Skip to content
September 27, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Microsoft 365 Startup Boost: Faster Apps, But Is It On by Default Now? student discount Microsoft 365, Intelligent Services Microsoft 365 UWP, App Deprecation Microsoft 365, Startup Boost Windows 10 EOL, Microsoft 365 Support Protocol Deprecation Microsoft 365 Updates, IT Admin Alert Microsoft 365 VPN shut down Microsoft Authenticator, password manager Windows 10 Microsoft 365 Microsoft nonprofit policy, software donations
  • Windows

Microsoft 365 Startup Boost: Faster Apps, But Is It On by Default Now?

Do Son July 18, 2025 0
Read More Read more about Microsoft 365 Startup Boost: Faster Apps, But Is It On by Default Now?
Claude Code Hits Unexpected Usage Limits: Anthropic Faces Backlash Over Pricing Opacity Claude Code Limits, Anthropic Transparency
  • Technology

Claude Code Hits Unexpected Usage Limits: Anthropic Faces Backlash Over Pricing Opacity

Do Son July 18, 2025 0
Read More Read more about Claude Code Hits Unexpected Usage Limits: Anthropic Faces Backlash Over Pricing Opacity
OpenAI Unveils ChatGPT Agent: The AI That Acts, Plans, and Executes Complex Tasks for You ChatGPT Agent, AI Execution
  • Technology

OpenAI Unveils ChatGPT Agent: The AI That Acts, Plans, and Executes Complex Tasks for You

Do Son July 18, 2025 0
Read More Read more about OpenAI Unveils ChatGPT Agent: The AI That Acts, Plans, and Executes Complex Tasks for You
Amazon’s AI Boom Collides with Climate Pledge: Carbon Emissions Soar 6% Amazon AI, Carbon Footprint Nova Sonic, speech AI Amazon Nova
  • Technology

Amazon’s AI Boom Collides with Climate Pledge: Carbon Emissions Soar 6%

Do Son July 18, 2025 0
Read More Read more about Amazon’s AI Boom Collides with Climate Pledge: Carbon Emissions Soar 6%
Mark Zuckerberg & Meta Directors Settle $8 Billion Privacy Lawsuit Over Cambridge Analytica Meta Settlement, Privacy Lawsuit
  • Data Leak

Mark Zuckerberg & Meta Directors Settle $8 Billion Privacy Lawsuit Over Cambridge Analytica

Do Son July 18, 2025 0
Read More Read more about Mark Zuckerberg & Meta Directors Settle $8 Billion Privacy Lawsuit Over Cambridge Analytica
Google Sues BadBox 2.0 Botnet Operators, Protecting 10 Million+ Infected Android Devices BadBox 2.0, Android Botnet Alien spyware - CVE-2024-43093
  • Malware

Google Sues BadBox 2.0 Botnet Operators, Protecting 10 Million+ Infected Android Devices

Do Son July 18, 2025 0
Read More Read more about Google Sues BadBox 2.0 Botnet Operators, Protecting 10 Million+ Infected Android Devices
Grafana Patches XSS (CVE-2025-6023) and Open Redirect (CVE-2025-6197) Flaws in Recent Security Release Grafana SCIM Flaw CVE-2025-41115 Grafana Vulnerabilities, XSS Flaw Grafana security alert, XSS patch
  • Vulnerability Report

Grafana Patches XSS (CVE-2025-6023) and Open Redirect (CVE-2025-6197) Flaws in Recent Security Release

Do Son July 18, 2025 0
Read More Read more about Grafana Patches XSS (CVE-2025-6023) and Open Redirect (CVE-2025-6197) Flaws in Recent Security Release
GitHub Abused in Amadey MaaS Campaign: Talos Uncovers Malware-as-a-Service Network Leveraging Public Repositories GitHub MaaS, Emmenhtal Loader
  • Malware

GitHub Abused in Amadey MaaS Campaign: Talos Uncovers Malware-as-a-Service Network Leveraging Public Repositories

