Skip to content
September 14, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Broadcom Patches CVE-2026-59309 & CVE-2026-59310 (CVSS 9.8) in VMware VMware authentication bypass advisory CVE-2026-59309 directory traversal
  • Vulnerability Report

Broadcom Patches CVE-2026-59309 & CVE-2026-59310 (CVSS 9.8) in VMware

Do Son July 29, 2026 0
Read More Read more about Broadcom Patches CVE-2026-59309 & CVE-2026-59310 (CVSS 9.8) in VMware
TrickBot Variant Hides C2 Traffic Inside Malformed DNS Queries FSB Center 16 targeting vulnerable routers across critical infrastructure via weak SNMP
  • Malware

TrickBot Variant Hides C2 Traffic Inside Malformed DNS Queries

Do Son July 29, 2026 0
Read More Read more about TrickBot Variant Hides C2 Traffic Inside Malformed DNS Queries
Gitea RCE Flaw CVE-2026-60004 (CVSS 9.8): Details and PoC Exploit Publicly Disclosed Gitea RCE vulnerability CVE-2026-60004 via diffpatch Git hook installation rated CVSS 9.8
  • Vulnerability Report

Gitea RCE Flaw CVE-2026-60004 (CVSS 9.8): Details and PoC Exploit Publicly Disclosed

Do Son July 29, 2026 0
Read More Read more about Gitea RCE Flaw CVE-2026-60004 (CVSS 9.8): Details and PoC Exploit Publicly Disclosed
Lampion Malware Campaign Targets Portugal With Fake Payment Receipts C2Looper Rust backdoor diagram showing GitHub command-and-control and ClickFix ransomware infection chain
  • Malware

Lampion Malware Campaign Targets Portugal With Fake Payment Receipts

Do Son July 29, 2026 0
Read More Read more about Lampion Malware Campaign Targets Portugal With Fake Payment Receipts
Chaos Ransomware Uses msaRAT to Hide C2 Traffic Inside Chrome msaRAT malware used by the Chaos ransomware group to route C2 traffic through a headless Chrome browser session
  • Malware

Chaos Ransomware Uses msaRAT to Hide C2 Traffic Inside Chrome

Do Son July 29, 2026 0
Read More Read more about Chaos Ransomware Uses msaRAT to Hide C2 Traffic Inside Chrome
MCP Protocol Embraces Stateless Architecture in Major Overhaul MCP protocol update transitioning to a stateless architecture with HTTP header routing
  • Technology

MCP Protocol Embraces Stateless Architecture in Major Overhaul

Do Son July 29, 2026 0
Read More Read more about MCP Protocol Embraces Stateless Architecture in Major Overhaul
Exploited in the Wild: CVE-2026-18072 (CVSS 9.8) Grants Full Administrative Control to 20,000 WordPress Sites CVE-2026-18072 video embedder backdoor authentication bypass
  • Vulnerability Report

Exploited in the Wild: CVE-2026-18072 (CVSS 9.8) Grants Full Administrative Control to 20,000 WordPress Sites

Do Son July 29, 2026 0
Read More Read more about Exploited in the Wild: CVE-2026-18072 (CVSS 9.8) Grants Full Administrative Control to 20,000 WordPress Sites
Check Point SmartConsole Authentication Bypass CVE-2026-16232 Exploited as Zero-Day, PoC and Details Public SmartConsole authentication bypass CVE-2026-16232 in Check Point Security Management Server
  • Vulnerability Report

Check Point SmartConsole Authentication Bypass CVE-2026-16232 Exploited as Zero-Day, PoC and Details Public

Do Son July 29, 2026 0
Read More Read more about Check Point SmartConsole Authentication Bypass CVE-2026-16232 Exploited as Zero-Day, PoC and Details Public
NVIDIA BlueField Flaw CVE-2026-65094 Allows Code Execution (CVSS 9.0) NVIDIA BlueField VIRTIO-Net vulnerability CVE-2026-65094 leading to code execution
  • Vulnerability Report

