Skip to content
July 21, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
CISA Adds Oracle E-Business Suite and KNX Flaws to KEV Catalog CISA KEV catalog additions CVE-2026-46817 and CVE-2023-4346 illustration
  • Vulnerability Report

CISA Adds Oracle E-Business Suite and KNX Flaws to KEV Catalog

Do Son July 16, 2026 0
Read More Read more about CISA Adds Oracle E-Business Suite and KNX Flaws to KEV Catalog
Splunk Fixes Three Splunk Enterprise Vulnerabilities Led by CVE-2026-20296 CSRF Flaw Splunk Enterprise vulnerabilities CVE-2026-20296 security advisory illustration
  • Vulnerability Report

Splunk Fixes Three Splunk Enterprise Vulnerabilities Led by CVE-2026-20296 CSRF Flaw

Do Son July 16, 2026 0
Read More Read more about Splunk Fixes Three Splunk Enterprise Vulnerabilities Led by CVE-2026-20296 CSRF Flaw
NGINX Code Execution Vulnerability CVE-2026-42533 Patched Alongside Two Memory Flaws NGINX code execution vulnerability CVE-2026-42533 advisory illustration
  • Vulnerability Report

NGINX Code Execution Vulnerability CVE-2026-42533 Patched Alongside Two Memory Flaws

Do Son July 16, 2026 0
Read More Read more about NGINX Code Execution Vulnerability CVE-2026-42533 Patched Alongside Two Memory Flaws
RabbitMQ Patches Two Critical Authentication Bypass Flaws RabbitMQ authentication bypass via TLS client cert forgery and OAuth2 JWKS flaw
  • Vulnerability Report

RabbitMQ Patches Two Critical Authentication Bypass Flaws

Do Son July 15, 2026 0
Read More Read more about RabbitMQ Patches Two Critical Authentication Bypass Flaws
Fake Braintree NuGet Package Skims Credit Cards and Steals Merchant API Keys Braintree NuGet typosquat credit card skimmer stealing payment data and merchant API keys
  • Malware

Fake Braintree NuGet Package Skims Credit Cards and Steals Merchant API Keys

Do Son July 15, 2026 0
Read More Read more about Fake Braintree NuGet Package Skims Credit Cards and Steals Merchant API Keys
Pulse Security Debuts Operational Management Platform Built for Security Leaders pulse_security_ai_logo_stack_rgb_lightmode_black_t_1784060191DoBnutvtFo
  • Press Release

Pulse Security Debuts Operational Management Platform Built for Security Leaders

cybernewswire July 15, 2026 0
Read More Read more about Pulse Security Debuts Operational Management Platform Built for Security Leaders
CVE-2026-53412: CVSS 9.8 Zoom Vulnerability Allows Unauthenticated Account Takeover Zoom vulnerability CVE-2026-53412 account takeover flaw in Zoom Workplace for Windows
  • Vulnerability Report

CVE-2026-53412: CVSS 9.8 Zoom Vulnerability Allows Unauthenticated Account Takeover

Do Son July 15, 2026 0
Read More Read more about CVE-2026-53412: CVSS 9.8 Zoom Vulnerability Allows Unauthenticated Account Takeover
Clubfoot Wolf Hits Russian Firms With NetSupport Manager exfiltrating AWS credentials - fabrice package
  • Cybercriminals

Clubfoot Wolf Hits Russian Firms With NetSupport Manager

Do Son July 15, 2026 0
Read More Read more about Clubfoot Wolf Hits Russian Firms With NetSupport Manager
JetBrains Fixes CVSS 10 YouTrack Authentication Bypass and Five More Flaws in IntelliJ IDEA and TeamCity JetBrains vulnerabilities CVE-2026-62422 YouTrack authentication bypass CVSS 10
  • Vulnerability Report

JetBrains Fixes CVSS 10 YouTrack Authentication Bypass and Five More Flaws in IntelliJ IDEA and TeamCity

