Skip to content
July 28, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
CVE-2025-14026: Forcepoint DLP Flaw Lets Attackers Unchain Restricted Python Fortra BoKS vulnerability OS command injection, CVE-2026-9862 Altium Enterprise Server Vulnerability CVE-2026-9129 Path Traversal Patreon OAuth Vulnerability Identity Collision DRC INSIGHT Vulnerability Exam Data Hijacking Horner Automation PLC Industrial Brute Force Honeywell IQ4x Vulnerability CVE-2026-3611 DJI Romo vacuum security flaw Python Cryptography Vulnerability CVE-2026-26007 Open5GS Vulnerability CVE-2026-0622 Vivotek IP7137 Vulnerabilities CVE-2025-66049 Forcepoint DLP Vulnerability CVE-2025-14026 Cellopoint Secure Email Gateway - CVE-2024-9043
  • Vulnerability Report

CVE-2025-14026: Forcepoint DLP Flaw Lets Attackers Unchain Restricted Python

Do Son January 7, 2026 0
Read More Read more about CVE-2025-14026: Forcepoint DLP Flaw Lets Attackers Unchain Restricted Python
Google Patches High-Severity “WebView” Flaw in Chrome 143 Chrome Security Update Use After Free Chrome Security Update Critical Vulnerabilities Chrome Security Update CVE-2026-3062 Chrome Security Update V8 Engine Vulnerability Chrome Security Update CVE-2026-1862 CVE-2026-0628 Chrome 143 Update Chrome Safe Browsing UAF, CVE-2025-11756 Chrome Memory Flaws, CVE-2025-11460 Google Chrome, vulnerability CVE-2025-10200, CVE-2025-10201 Big Sleep CVE-2025-9478 Chrome Update, Security Vulnerabilities
  • Vulnerability Report

Google Patches High-Severity “WebView” Flaw in Chrome 143

Do Son January 7, 2026 0
Read More Read more about Google Patches High-Severity “WebView” Flaw in Chrome 143
Zero-Day Chronomaly Exploit Grants Root Access to Vulnerable Linux Kernels CVE-2025-38352 Chronomaly exploit, Linux kernel privilege escalation 2026
  • Vulnerability Report

Zero-Day Chronomaly Exploit Grants Root Access to Vulnerable Linux Kernels

Do Son January 7, 2026 0
Read More Read more about Zero-Day Chronomaly Exploit Grants Root Access to Vulnerable Linux Kernels
The ClickFix Trap: PHALT#BLYX Targets Hotels with Fake Blue Screens and DCRat PHALT#BLYX hospitality campaign, ClickFix BSOD malware
  • Cybercriminals

The ClickFix Trap: PHALT#BLYX Targets Hotels with Fake Blue Screens and DCRat

Do Son January 7, 2026 0
Read More Read more about The ClickFix Trap: PHALT#BLYX Targets Hotels with Fake Blue Screens and DCRat
Popular Chinese Utility Hijacked to Deploy Browser Malware Grafana Exploitation, Coordinated Scanning Arcserve UDP Vulnerabilities
  • Malware

Popular Chinese Utility Hijacked to Deploy Browser Malware

Do Son January 7, 2026 0
Read More Read more about Popular Chinese Utility Hijacked to Deploy Browser Malware
CVE-2025-67732: Dify Patch Fixes High-Severity Plaintext API Key Exposure Dify API Key Exposure, LLM Security Dify Information Disclosure, LLM Security
  • Vulnerability Report

CVE-2025-67732: Dify Patch Fixes High-Severity Plaintext API Key Exposure

Do Son January 7, 2026 0
Read More Read more about CVE-2025-67732: Dify Patch Fixes High-Severity Plaintext API Key Exposure
How to select a secure hosting platform for high-performance applications AISelect_20260105_224609_Docs
  • Technique

How to select a secure hosting platform for high-performance applications

Do Son January 6, 2026 0
Read More Read more about How to select a secure hosting platform for high-performance applications
n8n Sandbox Escape: How CVE-2025-68668 Turns Workflows into Weapons n8n Vulnerability CVE-2025-68668
  • Vulnerability Report

n8n Sandbox Escape: How CVE-2025-68668 Turns Workflows into Weapons

Do Son January 6, 2026 0
Read More Read more about n8n Sandbox Escape: How CVE-2025-68668 Turns Workflows into Weapons
The Robotics Revolution: NVIDIA Unveils Physical AI and the Jetson T4000 at CES 2026 NemoClaw Prompt Injection AI Sandbox Security NVIDIA Physical AI CES 2026, Jetson T4000 robotics hardware NVIDIA AI Security, Isaac Lab RCE NVIDIA Driver RCE, CVE-2025-23309 NVIDIA Triton, AI Server Vulnerabilities CVE-2023-31029 & CVE-2023-31024 - CVE‑2024-0112
  • Technology

The Robotics Revolution: NVIDIA Unveils Physical AI and the Jetson T4000 at CES 2026