Do Son July 18, 2025 0
Read More Read more about GitHub Abused in Amadey MaaS Campaign: Talos Uncovers Malware-as-a-Service Network Leveraging Public Repositories
Critical Flaw (CVSS 9.8) in Ubiquiti UniFi Access Devices Allows RCE shell-quote command injection AI-Driven Vulnerabilities Q1 2026 Cyber Threats vm2 Sandbox Escape Node.js RCE upKeeper Privilege Escalation CVE-2026-2449 Pharos Controls Vulnerability Root Access Exploit Cybersecurity Vulnerability Roundup CVSS 10.0 Flaws Shadow Archives CVE-2026-0866 MS-Agent Prompt Injection CVE-2026-2256 basic-ftp Path Traversal CVE-2026-27699 telnetd Root Vulnerability CVE-1999-0073 Regression USR-W610 Vulnerabilities End-of-Life IoT Security IceWarp Security Update IceWarp Vulnerabilities Airleader Master Vulnerability CVE-2026-1358 ZLAN5143D Vulnerability CISA ICS Advisory Acronis Cyber Protect Vulnerability CVE-2025-30411 WAGO 852 Vulnerability OT Network Security SandboxJS Vulnerability Sandbox Escape (CVSS 10.0) Kubernetes Local Path Provisioner CVE-2025-62878 CISA Unresponsive Vendors Avation & RISS Vulnerabilities KiloView Vulnerability CVE-2026-1453 OpenClaw RCE vulnerability Johnson Controls Vulnerability CVE-2025-26385 SandboxJS Vulnerability CVE-2026-23830 ibaPDA Vulnerability CVE-2025-14988 Protobuf Vulnerability CVE-2026-0994 AVEVA Process Optimization Vulnerability CVE-2025-61937 ConnectWise PSA Vulnerability CVE-2026-0695 Aruba VIA Vulnerability CVE-2025-37186 aiohttp v3.13.3, Denial of Service (DoS) SmarterMail RCE, CVE-2025-52691 Airoha RACE, Headphone Jacking HPE OneView RCE CVE-2025-37164 FreePBX Auth Bypass, PBX Takeover ScreenConnect Config Flaw, Untrusted Extensions Ruby SAML Auth Bypass, XML Parser Differential Devolutions SQL Injection, Password Manager Flaw Vivotek Unauthenticated RCE, EOL IP Camera Flaw Lynx+ Critical Flaw, Unauthenticated Reset Firebox Default Credentials, CVE-2025-59396 Veeder-Root RCE, Critical ATG Flaw ArcGIS Server SQLi Watchdoc RCE, CVE-2025-58384 Delta DIALink Daikin Security Gateway, authentication bypass Frostbyte10, industrial controller security SunPower, vulnerability Ubiquiti UniFi Connect, EV Station Vulnerabilities Adobe Experience Manager, RCE Vulnerability UniFi Access, Command Injection LDAPNightmare - CVE-2025-1316
  • Vulnerability

Critical Flaw (CVSS 9.8) in Ubiquiti UniFi Access Devices Allows RCE

Do Son July 18, 2025 0
Read More Read more about Critical Flaw (CVSS 9.8) in Ubiquiti UniFi Access Devices Allows RCE
GhostContainer: Kaspersky Uncovers Stealthy Backdoor Infiltrating Government & High-Tech Exchange Servers Exchange Backdoor, GhostContainer
  • Malware

GhostContainer: Kaspersky Uncovers Stealthy Backdoor Infiltrating Government & High-Tech Exchange Servers

Do Son July 18, 2025 0
Read More Read more about GhostContainer: Kaspersky Uncovers Stealthy Backdoor Infiltrating Government & High-Tech Exchange Servers
CVE-2025-34300 (CVSS 10): Critical RCE Flaw in Lighthouse Studio’s CGI Scripts Threatens Survey Servers Worldwide Lighthouse Studio RCE, Survey Platform Vulnerability
  • Vulnerability Report

CVE-2025-34300 (CVSS 10): Critical RCE Flaw in Lighthouse Studio’s CGI Scripts Threatens Survey Servers Worldwide

