Skip to content
October 10, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Windows Hybrid Intelligence and the New AI Search Menu Microsoft Windows 11 search menu integrating local AI agents
  • Windows

Windows Hybrid Intelligence and the New AI Search Menu

Do Son October 8, 2026 0
Read More Read more about Windows Hybrid Intelligence and the New AI Search Menu
Google Playground AI Platform: The Future of Game Creation Google Home MCP support letting AI agents like Claude control Nest and Matter smart home devices
  • Technology

Google Playground AI Platform: The Future of Game Creation

Do Son October 8, 2026 0
Read More Read more about Google Playground AI Platform: The Future of Game Creation
Apache DolphinScheduler 3.4.3 Fixes Six Authorization Flaws That Leak Passwords and Kubernetes Credentials Apache DolphinScheduler vulnerabilities CVE-2026-71896 and CVE-2026-71895 authorization bypass leaking Kubernetes credentials fixed in 3.4.3
  • Vulnerability Report

Apache DolphinScheduler 3.4.3 Fixes Six Authorization Flaws That Leak Passwords and Kubernetes Credentials

Do Son October 8, 2026 0
Read More Read more about Apache DolphinScheduler 3.4.3 Fixes Six Authorization Flaws That Leak Passwords and Kubernetes Credentials
wolfSSH 1.6.0 Fixes Five Flaws, Including Critical Host Key Bypass CVE-2026-16516 wolfSSH vulnerabilities CVE-2026-16516 ECDSA host key bypass and CVE-2026-83540 Windows logon token flaw fixed in wolfSSH 1.6.0
  • Vulnerability Report

wolfSSH 1.6.0 Fixes Five Flaws, Including Critical Host Key Bypass CVE-2026-16516

Do Son October 8, 2026 0
Read More Read more about wolfSSH 1.6.0 Fixes Five Flaws, Including Critical Host Key Bypass CVE-2026-16516
Cisco Finesse SSRF Flaw CVE-2026-20362 Publicly Disclosed, With Fixes Not Due Until 2027 Cisco Finesse vulnerability CVE-2026-20362 unauthenticated SSRF in contact center web interface publicly disclosed
  • Vulnerability Report

Cisco Finesse SSRF Flaw CVE-2026-20362 Publicly Disclosed, With Fixes Not Due Until 2027

Do Son October 8, 2026 0
Read More Read more about Cisco Finesse SSRF Flaw CVE-2026-20362 Publicly Disclosed, With Fixes Not Due Until 2027
VMware Workstation and Fusion VMXNET3 Flaw CVE-2026-59346 Detailed With Public PoC Exploit VMware VMXNET3 vulnerability CVE-2026-59346 integer overflow guest-to-host escape in Workstation and Fusion with public PoC exploit
  • Vulnerability Report

VMware Workstation and Fusion VMXNET3 Flaw CVE-2026-59346 Detailed With Public PoC Exploit

Do Son October 8, 2026 0
Read More Read more about VMware Workstation and Fusion VMXNET3 Flaw CVE-2026-59346 Detailed With Public PoC Exploit
Splunk Patches 22 Flaws in Splunk Enterprise, Including Critical Patroni API Command Execution Bug Splunk Enterprise vulnerabilities CVE-2026-76268 Patroni REST API command execution and CVE-2026-76281 fixed in 10.4.3 and 10.2.7
  • Vulnerability Report

Splunk Patches 22 Flaws in Splunk Enterprise, Including Critical Patroni API Command Execution Bug

Do Son October 8, 2026 0
Read More Read more about Splunk Patches 22 Flaws in Splunk Enterprise, Including Critical Patroni API Command Execution Bug
Top Industrial IoT & Embedded Firmware Development Partners ISO 27001
  • Technique

Top Industrial IoT & Embedded Firmware Development Partners

Do Son October 8, 2026 0
Read More Read more about Top Industrial IoT & Embedded Firmware Development Partners
Hackers Exploit Ninja Forms and WPC Product Bundles XSS Flaws to Plant Hidden WordPress Admins WordPress XSS campaign exploiting Ninja Forms CVE-2026-94504 and WPC Product Bundles CVE-2026-93836 to create hidden admin accounts
  • Vulnerability Report

Hackers Exploit Ninja Forms and WPC Product Bundles XSS Flaws to Plant Hidden WordPress Admins

Do Son October 8, 2026 0
Read More Read more about Hackers Exploit Ninja Forms and WPC Product Bundles XSS Flaws to Plant Hidden WordPress Admins
Cisco Fixes CVSS 10 License On-Prem Flaw and Ships Hardening Releases for APIC and Meraki Cisco License On-Prem vulnerabilities CVE-2026-76482 and CVE-2026-20328 plus APIC CVE-2026-76498 and Meraki hardening release fixes
  • Vulnerability Report

