Skip to content
September 24, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
ShinyHunters Expands With AI-Powered Vishing, Supply Chain Intrusions, and Insider Recruitment Open VSX Malware String-Fragment Reconstruction DarkCloud Stealer, steganography APT 35 Charming Kitten cyclops
  • Cybercriminals

ShinyHunters Expands With AI-Powered Vishing, Supply Chain Intrusions, and Insider Recruitment

Do Son September 19, 2025 0
Read More Read more about ShinyHunters Expands With AI-Powered Vishing, Supply Chain Intrusions, and Insider Recruitment
MuddyWater APT Shifts Tactics to Custom Malware MuddyWater APT ANY.RUN security incident
  • Cyber Security

MuddyWater APT Shifts Tactics to Custom Malware

Do Son September 19, 2025 0
Read More Read more about MuddyWater APT Shifts Tactics to Custom Malware
XillenStealer: New Open-Source Malware Lowers Cybercrime Barrier XillenStealer, open-source malware
  • Malware

XillenStealer: New Open-Source Malware Lowers Cybercrime Barrier

Do Son September 19, 2025 0
Read More Read more about XillenStealer: New Open-Source Malware Lowers Cybercrime Barrier
CISA Warns of Critical Flaw in Delta DIALink: CVE-2025-58321 (CVSS 10.0) shell-quote command injection AI-Driven Vulnerabilities Q1 2026 Cyber Threats vm2 Sandbox Escape Node.js RCE upKeeper Privilege Escalation CVE-2026-2449 Pharos Controls Vulnerability Root Access Exploit Cybersecurity Vulnerability Roundup CVSS 10.0 Flaws Shadow Archives CVE-2026-0866 MS-Agent Prompt Injection CVE-2026-2256 basic-ftp Path Traversal CVE-2026-27699 telnetd Root Vulnerability CVE-1999-0073 Regression USR-W610 Vulnerabilities End-of-Life IoT Security IceWarp Security Update IceWarp Vulnerabilities Airleader Master Vulnerability CVE-2026-1358 ZLAN5143D Vulnerability CISA ICS Advisory Acronis Cyber Protect Vulnerability CVE-2025-30411 WAGO 852 Vulnerability OT Network Security SandboxJS Vulnerability Sandbox Escape (CVSS 10.0) Kubernetes Local Path Provisioner CVE-2025-62878 CISA Unresponsive Vendors Avation & RISS Vulnerabilities KiloView Vulnerability CVE-2026-1453 OpenClaw RCE vulnerability Johnson Controls Vulnerability CVE-2025-26385 SandboxJS Vulnerability CVE-2026-23830 ibaPDA Vulnerability CVE-2025-14988 Protobuf Vulnerability CVE-2026-0994 AVEVA Process Optimization Vulnerability CVE-2025-61937 ConnectWise PSA Vulnerability CVE-2026-0695 Aruba VIA Vulnerability CVE-2025-37186 aiohttp v3.13.3, Denial of Service (DoS) SmarterMail RCE, CVE-2025-52691 Airoha RACE, Headphone Jacking HPE OneView RCE CVE-2025-37164 FreePBX Auth Bypass, PBX Takeover ScreenConnect Config Flaw, Untrusted Extensions Ruby SAML Auth Bypass, XML Parser Differential Devolutions SQL Injection, Password Manager Flaw Vivotek Unauthenticated RCE, EOL IP Camera Flaw Lynx+ Critical Flaw, Unauthenticated Reset Firebox Default Credentials, CVE-2025-59396 Veeder-Root RCE, Critical ATG Flaw ArcGIS Server SQLi Watchdoc RCE, CVE-2025-58384 Delta DIALink Daikin Security Gateway, authentication bypass Frostbyte10, industrial controller security SunPower, vulnerability Ubiquiti UniFi Connect, EV Station Vulnerabilities Adobe Experience Manager, RCE Vulnerability UniFi Access, Command Injection LDAPNightmare - CVE-2025-1316
  • Vulnerability Report

CISA Warns of Critical Flaw in Delta DIALink: CVE-2025-58321 (CVSS 10.0)

Do Son September 19, 2025 0
Read More Read more about CISA Warns of Critical Flaw in Delta DIALink: CVE-2025-58321 (CVSS 10.0)
North Korean Hackers Evolve Tactics with New Malware Campaign North Korea malware North Korea, OFAC sanctions DPRK AI hiring, Wagemole campaigns
  • Malware