Do Son January 6, 2026 0
Read More Read more about The Robotics Revolution: NVIDIA Unveils Physical AI and the Jetson T4000 at CES 2026
Connex IT Partners with AccuKnox for Zero Trust CNAPP Security in Southeast Asia connex_1767678638U9fchtEus6
  • Press Release

Connex IT Partners with AccuKnox for Zero Trust CNAPP Security in Southeast Asia

cybernewswire January 6, 2026 0
Read More Read more about Connex IT Partners with AccuKnox for Zero Trust CNAPP Security in Southeast Asia
The Rubin Era: NVIDIA’s Next-Gen AI Factory Chips Enter Mass Production NVIDIA Rubin GPU mass production, Vera CPU Olympus cores
  • Technology

The Rubin Era: NVIDIA’s Next-Gen AI Factory Chips Enter Mass Production

Do Son January 6, 2026 0
Read More Read more about The Rubin Era: NVIDIA’s Next-Gen AI Factory Chips Enter Mass Production
The Reasoning Car: NVIDIA Launches Alpamayo to Give AI Vehicles Human Logic NVIDIA Alpamayo open source AI, Mercedes-Benz CLA NVIDIA DRIVE AV
  • Technology

The Reasoning Car: NVIDIA Launches Alpamayo to Give AI Vehicles Human Logic

Do Son January 6, 2026 0
Read More Read more about The Reasoning Car: NVIDIA Launches Alpamayo to Give AI Vehicles Human Logic
The Desk-Side Revolution: NVIDIA’s DGX Spark Update Delivers 2.5× AI Speed Boost NVIDIA DGX Spark CES 2026, RTX 5090 AI collaboration
  • Technology

The Desk-Side Revolution: NVIDIA’s DGX Spark Update Delivers 2.5× AI Speed Boost

Do Son January 6, 2026 0
Read More Read more about The Desk-Side Revolution: NVIDIA’s DGX Spark Update Delivers 2.5× AI Speed Boost
The Open Door: Critical 9.8 Severity Flaw in Harvester Lets Hackers Hijack New Servers Harvester HCI, CVE-2025-62877
  • Vulnerability

The Open Door: Critical 9.8 Severity Flaw in Harvester Lets Hackers Hijack New Servers

Do Son January 6, 2026 0
Read More Read more about The Open Door: Critical 9.8 Severity Flaw in Harvester Lets Hackers Hijack New Servers
CVE-2025-68428: Critical Flaw in jsPDF Library Allows Server-Side File Theft CVE-2026-31938 jsPDF Vulnerability CVE-2026-25755 jsPDF, CVE-2025-68428 jsPDF Vulnerability CVE-2026-24133
  • Vulnerability Report

CVE-2025-68428: Critical Flaw in jsPDF Library Allows Server-Side File Theft

Do Son January 6, 2026 0
Read More Read more about CVE-2025-68428: Critical Flaw in jsPDF Library Allows Server-Side File Theft
Aiohttp Patches Seven Vulnerabilities Including High-Severity DoS Risks shell-quote command injection AI-Driven Vulnerabilities Q1 2026 Cyber Threats vm2 Sandbox Escape Node.js RCE upKeeper Privilege Escalation CVE-2026-2449 Pharos Controls Vulnerability Root Access Exploit Cybersecurity Vulnerability Roundup CVSS 10.0 Flaws Shadow Archives CVE-2026-0866 MS-Agent Prompt Injection CVE-2026-2256 basic-ftp Path Traversal CVE-2026-27699 telnetd Root Vulnerability CVE-1999-0073 Regression USR-W610 Vulnerabilities End-of-Life IoT Security IceWarp Security Update IceWarp Vulnerabilities Airleader Master Vulnerability CVE-2026-1358 ZLAN5143D Vulnerability CISA ICS Advisory Acronis Cyber Protect Vulnerability CVE-2025-30411 WAGO 852 Vulnerability OT Network Security SandboxJS Vulnerability Sandbox Escape (CVSS 10.0) Kubernetes Local Path Provisioner CVE-2025-62878 CISA Unresponsive Vendors Avation & RISS Vulnerabilities KiloView Vulnerability CVE-2026-1453 OpenClaw RCE vulnerability Johnson Controls Vulnerability CVE-2025-26385 SandboxJS Vulnerability CVE-2026-23830 ibaPDA Vulnerability CVE-2025-14988 Protobuf Vulnerability CVE-2026-0994 AVEVA Process Optimization Vulnerability CVE-2025-61937 ConnectWise PSA Vulnerability CVE-2026-0695 Aruba VIA Vulnerability CVE-2025-37186 aiohttp v3.13.3, Denial of Service (DoS) SmarterMail RCE, CVE-2025-52691 Airoha RACE, Headphone Jacking HPE OneView RCE CVE-2025-37164 FreePBX Auth Bypass, PBX Takeover ScreenConnect Config Flaw, Untrusted Extensions Ruby SAML Auth Bypass, XML Parser Differential Devolutions SQL Injection, Password Manager Flaw Vivotek Unauthenticated RCE, EOL IP Camera Flaw Lynx+ Critical Flaw, Unauthenticated Reset Firebox Default Credentials, CVE-2025-59396 Veeder-Root RCE, Critical ATG Flaw ArcGIS Server SQLi Watchdoc RCE, CVE-2025-58384 Delta DIALink Daikin Security Gateway, authentication bypass Frostbyte10, industrial controller security SunPower, vulnerability Ubiquiti UniFi Connect, EV Station Vulnerabilities Adobe Experience Manager, RCE Vulnerability UniFi Access, Command Injection LDAPNightmare - CVE-2025-1316
  • Vulnerability Report