NVIDIA BlueField Flaw CVE-2026-65094 Allows Code Execution (CVSS 9.0)

Do Son July 29, 2026 0
Read More Read more about NVIDIA BlueField Flaw CVE-2026-65094 Allows Code Execution (CVSS 9.0)
IBM Aspera Vulnerabilities Patched in Faspex 5 and Desktop App IBM Aspera vulnerabilities in Faspex 5 and Desktop App including CVE-2026-14973
  • Vulnerability Report

IBM Aspera Vulnerabilities Patched in Faspex 5 and Desktop App

Do Son July 29, 2026 0
Read More Read more about IBM Aspera Vulnerabilities Patched in Faspex 5 and Desktop App
CVE-2026-45293: Arbitrary Code Execution in WordPress Coding Standards, a Tool With 49M+ Installs CVE-2026-45293 arbitrary code execution flaw in WordPress Coding Standards linting tool rated CVSS 8.6
  • Vulnerability Report

CVE-2026-45293: Arbitrary Code Execution in WordPress Coding Standards, a Tool With 49M+ Installs

Do Son July 29, 2026 0
Read More Read more about CVE-2026-45293: Arbitrary Code Execution in WordPress Coding Standards, a Tool With 49M+ Installs
Aembit Joins Snowflake to Tackle AI’s Next Security Frontier: Trusted Agent Interoperability result_Aembit-Snowflake-Revised_1785251578w6w40xbGlY
  • Press Release

Aembit Joins Snowflake to Tackle AI’s Next Security Frontier: Trusted Agent Interoperability

cybernewswire July 28, 2026 0
Read More Read more about Aembit Joins Snowflake to Tackle AI’s Next Security Frontier: Trusted Agent Interoperability
Mitel Patches MiCollab Command Injection Flaw (CVSS 9.8) That Lets Attackers Gain Control of the System MiCollab command injection and OpenScape UC vulnerability advisories from Mitel showing CVSS 9.8 and CVSS 8.0 severity ratings
  • Vulnerability Report

Mitel Patches MiCollab Command Injection Flaw (CVSS 9.8) That Lets Attackers Gain Control of the System

Do Son July 28, 2026 0
Read More Read more about Mitel Patches MiCollab Command Injection Flaw (CVSS 9.8) That Lets Attackers Gain Control of the System
Panduit IntraVUE Vulnerability CVE-2026-42933 (CVSS 10) Bypasses OT Segmentation Panduit IntraVUE vulnerability CVE-2026-42933 CVSS 10 rating enabling OT segmentation bypass in industrial networks
  • Vulnerability Report

Panduit IntraVUE Vulnerability CVE-2026-42933 (CVSS 10) Bypasses OT Segmentation

Do Son July 28, 2026 0
Read More Read more about Panduit IntraVUE Vulnerability CVE-2026-42933 (CVSS 10) Bypasses OT Segmentation
TeamCity RCE Flaw CVE-2026-63077 (CVSS 9.8) Enables Unauthenticated Command Execution TeamCity RCE vulnerability CVE-2026-63077 in TeamCity On-Premises rated CVSS 9.8
  • Vulnerability Report

TeamCity RCE Flaw CVE-2026-63077 (CVSS 9.8) Enables Unauthenticated Command Execution

Do Son July 28, 2026 0
Read More Read more about TeamCity RCE Flaw CVE-2026-63077 (CVSS 9.8) Enables Unauthenticated Command Execution
CVE-2026-42533: NGINX Heap Overflow Enables RCE and ASLR Bypass, Public PoC Released CVE-2026-42533 NGINX heap overflow proof-of-concept enabling an ASLR bypass and RCE
  • Vulnerability Report

CVE-2026-42533: NGINX Heap Overflow Enables RCE and ASLR Bypass, Public PoC Released

Do Son July 28, 2026 0
Read More Read more about CVE-2026-42533: NGINX Heap Overflow Enables RCE and ASLR Bypass, Public PoC Released
Fraggap Linux Kernel Vulnerability: Full Details and PoC Exploit Code Now Public Fraggap Linux kernel vulnerability CVE-2026-53362 enabling local privilege escalation through a UDPv6 out-of-bounds write
  • Vulnerability Report

