Skip to content
September 14, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Aeternum Blockchain Botnet Hides C2 Commands in Polygon Smart Contracts Aeternum blockchain botnet Polygon smart contracts C2 diagram
  • Malware

Aeternum Blockchain Botnet Hides C2 Commands in Polygon Smart Contracts

Do Son August 18, 2026 0
Read More Read more about Aeternum Blockchain Botnet Hides C2 Commands in Polygon Smart Contracts
GeoServer Unauthenticated SQL Injection (CVSS 9.8) Exploited in the Wild, PoC Public GeoServer unauthenticated SQL injection jsonArrayContains vulnerability CVSS 9.8 exploited in the wild proof-of-concept RCE
  • Vulnerability Report

GeoServer Unauthenticated SQL Injection (CVSS 9.8) Exploited in the Wild, PoC Public

Do Son August 18, 2026 0
Read More Read more about GeoServer Unauthenticated SQL Injection (CVSS 9.8) Exploited in the Wild, PoC Public
WSL Ubuntu Installations Threaten Native Desktop Dominance Ubuntu running seamlessly within the Windows 11 Subsystem for Linux (WSL) environment
  • Linux

WSL Ubuntu Installations Threaten Native Desktop Dominance

Do Son August 18, 2026 0
Read More Read more about WSL Ubuntu Installations Threaten Native Desktop Dominance
Researchers Rebuild Leaked Tiangou Secure Gateway, Find Great Firewall Ties Tiangou Secure Gateway leaked source code Great Firewall censorship research Geedge Networks
  • Data Leak

Researchers Rebuild Leaked Tiangou Secure Gateway, Find Great Firewall Ties

Do Son August 18, 2026 0
Read More Read more about Researchers Rebuild Leaked Tiangou Secure Gateway, Find Great Firewall Ties
Amazon Bans Class Action Lawsuits in Terms Update Amazon terms of service update email notifying users of class action lawsuit ban
  • Technology

Amazon Bans Class Action Lawsuits in Terms Update

Do Son August 18, 2026 0
Read More Read more about Amazon Bans Class Action Lawsuits in Terms Update
Windows Server 2022 Mainstream Support Ends October 2026 Windows Server 2022 mainstream support end extended security updates Server 2025 upgrade
  • Windows

Windows Server 2022 Mainstream Support Ends October 2026

Do Son August 18, 2026 0
Read More Read more about Windows Server 2022 Mainstream Support Ends October 2026
Linux Kernel 7.2 Arrives with Extensive Updates Linux Kernel 7.2 release graphic showing hardware driver and security updates
  • Linux

Linux Kernel 7.2 Arrives with Extensive Updates

Do Son August 18, 2026 0
Read More Read more about Linux Kernel 7.2 Arrives with Extensive Updates
Firefox for iOS Tests Native Ad Blocker Using EasyList Filtering Firefox iOS native ad blocker EasyList network level filtering settings
  • Technology

Firefox for iOS Tests Native Ad Blocker Using EasyList Filtering

Do Son August 18, 2026 0
Read More Read more about Firefox for iOS Tests Native Ad Blocker Using EasyList Filtering
CVE-2026-66804: PoC Exploit Gains SYSTEM via Cross Device Service CVE-2026-66804 Cross Device Service elevation of privilege proof-of-concept exploit gaining SYSTEM privileges on Windows 11
  • Vulnerability Report

CVE-2026-66804: PoC Exploit Gains SYSTEM via Cross Device Service

Do Son August 18, 2026 0
Read More Read more about CVE-2026-66804: PoC Exploit Gains SYSTEM via Cross Device Service
CVE-2026-71479: New API Integer Overflow Exploited in the Wild CVE-2026-71479 New API integer overflow quota billing vulnerability exploited in the wild self-crediting AI gateway
  • Vulnerability Report

CVE-2026-71479: New API Integer Overflow Exploited in the Wild

Do Son August 18, 2026 0
Read More Read more about CVE-2026-71479: New API Integer Overflow Exploited in the Wild
CVE-2026-15748 (CVSS 9.8): Forminator Flaw Enables Pre-Auth RCE CVE-2026-15748 Forminator Forms unauthenticated arbitrary file upload vulnerability CVSS 9.8 pre-auth remote code execution WordPress
  • Vulnerability Report

CVE-2026-15748 (CVSS 9.8): Forminator Flaw Enables Pre-Auth RCE

Do Son August 18, 2026 0
Read More Read more about CVE-2026-15748 (CVSS 9.8): Forminator Flaw Enables Pre-Auth RCE
CVE-2026-19478 (CVSS 9.4): GitLab GraphQL Code Injection Flaw Patched CVE-2026-19478 GitLab GraphQL code injection vulnerability CVSS 9.4 patch release CVE-2026-19650 CSRF
  • Vulnerability Report

CVE-2026-19478 (CVSS 9.4): GitLab GraphQL Code Injection Flaw Patched

Do Son August 18, 2026 0
Read More Read more about CVE-2026-19478 (CVSS 9.4): GitLab GraphQL Code Injection Flaw Patched
DCRat Campaign Uses SVG HTML Smuggling to Deliver DarkCrystal RAT TanStack Typosquatting npm Supply Chain Attack Axios Supply Chain Attack npm Poisoning eScan Supply Chain Attack Antivirus Compromise APT-36, NCERT WhatsApp Advisory FBI alert, Salesforce Salt Typhoon, APT group ConnectWise ScreenConnect hack Nation-state cyberattack FortiGate Leak - zkLend vulnerability - TRIPLESTRENGTH Threat Actor Group Dark Storm
  • Malware