Aiohttp Patches Seven Vulnerabilities Including High-Severity DoS Risks

Do Son January 6, 2026 0
Read More Read more about Aiohttp Patches Seven Vulnerabilities Including High-Severity DoS Risks
Apache SIS Patch Blocks XML Attack That Leaks Server Files Apache SIS, CVE-2025-68280
  • Vulnerability Report

Apache SIS Patch Blocks XML Attack That Leaks Server Files

Do Son January 6, 2026 0
Read More Read more about Apache SIS Patch Blocks XML Attack That Leaks Server Files
CVE-2025-66518: High-Severity Flaw in Apache Kyuubi Exposes Local Server Files Apache Kyuubi, CVE-2025-66518
  • Vulnerability Report

CVE-2025-66518: High-Severity Flaw in Apache Kyuubi Exposes Local Server Files

Do Son January 6, 2026 0
Read More Read more about CVE-2025-66518: High-Severity Flaw in Apache Kyuubi Exposes Local Server Files
Attacking from Within: How Adobe ColdFusion Admins Can Weaponize Remote Shares ColdFusion Archive (CAR), UNC Path Exploitation
  • Vulnerability Report

Attacking from Within: How Adobe ColdFusion Admins Can Weaponize Remote Shares

Do Son January 6, 2026 0
Read More Read more about Attacking from Within: How Adobe ColdFusion Admins Can Weaponize Remote Shares
MediaTek Kicks Off 2026 with Major Security Overhaul for Mobile Chipsets MediaTek Modem Vulnerabilities, January 2026 Security Bulletin MediaTek Vulnerabilities, Chipset Security CVE-2024-20103 & CVE-2024-20100 - CVE-2024-20154 - February 2025 Product Security Bulletin
  • Vulnerability Report

MediaTek Kicks Off 2026 with Major Security Overhaul for Mobile Chipsets

Do Son January 6, 2026 0
Read More Read more about MediaTek Kicks Off 2026 with Major Security Overhaul for Mobile Chipsets
macOS Developers in the Crosshairs: GlassWorm’s Wave 4 Exploits VS Code to Trojanize Hardware Wallets GlassWorm Wave 4, macOS Supply Chain Attack
  • Malware

macOS Developers in the Crosshairs: GlassWorm’s Wave 4 Exploits VS Code to Trojanize Hardware Wallets

Do Son January 6, 2026 0
Read More Read more about macOS Developers in the Crosshairs: GlassWorm’s Wave 4 Exploits VS Code to Trojanize Hardware Wallets
Researcher Details Stack Buffer Overflow Flaw in Net-SNMP snmptrapd with PoC Net-SNMP, CVE-2025-68615
  • Vulnerability

Researcher Details Stack Buffer Overflow Flaw in Net-SNMP snmptrapd with PoC

Do Son January 6, 2026 0
Read More Read more about Researcher Details Stack Buffer Overflow Flaw in Net-SNMP snmptrapd with PoC
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-16812CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access...
    Admin intelCISA KEV📅 Added to KEV: Jul 27, 2026📅 Updated: Jul 27, 2026
  • CVE-2025-68686CVSS 5.9
    An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1,...
    CISA KEV📅 Added to KEV: Jul 27, 2026
  • CVE-2026-16723CVSS 9.0
    A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson\'s stock...
    Admin intel📅 Updated: Jul 25, 2026
  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-0770CVSS 9.8
    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers...
    CISA KEV📅 Added to KEV: Jul 21, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-11756CVSS 10.0
    A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE...
  • CVE-2026-15014CVSS 9.8
    The SMS Alert – SMS & OTP for WooCommerce, Order Notifications &...
  • CVE-2026-55579CVSS 9.8
    Pheditor is a single-file editor and file manager written in PHP. From...
  • CVE-2026-48030CVSS 9.9
    Pheditor is a single-file editor and file manager written in PHP. From...
  • CVE-2026-63077CVSS 9.8
    In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible...
  • CVE-2026-17191CVSS 9.1
    An input validation vulnerability exists in an API component of the orchestrator....
  • CVE-2026-51303CVSS 9.8
    A use-after-free (UAF) vulnerability was discovered in the core parsing component of...
  • CVE-2025-50455CVSS 9.1
    SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint...
  • CVE-2026-16812CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may...
  • CVE-2026-66395CVSS 9.6
    SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.