Skip to content
September 21, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Critical Pre-Auth RCE: vBulletin Flaw Allows Full Server Compromise (PoC Available) vBulletin RCE, pre-auth RCE
  • Vulnerability

Critical Pre-Auth RCE: vBulletin Flaw Allows Full Server Compromise (PoC Available)

Do Son May 26, 2025 0
Read More Read more about Critical Pre-Auth RCE: vBulletin Flaw Allows Full Server Compromise (PoC Available)
Critical WSO2 Flaw: Unauthenticated Account Takeover Risk (CVSS 9.8) WSO2 vulnerability, account takeover
  • Vulnerability

Critical WSO2 Flaw: Unauthenticated Account Takeover Risk (CVSS 9.8)

Do Son May 26, 2025 0
Read More Read more about Critical WSO2 Flaw: Unauthenticated Account Takeover Risk (CVSS 9.8)
Sony Camera Hack (CVSS 9.4): Default Credential Flaw Risks Full Control (PoC) Sony camera hack, default credential exploit
  • Vulnerability

Sony Camera Hack (CVSS 9.4): Default Credential Flaw Risks Full Control (PoC)

Do Son May 26, 2025 0
Read More Read more about Sony Camera Hack (CVSS 9.4): Default Credential Flaw Risks Full Control (PoC)
Decade of Stealth: China-Linked TA-ShadowCricket Targets Asia-Pacific TA-ShadowCricket, Shadow Force malware
  • Cyber Security
  • Malware

Decade of Stealth: China-Linked TA-ShadowCricket Targets Asia-Pacific

Do Son May 26, 2025 0
Read More Read more about Decade of Stealth: China-Linked TA-ShadowCricket Targets Asia-Pacific
DOUBLELOADER Malware Uses ALCATRAZ Obfuscator to Evade Detection DOUBLELOADER malware, ALCATRAZ obfuscator
  • Malware

DOUBLELOADER Malware Uses ALCATRAZ Obfuscator to Evade Detection

Do Son May 26, 2025 0
Read More Read more about DOUBLELOADER Malware Uses ALCATRAZ Obfuscator to Evade Detection
NPM Recon: Malicious Packages Found Stealing Internal Network IPs and Hostnames npm security, internal IP theft
  • Malware

NPM Recon: Malicious Packages Found Stealing Internal Network IPs and Hostnames

Do Son May 26, 2025 0
Read More Read more about NPM Recon: Malicious Packages Found Stealing Internal Network IPs and Hostnames
Russian-Aligned TAG-110 Targets Tajikistan Governments with Stealthy Cyber-Espionage TAG-110 cyber-espionage, Tajikistan phishing
  • Cyber Security

Russian-Aligned TAG-110 Targets Tajikistan Governments with Stealthy Cyber-Espionage

Do Son May 26, 2025 0
Read More Read more about Russian-Aligned TAG-110 Targets Tajikistan Governments with Stealthy Cyber-Espionage
Persistent DoS: Unauthenticated Attacker Crashes GNOME RDP (Even After Systemd) Linux desktop security, GNOME RDP
  • Vulnerability

Persistent DoS: Unauthenticated Attacker Crashes GNOME RDP (Even After Systemd)

Do Son May 26, 2025 0
Read More Read more about Persistent DoS: Unauthenticated Attacker Crashes GNOME RDP (Even After Systemd)
Qakbot Mastermind Indicted: Russian Architect of $50M Malware Empire Charged Qakbot mastermind, Rustam Rafailevich Gallyamov
  • Cybercriminals

Qakbot Mastermind Indicted: Russian Architect of $50M Malware Empire Charged

Do Son May 26, 2025 0
Read More Read more about Qakbot Mastermind Indicted: Russian Architect of $50M Malware Empire Charged
Chrome Web Store Under Siege: 40+ Malicious Extensions Found Stealing Data Chrome Web Store malware, browser hijacking
  • Malware

Chrome Web Store Under Siege: 40+ Malicious Extensions Found Stealing Data

Do Son May 26, 2025 0
Read More Read more about Chrome Web Store Under Siege: 40+ Malicious Extensions Found Stealing Data
Deceptive CAPTCHA: ClickFix Campaign Uses Clipboard Injection to Deliver Malware Example infection chain from CAPTCHA to Lumma Stealer
  • Malware

Deceptive CAPTCHA: ClickFix Campaign Uses Clipboard Injection to Deliver Malware

Do Son May 26, 2025 0
Read More Read more about Deceptive CAPTCHA: ClickFix Campaign Uses Clipboard Injection to Deliver Malware
Important Update: Vulnerability Articles Now Exclusive to Supporters content
  • Announcement

Important Update: Vulnerability Articles Now Exclusive to Supporters

ddos-admin May 25, 2025 7
Read More Read more about Important Update: Vulnerability Articles Now Exclusive to Supporters
Ghostscript Flaw Leaks Plaintext Passwords in Encrypted PDFs Ghostscript vulnerability, PDF password leak
  • Vulnerability

Ghostscript Flaw Leaks Plaintext Passwords in Encrypted PDFs

Do Son May 25, 2025 0
Read More Read more about Ghostscript Flaw Leaks Plaintext Passwords in Encrypted PDFs
Stealthy Data Theft: Hackers Use Legitimate DB Client Tools for Exfiltration turn
  • Cybercriminals

