Skip to content
September 29, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
MongoDB Flaws Allow Privilege Escalation & DoS MongoDB Vulnerability CVE-2026-25611 MongoDB zlib vulnerability, CVE-2025-14847 MongoDB Vulnerabilities, Data Access CVE-2024-6376 CVE-2025-0755
  • Vulnerability

MongoDB Flaws Allow Privilege Escalation & DoS

Do Son July 8, 2025 0
Read More Read more about MongoDB Flaws Allow Privilege Escalation & DoS
NetSupport RAT Returns: Weaponized via WordPress & “ClickFix” for Remote Access NetSupport RAT, ClickFix Technique
  • Malware

NetSupport RAT Returns: Weaponized via WordPress & “ClickFix” for Remote Access

Do Son July 8, 2025 0
Read More Read more about NetSupport RAT Returns: Weaponized via WordPress & “ClickFix” for Remote Access
New BERT Ransomware Unleashed: Multi-Threaded Attacks Hit Windows, Linux & ESXi with REvil Links ramsomware
  • Cybercriminals

New BERT Ransomware Unleashed: Multi-Threaded Attacks Hit Windows, Linux & ESXi with REvil Links

Do Son July 8, 2025 0
Read More Read more about New BERT Ransomware Unleashed: Multi-Threaded Attacks Hit Windows, Linux & ESXi with REvil Links
RedLine Stealer Unleashed: Inno Setup Installers Abused for Stealthy Data Theft & Cryptowallet Draining RedLine Stealer, Inno Setup Exploit
  • Malware

RedLine Stealer Unleashed: Inno Setup Installers Abused for Stealthy Data Theft & Cryptowallet Draining

Do Son July 8, 2025 0
Read More Read more about RedLine Stealer Unleashed: Inno Setup Installers Abused for Stealthy Data Theft & Cryptowallet Draining
Critical Frauscher Flaws (CVE-2025-3626 CVSS 9.1, CVE-2025-3705 CVSS 6.8): OS Command Injection Threatens Railway Systems Frauscher, Command Injection
  • Vulnerability Report

Critical Frauscher Flaws (CVE-2025-3626 CVSS 9.1, CVE-2025-3705 CVSS 6.8): OS Command Injection Threatens Railway Systems

Do Son July 8, 2025 0
Read More Read more about Critical Frauscher Flaws (CVE-2025-3626 CVSS 9.1, CVE-2025-3705 CVSS 6.8): OS Command Injection Threatens Railway Systems
NordDragonScan: New Infostealer Hits Via Weaponized HTAs, Stealing Browser Data & Documents! NordDragonScan, Infostealer
  • Malware

NordDragonScan: New Infostealer Hits Via Weaponized HTAs, Stealing Browser Data & Documents!

Do Son July 8, 2025 0
Read More Read more about NordDragonScan: New Infostealer Hits Via Weaponized HTAs, Stealing Browser Data & Documents!
Phishing Alert: Fake WeTransfer & HunCERT Pages Hosted on AWS S3 & Cloudflare Turnstile Stealing Credentials Phishing, File Sharing Scam
  • Cybercriminals

Phishing Alert: Fake WeTransfer & HunCERT Pages Hosted on AWS S3 & Cloudflare Turnstile Stealing Credentials

Do Son July 8, 2025 0
Read More Read more about Phishing Alert: Fake WeTransfer & HunCERT Pages Hosted on AWS S3 & Cloudflare Turnstile Stealing Credentials
XMRig Cryptojacking Surges: New Campaign Uses LOLBAS, Steals Monero Undetected XMRig Cryptojacking, LOLBAS
  • Malware

XMRig Cryptojacking Surges: New Campaign Uses LOLBAS, Steals Monero Undetected

Do Son July 8, 2025 0
Read More Read more about XMRig Cryptojacking Surges: New Campaign Uses LOLBAS, Steals Monero Undetected
Critical Vulnerabilities Found in Nimesa Backup and Recovery Software Nimesa Backup, Critical Vulnerabilities
  • Vulnerability Report

Critical Vulnerabilities Found in Nimesa Backup and Recovery Software

Do Son July 8, 2025 0
Read More Read more about Critical Vulnerabilities Found in Nimesa Backup and Recovery Software
XwormRAT Resurfaces with Steganography-Powered Attack Chain ra
  • Malware

XwormRAT Resurfaces with Steganography-Powered Attack Chain

Do Son July 8, 2025 0
Read More Read more about XwormRAT Resurfaces with Steganography-Powered Attack Chain
CVE-2025-41672 (CVSS 10): Critical JWT Certificate Flaw in WAGO Device Sphere Allows Full Remote Takeover WAGO Device Sphere, Critical Vulnerability
  • Vulnerability Report

CVE-2025-41672 (CVSS 10): Critical JWT Certificate Flaw in WAGO Device Sphere Allows Full Remote Takeover

Do Son July 8, 2025 0
Read More Read more about CVE-2025-41672 (CVSS 10): Critical JWT Certificate Flaw in WAGO Device Sphere Allows Full Remote Takeover
Galaxy Z Flip7 Leaked: Thinner Design, Punch-Hole Outer Display & Less Crease Confirmed Ahead of Unpacked Galaxy S26 Dimensions S26 Battery Upgrade Samsung Galaxy AI, AI Diversification Samsung Galaxy Z Flip7, Foldable Smartphone Samsung Foldable, Galaxy Z Fold7 Samsung Tri-Fold, Galaxy G Fold
  • Android

Galaxy Z Flip7 Leaked: Thinner Design, Punch-Hole Outer Display & Less Crease Confirmed Ahead of Unpacked