DCRat Campaign Uses SVG HTML Smuggling to Deliver DarkCrystal RAT

Do Son August 18, 2026 0
Read More Read more about DCRat Campaign Uses SVG HTML Smuggling to Deliver DarkCrystal RAT
BigBlueButton Fixes Maximum Severity Arbitrary File Read Flaw unauthenticated arbitrary file read and BigBlueButton path traversal vulnerability
  • Vulnerability Report

BigBlueButton Fixes Maximum Severity Arbitrary File Read Flaw

Do Son August 18, 2026 0
Read More Read more about BigBlueButton Fixes Maximum Severity Arbitrary File Read Flaw
CVE-2025-62593: Ray RCE Exploited in the Wild, PoC Public CVE-2025-62593 Ray remote code execution vulnerability exploited in the wild DNS rebinding proof-of-concept exploit
  • Vulnerability Report

CVE-2025-62593: Ray RCE Exploited in the Wild, PoC Public

Do Son August 17, 2026 0
Read More Read more about CVE-2025-62593: Ray RCE Exploited in the Wild, PoC Public
Docker CopyEscape Flaw (CVE-2026-17106) Enables Host File Overwrite and Code Execution Docker CopyEscape vulnerability CVE-2026-17106 docker cp file write diagram
  • Vulnerability Report

Docker CopyEscape Flaw (CVE-2026-17106) Enables Host File Overwrite and Code Execution

Do Son August 17, 2026 0
Read More Read more about Docker CopyEscape Flaw (CVE-2026-17106) Enables Host File Overwrite and Code Execution
Red Hat ACM Fixes Five Critical Flaws, Including CVE-2026-72526 RCE Bug (CVSS 9.9) RHACM remote code execution CVE-2026-72526 vulnerability diagram
  • Vulnerability Report

Red Hat ACM Fixes Five Critical Flaws, Including CVE-2026-72526 RCE Bug (CVSS 9.9)

Do Son August 17, 2026 0
Read More Read more about Red Hat ACM Fixes Five Critical Flaws, Including CVE-2026-72526 RCE Bug (CVSS 9.9)
OpenMatter Network to Take Verification Message to Belgrade Blockchain Week 2026 Untitled_design_1_1785345577GFlH2l3KbJ
  • Press Release

OpenMatter Network to Take Verification Message to Belgrade Blockchain Week 2026

cybernewswire August 17, 2026 0
Read More Read more about OpenMatter Network to Take Verification Message to Belgrade Blockchain Week 2026
CVE-2026-19188: Haiwell HMI Gateway Flaw Lets Attackers Execute Arbitrary OS Commands With Root Privileges (CVSS 10.0) CVE-2026-19188 OS command injection in Haiwell HMI Gateway flaw
  • Vulnerability Report

CVE-2026-19188: Haiwell HMI Gateway Flaw Lets Attackers Execute Arbitrary OS Commands With Root Privileges (CVSS 10.0)

Do Son August 17, 2026 0
Read More Read more about CVE-2026-19188: Haiwell HMI Gateway Flaw Lets Attackers Execute Arbitrary OS Commands With Root Privileges (CVSS 10.0)
Anthropic Revenue Surges 14x to $11.5B in Q2 2026 Ahead of IPO Anthropic revenue surge Q2 2026 IPO Claude enterprise growth Wall Street
  • Technology

Anthropic Revenue Surges 14x to $11.5B in Q2 2026 Ahead of IPO

Do Son August 17, 2026 0
Read More Read more about Anthropic Revenue Surges 14x to $11.5B in Q2 2026 Ahead of IPO
Linux AF_PACKET Race (03390aa): PoC Exploit Enables Local Privilege Escalation Linux AF_PACKET hard_header_len race local privilege escalation kernel proof-of-concept exploit to root commit 03390aa
  • Vulnerability Report

Linux AF_PACKET Race (03390aa): PoC Exploit Enables Local Privilege Escalation

Do Son August 17, 2026 0
Read More Read more about Linux AF_PACKET Race (03390aa): PoC Exploit Enables Local Privilege Escalation
Stripe Finalizes $7 Billion Acquisition of OpenRouter Stripe acquiring AI startup OpenRouter, OpenRouter API hub interface
  • Technology

Stripe Finalizes $7 Billion Acquisition of OpenRouter

Do Son August 17, 2026 0
Read More Read more about Stripe Finalizes $7 Billion Acquisition of OpenRouter
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-51990
    A critical remote code execution vulnerability in Sogou Input Method, one of the most widely used Chinese-language input...
    Admin intel📅 Updated: Sep 12, 2026
  • CVE-2026-85706CVSS 10.0
    GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42016CVSS 8.1
    JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42018CVSS 7.5
    JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-84869CVSS 9.9
    A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote...
    CISA KEV📅 Added to KEV: Sep 11, 2026
  • CVE-2026-20079CVSS 10.0
    A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated,...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2025-25249CVSS 8.1
    A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2026-87491
    Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-90608CVSS 9.9
    A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element...
  • CVE-2026-90607CVSS 9.9
    A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function...
  • CVE-2026-90606CVSS 9.9
    A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue...
  • CVE-2026-90605CVSS 9.9
    A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects...
  • CVE-2026-81648CVSS 10.0
    The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply...
  • CVE-2026-90558CVSS 9.8
    sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting...
  • CVE-2026-78159CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code...
  • CVE-2026-78006CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code...
  • CVE-2026-85681CVSS 9.8
    The WP Component WordPress plugin through 2.2.4 does not have any capability...
  • CVE-2026-84171CVSS 9.8
    The WP images upload on piclect WordPress plugin through 1.0 does not...
Powered by CVE WATCHTOWER

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.