Cisco Fixes CVSS 10 License On-Prem Flaw and Ships Hardening Releases for APIC and Meraki

Do Son October 7, 2026 0
Read More Read more about Cisco Fixes CVSS 10 License On-Prem Flaw and Ships Hardening Releases for APIC and Meraki
Cisco Fixes Critical NX-API Flaw CVE-2026-76471 and Ships NX-OS Hardening Release for Six Bug Classes Cisco NX-OS vulnerabilities CVE-2026-76471 NX-API remote code execution and CVE-2026-76455 fixed in October 2026 hardening release
  • Vulnerability Report

Cisco Fixes Critical NX-API Flaw CVE-2026-76471 and Ships NX-OS Hardening Release for Six Bug Classes

Do Son October 7, 2026 0
Read More Read more about Cisco Fixes Critical NX-API Flaw CVE-2026-76471 and Ships NX-OS Hardening Release for Six Bug Classes
Cisco Patches Four Critical Nexus Switch Flaws That Allow Root-Level Remote Code Execution Cisco Nexus vulnerabilities CVE-2026-76485 and CVE-2026-76465 NGOAM and MPLS OAM remote code execution on Nexus 3000 and 9000 switches
  • Vulnerability Report

Cisco Patches Four Critical Nexus Switch Flaws That Allow Root-Level Remote Code Execution

Do Son October 7, 2026 0
Read More Read more about Cisco Patches Four Critical Nexus Switch Flaws That Allow Root-Level Remote Code Execution
Argo CD Patches Four Critical CVSS 9.9 Flaws Affecting the Repo-Server and AppProject Controls Argo CD vulnerabilities CVE-2026-77459 AppProject bypass and repo-server command execution flaws fixed in v3.5.4
  • Vulnerability Report

Argo CD Patches Four Critical CVSS 9.9 Flaws Affecting the Repo-Server and AppProject Controls

Do Son October 7, 2026 0
Read More Read more about Argo CD Patches Four Critical CVSS 9.9 Flaws Affecting the Repo-Server and AppProject Controls
Apache Jackrabbit Fixes Critical WebDAV Session Hijack Flaw CVE-2026-92414 Apache Jackrabbit vulnerabilities CVE-2026-92414 WebDAV session hijack and CVE-2026-92415 unsafe reflection fixed in 2.23.6
  • Vulnerability Report

Apache Jackrabbit Fixes Critical WebDAV Session Hijack Flaw CVE-2026-92414

Do Son October 7, 2026 0
Read More Read more about Apache Jackrabbit Fixes Critical WebDAV Session Hijack Flaw CVE-2026-92414
Gitea Fixes 27 Security Flaws Across 28.0.0 and 28.1.0, Including SSRF and Account Takeover Bugs Gitea security update 28.0.0 and 28.1.0 fixes SSRF flaw CVE-2026-101027 installer takeover CVE-2026-96404 and SSH key bug CVE-2026-103059
  • Vulnerability Report

Gitea Fixes 27 Security Flaws Across 28.0.0 and 28.1.0, Including SSRF and Account Takeover Bugs

Do Son October 7, 2026 0
Read More Read more about Gitea Fixes 27 Security Flaws Across 28.0.0 and 28.1.0, Including SSRF and Account Takeover Bugs
Four Attacker Clusters Exploit Citrix NetScaler Flaw CVE-2026-88771 to Plant Web Shells CVE-2026-88771 exploitation by four clusters deploying NetScaler web shells, Platypus agents, and reverse shells
  • Malware

Four Attacker Clusters Exploit Citrix NetScaler Flaw CVE-2026-88771 to Plant Web Shells

Do Son October 7, 2026 0
Read More Read more about Four Attacker Clusters Exploit Citrix NetScaler Flaw CVE-2026-88771 to Plant Web Shells
CVE-2026-21589 Exploited in the Wild as Atlassian File Read Flaw Details and PoC Go Public CVE-2026-21589 exploitation in the wild targets Atlassian Jira Confluence and Bitbucket arbitrary file read vulnerability with public PoC
  • Vulnerability Report

CVE-2026-21589 Exploited in the Wild as Atlassian File Read Flaw Details and PoC Go Public

Do Son October 7, 2026 0
Read More Read more about CVE-2026-21589 Exploited in the Wild as Atlassian File Read Flaw Details and PoC Go Public
Anthropic IPO Filing Reveals Amodei’s $18M Pay Anthropic IPO draft prospectus revealing executive pay and Dario Amodei compensation ahead of a possible listing
  • Technology