North Korean Hackers Evolve Tactics with New Malware Campaign

Do Son September 19, 2025 0
Read More Read more about North Korean Hackers Evolve Tactics with New Malware Campaign
Why Patterns Repeat in Human Behavior Img_2025_09_16_18_10_12
  • Technique

Why Patterns Repeat in Human Behavior

Do Son September 18, 2025
Read More Read more about Why Patterns Repeat in Human Behavior
Palo Alto Networks Acknowledges SquareX Research on Limitations of SWGs Against Last Mile Reassembly Attacks YOBB-SWGs-CyberNews-1200x720_1758100200j4Yf6WQGHL
  • Press Release

Palo Alto Networks Acknowledges SquareX Research on Limitations of SWGs Against Last Mile Reassembly Attacks

cybernewswire September 18, 2025 0
Read More Read more about Palo Alto Networks Acknowledges SquareX Research on Limitations of SWGs Against Last Mile Reassembly Attacks
SolarWinds Issues Advisory on Salesforce Data Breach Linked to Salesloft Drift Serv-U RCE, Authenticated RCE CVE-2024-0692 Salesforce breach
  • Data Leak

SolarWinds Issues Advisory on Salesforce Data Breach Linked to Salesloft Drift

Do Son September 18, 2025 0
Read More Read more about SolarWinds Issues Advisory on Salesforce Data Breach Linked to Salesloft Drift
Google Discover Evolves into a Multimedia Hub, Integrating Instagram, X, and YouTube Google Discover, social media integration
  • Technology

Google Discover Evolves into a Multimedia Hub, Integrating Instagram, X, and YouTube

Do Son September 18, 2025 0
Read More Read more about Google Discover Evolves into a Multimedia Hub, Integrating Instagram, X, and YouTube
Microsoft Launches MCP Server for AI to Access Official Documentation Microsoft MAI-Image-1, In-House AI Microsoft Learn, MCP Server Windows Kernel Vulnerability - CVE-2024-38106 PoC exploit
  • Technology

Microsoft Launches MCP Server for AI to Access Official Documentation

Do Son September 18, 2025 0
Read More Read more about Microsoft Launches MCP Server for AI to Access Official Documentation
Warning to Mac Studio M3 Ultra Owners: Postpone Your macOS Upgrade Mac Pro discontinued 2026 iOS 27 Snow Leopard update iOS 27 Maintenance Apple Stability Focus M5 MacBook, Studio Display macOS update, Mac Studio M3 Ultra Perplexity Apple, Perplexity AI Acquisition Mac Mini M2, Power Issue macOS, Intel Macs
  • Technology

Warning to Mac Studio M3 Ultra Owners: Postpone Your macOS Upgrade

Do Son September 18, 2025 0
Read More Read more about Warning to Mac Studio M3 Ultra Owners: Postpone Your macOS Upgrade
Notepad Goes Private: Microsoft Adds On-Device AI Notepad, On-device AI
  • Windows

Notepad Goes Private: Microsoft Adds On-Device AI

Do Son September 18, 2025 0
Read More Read more about Notepad Goes Private: Microsoft Adds On-Device AI
Slow Charger? Your Apple Watch Now Has a New Warning for That Apple Watch EU Ban, Wi-Fi Sync Apple Watch blood oxygen workaround
  • Technology

Slow Charger? Your Apple Watch Now Has a New Warning for That

Do Son September 18, 2025 0
Read More Read more about Slow Charger? Your Apple Watch Now Has a New Warning for That
Microsoft Paint’s New Features Are Making It More Like Photoshop Microsoft Developer Account Suspension Microsoft Web Activation Portal Driver Signing Account Suspension Windows 11 Smart App Control Windows 11 SE end of support, Microsoft education hardware pivot Microsoft Product Activation Portal 2025, Windows telephone activation discontinued Windows Update Naming, Microsoft Update Microsoft earnings, OpenAI valuation VBScript deprecation Microsoft Pakistan, Office Closure Microsoft job cuts Microsoft Own AI Models
  • Windows

Microsoft Paint’s New Features Are Making It More Like Photoshop

Do Son September 18, 2025 0
Read More Read more about Microsoft Paint’s New Features Are Making It More Like Photoshop
Meta’s New AI Tools Are Redefining the Metaverse Metaverse, AI Meta smart glasses
  • Technology