Do Son July 18, 2025 0
Read More Read more about CVE-2025-34300 (CVSS 10): Critical RCE Flaw in Lighthouse Studio’s CGI Scripts Threatens Survey Servers Worldwide
Massistant: China’s New Mobile Forensics App Deepens Digital Surveillance Honeywell CCTV Vulnerability CVE-2026-1670 EagleMsgSpy Spyware Tool ResidentBat Spyware, Belarusian KGB Surveillance
  • Data Leak

Massistant: China’s New Mobile Forensics App Deepens Digital Surveillance

Do Son July 18, 2025 0
Read More Read more about Massistant: China’s New Mobile Forensics App Deepens Digital Surveillance
New macOS Infostealer Slips Past Apple’s Defenses with Code Signing and Notarization macOS Infostealer, Apple Notarization Bypass
  • Malware

New macOS Infostealer Slips Past Apple’s Defenses with Code Signing and Notarization

Do Son July 18, 2025 0
Read More Read more about New macOS Infostealer Slips Past Apple’s Defenses with Code Signing and Notarization
ISC Warns of Cache Poisoning and Crash Risks in BIND: What You Need to Know About CVE-2025-40776 and CVE-2025-40777 BIND 9 Vulnerability CVE-2025-13878 BIND Cache Poisoning, DNS RCE BIND Vulnerabilities, DNS Security BIND 9 vulnerabilities BIND vulnerability, DNS server crash
  • Vulnerability Report

ISC Warns of Cache Poisoning and Crash Risks in BIND: What You Need to Know About CVE-2025-40776 and CVE-2025-40777

Do Son July 18, 2025 0
Read More Read more about ISC Warns of Cache Poisoning and Crash Risks in BIND: What You Need to Know About CVE-2025-40776 and CVE-2025-40777
H2Miner Botnet Unleashes Lcrypt0rx: Flawed, AI-Generated Ransomware with Zero Detection Rates AI Ransomware, H2Miner Evolution
  • Malware

H2Miner Botnet Unleashes Lcrypt0rx: Flawed, AI-Generated Ransomware with Zero Detection Rates

Do Son July 18, 2025 0
Read More Read more about H2Miner Botnet Unleashes Lcrypt0rx: Flawed, AI-Generated Ransomware with Zero Detection Rates
Hijacking the Cloud: How a Misconfigured App Can Become a Global Admin in Entra ID Entra ID Impersonation, Privilege Escalation
  • Vulnerability Report

Hijacking the Cloud: How a Misconfigured App Can Become a Global Admin in Entra ID

Do Son July 18, 2025 0
Read More Read more about Hijacking the Cloud: How a Misconfigured App Can Become a Global Admin in Entra ID
SquareX Collaborates with Top Fortune 500 CISOs to Launch The Browser Security Field Manual at Black Hat TheBrowserSecurityFieldManual-Hero_Image-1200x720_175272573813MxoLQcOJ
  • Press Release

SquareX Collaborates with Top Fortune 500 CISOs to Launch The Browser Security Field Manual at Black Hat

cybernewswire July 17, 2025 0
Read More Read more about SquareX Collaborates with Top Fortune 500 CISOs to Launch The Browser Security Field Manual at Black Hat
Arm’s SME2 Supercharges Mobile AI: 6x Faster Responses & On-Device Gemma 3 Arm Physical AI 2026, AI-Defined Platforms CVE-2022-46891 Arm SME2, Mobile AI Performance
  • Technology