Anthropic IPO Filing Reveals Amodei’s $18M Pay

Do Son October 7, 2026 0
Read More Read more about Anthropic IPO Filing Reveals Amodei’s $18M Pay
Elastic Patches 14 Flaws in Elasticsearch, Kibana and Elastic Defend Elastic Stack vulnerabilities CVE-2026-102406 and CVE-2026-103007 in Kibana and Elasticsearch fixed in 8.19.23, 9.4.8 and 9.5.5
  • Vulnerability Report

Elastic Patches 14 Flaws in Elasticsearch, Kibana and Elastic Defend

Do Son October 7, 2026 0
Read More Read more about Elastic Patches 14 Flaws in Elasticsearch, Kibana and Elastic Defend
ASUS Patches Four Router Firmware Flaws, Including Two Critical Bugs Rated CVSS 9.3 ASUS router vulnerabilities CVE-2026-14911 and CVE-2026-19386 critical cross-site scripting and code execution flaws fixed in firmware update
  • Vulnerability Report

ASUS Patches Four Router Firmware Flaws, Including Two Critical Bugs Rated CVSS 9.3

Do Son October 7, 2026 0
Read More Read more about ASUS Patches Four Router Firmware Flaws, Including Two Critical Bugs Rated CVSS 9.3
ccTLD Registry Hijacks Let Attackers Mint TLS Certs ccTLD registry hijack diagram showing altered DNS records used to obtain unauthorized TLS certificates for .gh, .sl, and .as domains
  • Cybercriminals

ccTLD Registry Hijacks Let Attackers Mint TLS Certs

Do Son October 7, 2026 0
Read More Read more about ccTLD Registry Hijacks Let Attackers Mint TLS Certs
ASUSTOR Fixes Critical ADM Flaw CVE-2026-105324 That Lets Attackers Read NAS Files Without Login ASUSTOR ADM vulnerability CVE-2026-105324 unauthenticated arbitrary file read on NAS fixed in ADM 5.1.4.RM62 and 4.3.3.RY62
  • Vulnerability Report

ASUSTOR Fixes Critical ADM Flaw CVE-2026-105324 That Lets Attackers Read NAS Files Without Login

Do Son October 7, 2026 0
Read More Read more about ASUSTOR Fixes Critical ADM Flaw CVE-2026-105324 That Lets Attackers Read NAS Files Without Login
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
๐Ÿ“ˆ

EPSS Spike Alerts
Catch risk spikes before they make headlines.

๐ŸŽฏ

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

๐Ÿ›ก๏ธ

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

๐Ÿ™

GitHub Issues
Auto-create alert tickets without duplication.

๐Ÿ“ฌ

Weekly Digest
Clean summaries, eliminating email spam.

๐Ÿท๏ธ

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

๐Ÿ”€

Smart Routing
Route chat channels based on severity levels.

๐Ÿšจ

RBP Tracker
Early warning detection and tracking system.

Subscribe โ€“ $7/mo or try free for 14 days โ†’

🚨 Active Exploits in the Wild

  • CVE-2026-102255CVSS 10.0
    A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access...
    Admin intel📅 Updated: Oct 9, 2026
  • CVE-2026-105133CVSS 6.9
    A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file...
    Admin intel📅 Updated: Oct 9, 2026
  • CVE-2023-22894CVSS 4.9
    Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2016-3081CVSS 8.1
    Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled,...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2015-3306CVSS 10.0
    The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2015-5477CVSS 7.5
    named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2021-3199CVSS 9.8
    Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-81797CVSS 9.8
    Unauthenticated PHP Object Injection in Buzz Stone | Magazine & Viral Blog WordPress Theme
    📅 Updated: Oct 10, 2026
  • CVE-2026-78535CVSS 9.8
    Unauthenticated PHP Object Injection in Photolia
    📅 Updated: Oct 10, 2026
  • CVE-2026-78533CVSS 9.8
    Unauthenticated PHP Object Injection in Qwery
    📅 Updated: Oct 10, 2026
  • CVE-2026-78531CVSS 9.8
    Unauthenticated PHP Object Injection in Jacqueline
    📅 Updated: Oct 10, 2026
  • CVE-2026-78529CVSS 9.8
    Unauthenticated PHP Object Injection in Alliance
    📅 Updated: Oct 10, 2026
  • CVE-2026-66569CVSS 9.8
    Unauthenticated PHP Object Injection in Kicker
    📅 Updated: Oct 10, 2026
  • CVE-2026-66568CVSS 9.8
    Unauthenticated PHP Object Injection in Original
    📅 Updated: Oct 10, 2026
  • CVE-2026-66567CVSS 9.8
    Unauthenticated PHP Object Injection in Anesta
    📅 Updated: Oct 10, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Hereโ€™s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
ยฉ 2017 - 2026 Daily CyberSecurity. All Rights Reserved.