Do Son July 15, 2026 0
Read More Read more about JetBrains Fixes CVSS 10 YouTrack Authentication Bypass and Five More Flaws in IntelliJ IDEA and TeamCity
Insignary Launches Clarity On-Demand: SBOMs, No Annual Commitment Required Insignary_logo_full_1200x720_1_1784050762w8XHmBCjEL
  • Press Release

Insignary Launches Clarity On-Demand: SBOMs, No Annual Commitment Required

cybernewswire July 15, 2026 0
Read More Read more about Insignary Launches Clarity On-Demand: SBOMs, No Annual Commitment Required
Four Critical Coolify Vulnerabilities Allow Remote Code Execution and Cross-Team Server Access Coolify vulnerabilities enabling remote code execution and cross-tenant server access in the self-hosted PaaS
  • Vulnerability Report

Four Critical Coolify Vulnerabilities Allow Remote Code Execution and Cross-Team Server Access

Do Son July 15, 2026 0
Read More Read more about Four Critical Coolify Vulnerabilities Allow Remote Code Execution and Cross-Team Server Access
Seedream 5.0 Pro Photo Generator: Advancing AI-Assisted Visual Content Creation CVE-2024-31070 & CVE-2024-36491
  • Technique

Seedream 5.0 Pro Photo Generator: Advancing AI-Assisted Visual Content Creation

Do Son July 15, 2026 0
Read More Read more about Seedream 5.0 Pro Photo Generator: Advancing AI-Assisted Visual Content Creation
Cursor Zero-Day Vulnerability Remains Unpatched After Seven Months Cursor zero day vulnerability exploitation diagram, AI coding assistant security threat analysis
  • Vulnerability Report

Cursor Zero-Day Vulnerability Remains Unpatched After Seven Months

Do Son July 15, 2026 0
Read More Read more about Cursor Zero-Day Vulnerability Remains Unpatched After Seven Months
Google Images Turns 25: AI Personalization and Nano Banana Generation Arrive in Search Google Images 25th anniversary AI redesign with Nano Banana image generation
  • Technology

Google Images Turns 25: AI Personalization and Nano Banana Generation Arrive in Search

Do Son July 15, 2026 0
Read More Read more about Google Images Turns 25: AI Personalization and Nano Banana Generation Arrive in Search
CrySome RAT Spread Through Fake Freight Rate Confirmation Phishing NATS-as-C2 Sysdig CVE-2026-33017 Langflow RCE Microsoft Phone Link Hijack CloudZ Pheno Plugin Insider Threat BlackCat (ALPHV) OFAC Sanctions DPRK IT Workers Transparent Tribe APT36 React2Shell, EtherRAT SideWinder Espionage, Netlify Phishing DDNS Abuse, C2 Infrastructure Hacking Health Club
  • Malware

CrySome RAT Spread Through Fake Freight Rate Confirmation Phishing

Do Son July 15, 2026 0
Read More Read more about CrySome RAT Spread Through Fake Freight Rate Confirmation Phishing
RedWing Android Malware Rents Out Spyware and Bank Theft on Telegram RedWing Android malware panel sold as malware-as-a-service on Telegram with banking overlays
  • Malware

RedWing Android Malware Rents Out Spyware and Bank Theft on Telegram

Do Son July 15, 2026 0
Read More Read more about RedWing Android Malware Rents Out Spyware and Bank Theft on Telegram
CVE-2026-10577: CVSS 10 Access Control Vulnerability Hits Rockwell Automation 1715 Redundant I/O Modules Rockwell Automation vulnerability CVE-2026-10577 access control flaw in 1715 Redundant I/O
  • Vulnerability Report

CVE-2026-10577: CVSS 10 Access Control Vulnerability Hits Rockwell Automation 1715 Redundant I/O Modules