Arm’s SME2 Supercharges Mobile AI: 6x Faster Responses & On-Device Gemma 3

Do Son July 17, 2025 0
Read More Read more about Arm’s SME2 Supercharges Mobile AI: 6x Faster Responses & On-Device Gemma 3
ChatGPT Takes Aim at Microsoft Office: OpenAI’s New “Agent” Edits Spreadsheets & Presentations Directly OpenAI token price reduction OpenAI Deployment Company DeployCo OpenAI IPO strategy OpenAI Privacy Filter 1.5B OpenAI $122 billion funding OpenAI GitHub alternative OpenAI military agreement 2026 OpenAI Stargate project collapse NVIDIA OpenAI investment stall ChatGPT Go $8 subscription, OpenAI GPT-5.2 Instant ads OpenAI Torch acquisition, Unified Medical Memory OpenAI Head of Preparedness 2025, Sam Altman AI safety lawsuits ChatGPT Advertising Speculation OpenAI Ad Code Denial OpenAI AI Confession Hallucination Mitigation ChatGPT Quality Focus OpenAI Gemini Red Alert ChatGPT Login, AI ecosystem OpenAI Mental Health, AI Well-Being Council ChatGPT Instant Checkout, Agentic Commerce OpenAI cloud computing OpenAI, startup incubator OpenAI chips, NVIDIA competition AI competition, antitrust lawsuit GPT-5, OpenAI Livestream OpenAI Open-Weight, AI Models OpenAI Infrastructure, AI Data Centers ChatGPT Business, Office Productivity OpenAI Open-Weight Model, WindSurf Acquisition OpenAI AI Browser, ChatGPT Integration Mattel AI, OpenAI Partnership OpenAI o3, Price Cut OpenAI's Next-Gen AI: O3-Pro's Enhanced Reasoning PowerOpenAI profit OpenAI Bid OpenAI Social Network ChatGPT Social OpenAI Non-profit OpenAI UAE ChatGPT Plus free
  • Technology

ChatGPT Takes Aim at Microsoft Office: OpenAI’s New “Agent” Edits Spreadsheets & Presentations Directly

Do Son July 17, 2025 0
Read More Read more about ChatGPT Takes Aim at Microsoft Office: OpenAI’s New “Agent” Edits Spreadsheets & Presentations Directly
FCC to Vote on Banning Chinese Tech in US Undersea Cables Amid National Security Concerns Undertow Vulnerability CVE-2025-12543 CVE-2025-0107: PoC Exploit Code Undersea Cable Security, China Tech Ban
  • Technology

FCC to Vote on Banning Chinese Tech in US Undersea Cables Amid National Security Concerns

Do Son July 17, 2025 0
Read More Read more about FCC to Vote on Banning Chinese Tech in US Undersea Cables Amid National Security Concerns
New Web3 Identification Standard: IT Expert launches an innovative decentralized platform without servers and KYC CVE-2025-20059
  • Technique

New Web3 Identification Standard: IT Expert launches an innovative decentralized platform without servers and KYC

Dan Agbo July 17, 2025 0
Read More Read more about New Web3 Identification Standard: IT Expert launches an innovative decentralized platform without servers and KYC
AWS Unleashes Enterprise AI: Bedrock AgentCore & $100M Boost for AI Agent Development AWS AI Agents, Enterprise AI
  • Technology

AWS Unleashes Enterprise AI: Bedrock AgentCore & $100M Boost for AI Agent Development

Do Son July 17, 2025 0
Read More Read more about AWS Unleashes Enterprise AI: Bedrock AgentCore & $100M Boost for AI Agent Development
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 23, 2026
  • CVE-2026-94127CVSS 9.8
    When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-85102CVSS 9.8
    Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93616CVSS 9.8
    A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-100741CVSS 9.8
    Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3.3 on Windows,...
    📅 Updated: Sep 27, 2026
  • CVE-2026-94130CVSS 9.3
    Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injection...
    📅 Updated: Sep 27, 2026
  • CVE-2026-97161CVSS 9.2
    Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
    📅 Updated: Sep 27, 2026
  • CVE-2026-97163CVSS 10.0
    Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
    📅 Updated: Sep 27, 2026
  • CVE-2026-94132CVSS 9.5
    Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension <...
    📅 Updated: Sep 27, 2026
  • CVE-2026-97160CVSS 9.4
    Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
    📅 Updated: Sep 27, 2026
  • CVE-2026-100835CVSS 9.1
    Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report that verified...
    📅 Updated: Sep 27, 2026
  • CVE-2026-100721CVSS 9.5
    vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with...
    📅 Updated: Sep 27, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.