Meta’s New AI Tools Are Redefining the Metaverse

Do Son September 18, 2025 0
Read More Read more about Meta’s New AI Tools Are Redefining the Metaverse
New iPhone Air Camera Flaw: What You Need to Know iOS 27 AirDrop speed, AirDrop transfer speed, AirDrop file transfer, AWDL protocol iPhone 17e rumors iPhone Air 2 Roadmap Apple Launch Cadence Shift iPhone Air sales collapse Apple iPhone Fold iPhone Air, thinnest iPhone camera flaw
  • Technology

New iPhone Air Camera Flaw: What You Need to Know

Do Son September 18, 2025 0
Read More Read more about New iPhone Air Camera Flaw: What You Need to Know
The UK’s AI Revolution: NVIDIA’s £11 Billion Plan AI Infrastructure, NVIDIA
  • Technology

The UK’s AI Revolution: NVIDIA’s £11 Billion Plan

Do Son September 18, 2025 0
Read More Read more about The UK’s AI Revolution: NVIDIA’s £11 Billion Plan
Three Bugs Degraded Claude’s Response Quality Anthropic Claude Lawsuit Claude Max limits, AI subscription lawsuit, Claude Pro vs Max Claude Mythos security audit Claude Identity Verification Anthropic DMCA GitHub takedown bugs Nuclear weapons Xcode, Claude AI Anthropic, Claude Sonnet 4 Claude AI, AI safety
  • Technology

Three Bugs Degraded Claude’s Response Quality

Do Son September 18, 2025 0
Read More Read more about Three Bugs Degraded Claude’s Response Quality
A Safer Chat: OpenAI Unveils ChatGPT for Teens GPT-OSS-SafeGuard, AI safety ChatGPT Memory Management, Paid Feature ChatGPT Teens ChatGPT, mental health
  • Technology

A Safer Chat: OpenAI Unveils ChatGPT for Teens

Do Son September 18, 2025 0
Read More Read more about A Safer Chat: OpenAI Unveils ChatGPT for Teens
The MacBook is Getting a Touchscreen, But Not How You Think MacBook Touchscreen Apple OS Betas, Liquid Glass Design
  • Technology

The MacBook is Getting a Touchscreen, But Not How You Think

Do Son September 18, 2025 0
Read More Read more about The MacBook is Getting a Touchscreen, But Not How You Think
Meta Unveils Ray-Ban Display: Smart Glasses with a Built-In Screen Meta Reality Labs restructuring, AI wearables pivot Meta Alan Dye Hire Apple Design Defection smart glasses, Ray-Ban Display
  • Technology

Meta Unveils Ray-Ban Display: Smart Glasses with a Built-In Screen

Do Son September 18, 2025 0
Read More Read more about Meta Unveils Ray-Ban Display: Smart Glasses with a Built-In Screen
SonicWall Security Incident: Exposed Backups Could Put Your Firewall at Risk SonicWall Zero-Day, SMA1000 Exploit Chain SonicWall, firewall configuration CVE-2024-29010 & CVE-2024-29011 SonicWall NetExtender VPN Vulnerability
  • Data Leak

SonicWall Security Incident: Exposed Backups Could Put Your Firewall at Risk

Do Son September 18, 2025 0
Read More Read more about SonicWall Security Incident: Exposed Backups Could Put Your Firewall at Risk
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-94127CVSS 9.8
    When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-85102CVSS 9.8
    Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93616CVSS 9.8
    A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93952CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-32996CVSS 7.3
    A vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.
    Admin intel📅 Updated: Sep 22, 2026
  • CVE-2026-7273CVSS 8.8
    A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a...
    CISA KEV📅 Added to KEV: Sep 21, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-78312CVSS 9.1
    Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
    📅 Updated: Sep 24, 2026
  • CVE-2026-78308CVSS 9.8
    Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022.
    📅 Updated: Sep 24, 2026
  • CVE-2026-84502CVSS 9.9
    A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not...
    📅 Updated: Sep 24, 2026
  • CVE-2026-84719CVSS 9.9
    A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission...
    📅 Updated: Sep 24, 2026
  • CVE-2026-84474CVSS 9.9
    A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed...
    📅 Updated: Sep 24, 2026
  • CVE-2026-75884CVSS 9.1
    A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts...
    📅 Updated: Sep 24, 2026
  • CVE-2026-12564CVSS 9.6
    A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads...
    📅 Updated: Sep 24, 2026
  • CVE-2026-86708CVSS 10.0
    ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private...
    📅 Updated: Sep 24, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.