Do Son July 15, 2026 0
Read More Read more about CVE-2026-10577: CVSS 10 Access Control Vulnerability Hits Rockwell Automation 1715 Redundant I/O Modules
Malicious Go Module Exposes a 222-Repository GitHub Lure Network Malicious Go module exposing GitHub lure network of 222 repositories in Operation Muck and Load
  • Cybercriminals

Malicious Go Module Exposes a 222-Repository GitHub Lure Network

Do Son July 15, 2026 0
Read More Read more about Malicious Go Module Exposes a 222-Repository GitHub Lure Network
GodDamn Ransomware Rebrands Beast and Uses a Malicious Signed Driver to Disable Defenses digital-hacker
  • Malware

GodDamn Ransomware Rebrands Beast and Uses a Malicious Signed Driver to Disable Defenses

Do Son July 15, 2026 0
Read More Read more about GodDamn Ransomware Rebrands Beast and Uses a Malicious Signed Driver to Disable Defenses
Notepad++ v8.9.7 Fixes 5 Vulnerabilities, All With Public Details and PoC Exploit Code Notepad++ vulnerabilities public PoC exploit code path traversal CVE-2026-52886
  • Vulnerability Report

Notepad++ v8.9.7 Fixes 5 Vulnerabilities, All With Public Details and PoC Exploit Code

Do Son July 15, 2026 0
Read More Read more about Notepad++ v8.9.7 Fixes 5 Vulnerabilities, All With Public Details and PoC Exploit Code
Chrome 150 Security Update Fixes 15 Flaws, Including Two Critical Use-After-Free Bugs Chrome security update 150 fixing critical use-after-free flaws CVE-2026-15764 and CVE-2026-15765
  • Vulnerability Report

Chrome 150 Security Update Fixes 15 Flaws, Including Two Critical Use-After-Free Bugs

Do Son July 15, 2026 0
Read More Read more about Chrome 150 Security Update Fixes 15 Flaws, Including Two Critical Use-After-Free Bugs
Passkey Phishing Campaign Uses Vishing Calls to Hijack Microsoft Entra Accounts Passkey phishing vishing attack targeting Microsoft Entra passkey enrollment by O-UNC-066
  • Cybercriminals

Passkey Phishing Campaign Uses Vishing Calls to Hijack Microsoft Entra Accounts

Do Son July 15, 2026 0
Read More Read more about Passkey Phishing Campaign Uses Vishing Calls to Hijack Microsoft Entra Accounts
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intel📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intel📅 Updated: Jul 21, 2026
  • CVE-2026-6875CVSS 9.5
    ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability...
    Admin intel📅 Updated: Jul 18, 2026
  • CVE-2026-39808CVSS 9.8
    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox...
    CISA KEV📅 Added to KEV: Jul 16, 2026
  • CVE-2026-25089CVSS 9.8
    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox...
    CISA KEV📅 Added to KEV: Jul 16, 2026
  • CVE-2026-58644CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    CISA KEV📅 Added to KEV: Jul 16, 2026
  • CVE-2023-4346CVSS 7.5
    KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to...
    CISA KEV📅 Added to KEV: Jul 15, 2026
  • CVE-2026-53362
    In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation...
    Admin intel📅 Updated: Jul 14, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-64625CVSS 9.8
    AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps...
  • CVE-2026-53595CVSS 9.4
    FreeScout is a free help desk and shared inbox built with PHP's...
  • CVE-2026-44231CVSS 9.1
    RT is an open source, enterprise-grade issue and ticket tracking system. Versions...
  • CVE-2026-63766CVSS 9.8
    GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where...
  • CVE-2026-63767CVSS 9.8
    ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization...
  • CVE-2026-39878CVSS 9.3
    Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability...
  • CVE-2026-60034CVSS 9.4
    The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised...
  • CVE-2026-60032CVSS 9.4
    The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload,...
  • CVE-2026-54051CVSS 9.9
    Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent...
  • CVE-2026-41252CVSS 9.8
    xrdp is an open source RDP server. Versions 0.10.6 and prior contain...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.