0
Read More Read more about The XML Trap: Critical Struts 2 Flaw CVE-2025-68493 Exposes Data
CVE-2025-68637: Critical Apache Uniffle Flaw Exposes Clusters to Eavesdropping Apache Uniffle Vulnerability CVE-2025-68637
  • Vulnerability Report

CVE-2025-68637: Critical Apache Uniffle Flaw Exposes Clusters to Eavesdropping

Do Son January 12, 2026 0
Read More Read more about CVE-2025-68637: Critical Apache Uniffle Flaw Exposes Clusters to Eavesdropping
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-16812CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access...
    Admin intelCISA KEV📅 Added to KEV: Jul 27, 2026📅 Updated: Jul 27, 2026
  • CVE-2025-68686CVSS 5.9
    An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1,...
    CISA KEV📅 Added to KEV: Jul 27, 2026
  • CVE-2026-16723CVSS 9.0
    A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson\'s stock...
    Admin intel📅 Updated: Jul 25, 2026
  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-0770CVSS 9.8
    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers...
    CISA KEV📅 Added to KEV: Jul 21, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-55579CVSS 9.8
    Pheditor is a single-file editor and file manager written in PHP. From...
  • CVE-2026-48030CVSS 9.9
    Pheditor is a single-file editor and file manager written in PHP. From...
  • CVE-2026-63077CVSS 9.8
    In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible...
  • CVE-2026-17191CVSS 9.1
    An input validation vulnerability exists in an API component of the orchestrator....
  • CVE-2026-51303CVSS 9.8
    A use-after-free (UAF) vulnerability was discovered in the core parsing component of...
  • CVE-2025-50455CVSS 9.1
    SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint...
  • CVE-2026-16812CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may...
  • CVE-2026-66395CVSS 9.6
    SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the...
  • CVE-2026-59550CVSS 9.3
    Unauthenticated SQL Injection in AWP Classifieds
  • CVE-2026-59549CVSS 9.3
    Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.