Fraggap Linux Kernel Vulnerability: Full Details and PoC Exploit Code Now Public

Do Son July 28, 2026 0
Read More Read more about Fraggap Linux Kernel Vulnerability: Full Details and PoC Exploit Code Now Public
OVSwrap Local Root Vulnerability (CVE-2026-64531): Exploit Details and PoC Publicly Disclosed OVSwrap local root vulnerability CVE-2026-64531 in the Linux kernel Open vSwitch datapath
  • Vulnerability Report

OVSwrap Local Root Vulnerability (CVE-2026-64531): Exploit Details and PoC Publicly Disclosed

Do Son July 28, 2026 0
Read More Read more about OVSwrap Local Root Vulnerability (CVE-2026-64531): Exploit Details and PoC Publicly Disclosed
Microsoft Unveils Project Perception, an Agentic Security System Microsoft Project Perception agentic security system with red, blue, and green AI team agents, a security context layer, and actuators for the AI era
  • Technology

Microsoft Unveils Project Perception, an Agentic Security System

Do Son July 28, 2026 0
Read More Read more about Microsoft Unveils Project Perception, an Agentic Security System
Insikt Group Finds Four New Golden Chickens Malware Families Golden Chickens malware chain showing ChonkyChicken malware and TinyEgg delivered through ClickFix fake verification pages
  • Cybercriminals

Insikt Group Finds Four New Golden Chickens Malware Families

Do Son July 28, 2026 0
Read More Read more about Insikt Group Finds Four New Golden Chickens Malware Families
JadeProx Used TriBack Loader Against a Vietnamese Hospital, Malaysia’s Foreign Ministry, and Hong Kong Schools ACR Stealer infection chain starting with a ClickFix lure to steal browser credentials
  • Cybercriminals

JadeProx Used TriBack Loader Against a Vietnamese Hospital, Malaysia’s Foreign Ministry, and Hong Kong Schools

Do Son July 28, 2026 0
Read More Read more about JadeProx Used TriBack Loader Against a Vietnamese Hospital, Malaysia’s Foreign Ministry, and Hong Kong Schools
Fake Job Interviews Deliver PylangGhost and GolangGhost RATs to Crypto Workers ClickFake Interview campaign delivering PylangGhost RAT and GolangGhost RAT to crypto professionals
  • Cybercriminals

Fake Job Interviews Deliver PylangGhost and GolangGhost RATs to Crypto Workers

Do Son July 28, 2026 0
Read More Read more about Fake Job Interviews Deliver PylangGhost and GolangGhost RATs to Crypto Workers
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-51990
    A critical remote code execution vulnerability in Sogou Input Method, one of the most widely used Chinese-language input...
    Admin intel📅 Updated: Sep 12, 2026
  • CVE-2026-85706CVSS 10.0
    GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42016CVSS 8.1
    JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42018CVSS 7.5
    JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-84869CVSS 9.9
    A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote...
    CISA KEV📅 Added to KEV: Sep 11, 2026
  • CVE-2026-20079CVSS 10.0
    A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated,...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2025-25249CVSS 8.1
    A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2026-87491
    Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-90703CVSS 9.1
    A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element...
  • CVE-2026-90702CVSS 9.1
    A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the...
  • CVE-2026-90699CVSS 9.9
    A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects...
  • CVE-2026-90693CVSS 9.9
    A flaw has been found in D-Link DIR-878 120B05. This impacts the...
  • CVE-2026-90692CVSS 9.9
    A vulnerability was detected in D-Link DIR-878 120B05. This affects the function...
  • CVE-2026-82787CVSS 9.8
    Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability...
  • CVE-2026-90680CVSS 9.9
    A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted...
  • CVE-2026-90608CVSS 9.9
    A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element...
  • CVE-2026-90607CVSS 9.9
    A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function...
  • CVE-2026-90606CVSS 9.9
    A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue...
Powered by CVE WATCHTOWER

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.