Do Son July 7, 2025 0
Read More Read more about Galaxy Z Flip7 Leaked: Thinner Design, Punch-Hole Outer Display & Less Crease Confirmed Ahead of Unpacked
IBM Unveils Industry-First Unified Platform for AI Governance & Security IBM AI Governance, AI Security
  • Technology

IBM Unveils Industry-First Unified Platform for AI Governance & Security

Do Son July 7, 2025 0
Read More Read more about IBM Unveils Industry-First Unified Platform for AI Governance & Security
Microsoft Halts Automatic Windows 11 Upgrades via KB5001716, Shifts to Notifications Only KB5083769 Update Windows 11 24H2 end of support File Explorer White Flash Windows 11 Dark Mode Bug Windows 11 SE, End of Support Windows Update, Automatic Upgrade CVE-2023-38146 Windows 10
  • Windows

Microsoft Halts Automatic Windows 11 Upgrades via KB5001716, Shifts to Notifications Only

Do Son July 7, 2025 0
Read More Read more about Microsoft Halts Automatic Windows 11 Upgrades via KB5001716, Shifts to Notifications Only
TikTok Preps New “M2” App for US Launch Amid Divestment Deadline & Oracle Deal TikTok acquisition TikTok, U.S.-China deal TikTok M2, US DivestmentTrump saves TikTok
  • Technology

TikTok Preps New “M2” App for US Launch Amid Divestment Deadline & Oracle Deal

Do Son July 7, 2025 0
Read More Read more about TikTok Preps New “M2” App for US Launch Amid Divestment Deadline & Oracle Deal
Microsoft is Removing PowerShell 2.0 from Windows 11 PowerShell 2.0, Windows 11 Removal
  • Windows

Microsoft is Removing PowerShell 2.0 from Windows 11

Do Son July 7, 2025 0
Read More Read more about Microsoft is Removing PowerShell 2.0 from Windows 11
Microsoft Edge Continues Aggressive Tactics to Block Chrome Downloads (Outside EU) Microsoft Edge, Browser Interference
  • Technology
  • Windows

Microsoft Edge Continues Aggressive Tactics to Block Chrome Downloads (Outside EU)

Do Son July 7, 2025 0
Read More Read more about Microsoft Edge Continues Aggressive Tactics to Block Chrome Downloads (Outside EU)
Redis Vulnerability Opens Door to Remote Code Execution, PoC Releases Redis RCE, HyperLogLog Vulnerability CVE-2024-51741 - CVE-2024-46981
  • Vulnerability

Redis Vulnerability Opens Door to Remote Code Execution, PoC Releases

Do Son July 7, 2025 0
Read More Read more about Redis Vulnerability Opens Door to Remote Code Execution, PoC Releases
Redis DoS Flaw (CVE-2025-48367): Authenticated Clients Can Disrupt Service Redis DoS, Multi-Bulk Protocol
  • Vulnerability Report

Redis DoS Flaw (CVE-2025-48367): Authenticated Clients Can Disrupt Service

Do Son July 7, 2025 0
Read More Read more about Redis DoS Flaw (CVE-2025-48367): Authenticated Clients Can Disrupt Service
Apple’s Huge H2 2025 Lineup: iPhone 17 Air, Apple Watch Ultra 3 (5G/Satellite), M5 Macs & More Apple C2 modem Apple Product Roadmap, iPhone 17
  • Technology

Apple’s Huge H2 2025 Lineup: iPhone 17 Air, Apple Watch Ultra 3 (5G/Satellite), M5 Macs & More

Do Son July 7, 2025 0
Read More Read more about Apple’s Huge H2 2025 Lineup: iPhone 17 Air, Apple Watch Ultra 3 (5G/Satellite), M5 Macs & More
ScriptCase Flaws (CVE-2025-47227/47228): Pre-Auth RCE & Admin Takeover Risk for Web Servers, PoC Published ScriptCase RCE, Pre-Auth Vulnerability
  • Vulnerability Report

ScriptCase Flaws (CVE-2025-47227/47228): Pre-Auth RCE & Admin Takeover Risk for Web Servers, PoC Published

Do Son July 7, 2025 0
Read More Read more about ScriptCase Flaws (CVE-2025-47227/47228): Pre-Auth RCE & Admin Takeover Risk for Web Servers, PoC Published
Hpingbot: New Go-Based Botnet Leverages Pastebin & Hping3 for Stealthy Attacks botnet
  • Malware

Hpingbot: New Go-Based Botnet Leverages Pastebin & Hping3 for Stealthy Attacks

Do Son July 7, 2025 0
Read More Read more about Hpingbot: New Go-Based Botnet Leverages Pastebin & Hping3 for Stealthy Attacks
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intel📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-88771
    Remote code execution due to improper input validation that can allow an unauthenticated attacker to execute arbitrary commands.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 23, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-102361CVSS 9.3
    mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to...
    📅 Updated: Sep 28, 2026
  • CVE-2026-101264CVSS 9.4
    A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the file /api/ZRnetwork/set_passwd....
    📅 Updated: Sep 28, 2026
  • CVE-2026-13214CVSS 9.8
    The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a stack buffer overflow in parse_getconfig_msg(). When handling a GetConfiguration request...
    📅 Updated: Sep 28, 2026
  • CVE-2026-49845CVSS 9.8
    SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows...
    📅 Updated: Sep 28, 2026
  • CVE-2026-55976CVSS 9.1
    Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authenticated remote...
    📅 Updated: Sep 28, 2026
  • CVE-2026-90048CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list() ni_create_attr_list() allocates...
    📅 Updated: Sep 28, 2026
  • CVE-2026-90049CVSS 9.3
    In the Linux kernel, the following vulnerability has been resolved: net: skbuff: don't skb_tx_error() the source skb in...
    📅 Updated: Sep 28, 2026
  • CVE-2026-101263CVSS 9.4
    A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file...
    📅 Updated: Sep 28, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.