Stealthy Data Theft: Hackers Use Legitimate DB Client Tools for Exfiltration

Do Son May 25, 2025 0
Read More Read more about Stealthy Data Theft: Hackers Use Legitimate DB Client Tools for Exfiltration
ViciousTrap: New Cyber-Espionage Group Hijacks Routers for Honeypot Surveillance ViciousTrap, router honeypot
  • Cybercriminals

ViciousTrap: New Cyber-Espionage Group Hijacks Routers for Honeypot Surveillance

Do Son May 25, 2025 0
Read More Read more about ViciousTrap: New Cyber-Espionage Group Hijacks Routers for Honeypot Surveillance
ABB ASPECT BMS Critical Flaws: RCE and Privilege Escalation Risks ABB ASPECT vulnerabilities, BMS security
  • Vulnerability

ABB ASPECT BMS Critical Flaws: RCE and Privilege Escalation Risks

Do Son May 24, 2025 0
Read More Read more about ABB ASPECT BMS Critical Flaws: RCE and Privilege Escalation Risks
AI-Generated Malware: TikTok Videos Push Infostealers with PowerShell Commands TikTok malware, AI-generated malware
  • Malware

AI-Generated Malware: TikTok Videos Push Infostealers with PowerShell Commands

Do Son May 24, 2025 0
Read More Read more about AI-Generated Malware: TikTok Videos Push Infostealers with PowerShell Commands
Warning: New Malvertising Campaign Uses Fake Cloudflare Pages to Deliver Malware Fake Cloudflare page, WordPress theme malware
  • Malware

Warning: New Malvertising Campaign Uses Fake Cloudflare Pages to Deliver Malware

Do Son May 24, 2025 0
Read More Read more about Warning: New Malvertising Campaign Uses Fake Cloudflare Pages to Deliver Malware
DanaBot Takedown: 16 Indicted for $50M Malware Operation DanaBot takedown, cybercrime charges
  • Cybercriminals

DanaBot Takedown: 16 Indicted for $50M Malware Operation

Do Son May 23, 2025 0
Read More Read more about DanaBot Takedown: 16 Indicted for $50M Malware Operation
Operation Endgame: Global Takedown Disrupts Major Ransomware Malware Infrastructure Operation Endgame, ransomware takedown
  • Cybercriminals

Operation Endgame: Global Takedown Disrupts Major Ransomware Malware Infrastructure

Do Son May 23, 2025 0
Read More Read more about Operation Endgame: Global Takedown Disrupts Major Ransomware Malware Infrastructure
184 Million Leaked Credentials Found in Open Database Compromised Credentials, Data Breach
  • Data Leak

184 Million Leaked Credentials Found in Open Database

Do Son May 23, 2025 0
Read More Read more about 184 Million Leaked Credentials Found in Open Database
Pocket and Fakespot Apps Closing: Mozilla Discontinues Popular Services Pocket app closure, Fakespot discontinuation
  • Technology

Pocket and Fakespot Apps Closing: Mozilla Discontinues Popular Services

Do Son May 23, 2025 0
Read More Read more about Pocket and Fakespot Apps Closing: Mozilla Discontinues Popular Services
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-58138CVSS 9.8
    Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute...
    Admin intel📅 Updated: Sep 20, 2026
  • CVE-2026-86124CVSS 9.8
    AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and...
    Admin intel📅 Updated: Sep 19, 2026
  • CVE-2025-39682CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the...
    CISA KEV📅 Added to KEV: Sep 18, 2026
  • CVE-2025-39964CVSS 7.8
    In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg...
    CISA KEV📅 Added to KEV: Sep 18, 2026
  • CVE-2026-53266CVSS 8.8
    In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The...
    CISA KEV📅 Added to KEV: Sep 18, 2026
  • CVE-2026-76460CVSS 10.0
    A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to...
    Admin intelCISA KEV📅 Added to KEV: Sep 16, 2026📅 Updated: Sep 16, 2026
  • CVE-2026-89026CVSS 9.8
    The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT...
    Admin intel📅 Updated: Sep 16, 2026
  • CVE-2026-58704
    In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This...
    Admin intelCISA KEV📅 Added to KEV: Sep 16, 2026📅 Updated: Sep 16, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-69586CVSS 9.8
    Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network.
    📅 Updated: Sep 21, 2026
  • CVE-2026-69590CVSS 9.8
    Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access...
    📅 Updated: Sep 21, 2026
  • CVE-2026-69595CVSS 9.8
    Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code...
    📅 Updated: Sep 21, 2026
  • CVE-2026-58491CVSS 9.3
    Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.5, the /@warpgate/api/sso/providers/:name/start...
    📅 Updated: Sep 21, 2026
  • CVE-2026-93765CVSS 9.1
    Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose...
    📅 Updated: Sep 21, 2026
  • CVE-2026-85497CVSS 9.8
    CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient...
    📅 Updated: Sep 21, 2026
  • CVE-2026-93742CVSS 9.9
    A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of...
    📅 Updated: Sep 21, 2026
  • CVE-2024-58385CVSS 9.8
    Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter...
    📅 Updated: Sep 21, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.