Skip to content
September 14, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Tycon Power Monitor Authentication Bypass CVE-2026-61884 Rated CVSS 9.8 Tycon authentication bypass CVE-2026-61884 in TPDIN-Monitor-WEB2 rated CVSS 9.8
  • Vulnerability Report

Tycon Power Monitor Authentication Bypass CVE-2026-61884 Rated CVSS 9.8

Do Son July 24, 2026 0
Read More Read more about Tycon Power Monitor Authentication Bypass CVE-2026-61884 Rated CVSS 9.8
GoSerpent Backdoor Drives a Patient Cyber Espionage Campaign Against Southeast Asian Governments GoSerpent backdoor cyber espionage attack chain against Southeast Asian government networks
  • Cyber Security

GoSerpent Backdoor Drives a Patient Cyber Espionage Campaign Against Southeast Asian Governments

Do Son July 24, 2026 0
Read More Read more about GoSerpent Backdoor Drives a Patient Cyber Espionage Campaign Against Southeast Asian Governments
Tego AI Discloses Second Claude Flaw in a Week: Hidden Link Silently Sends Files to Attackers ChatGPT_Image_Jul_24_2026_11_58_11_AM_1784887099UOeFRyUzMz
  • Press Release

Tego AI Discloses Second Claude Flaw in a Week: Hidden Link Silently Sends Files to Attackers

cybernewswire July 24, 2026 0
Read More Read more about Tego AI Discloses Second Claude Flaw in a Week: Hidden Link Silently Sends Files to Attackers
Google Gemini Spark Expands Access to Pro and Ultra Subscribers Google Gemini Spark agentic AI assistant running in the Google Workspace sidebar, drafting Gmail replies and Google Docs reports
  • Technology

Google Gemini Spark Expands Access to Pro and Ultra Subscribers

Do Son July 24, 2026 0
Read More Read more about Google Gemini Spark Expands Access to Pro and Ultra Subscribers
Google DMA Fine of €890 Million Lands in Brussels Google DMA fine of 890 million euros from the European Commission over search self-preferencing and Play Store steering restrictions
  • Technology

Google DMA Fine of €890 Million Lands in Brussels

Do Son July 24, 2026 0
Read More Read more about Google DMA Fine of €890 Million Lands in Brussels
TAG-150 Attack Chain Deploys DenoRAT Malware Head Mare TrueConf attack PhantomCore backdoor diagram
  • Malware

TAG-150 Attack Chain Deploys DenoRAT Malware

Do Son July 24, 2026 0
Read More Read more about TAG-150 Attack Chain Deploys DenoRAT Malware
North Korean Contagious Interview Campaign Hides Malware in Fake Coding Tests AccountDumpling Phishing Google AppSheet Abuse AI-Generated Malware PureRAT Campaign RondoDoX Botnet, Next.js React2Shell EchoGather, Paper Werewolf Salt Typhoon, Telecom Espionage BreachForums, Conor Fitzpatrick Ransomware Negotiation, DOJ Investigation MirrorFace group - Earth Kasha Emperor Dragonfly
  • Cybercriminals

North Korean Contagious Interview Campaign Hides Malware in Fake Coding Tests

Do Son July 24, 2026 0
Read More Read more about North Korean Contagious Interview Campaign Hides Malware in Fake Coding Tests
ACR Stealer Spreads Through ClickFix Lures in Two Attack Chains ACR Stealer infection chain starting with a ClickFix lure to steal browser credentials
  • Malware

ACR Stealer Spreads Through ClickFix Lures in Two Attack Chains

Do Son July 24, 2026 0
Read More Read more about ACR Stealer Spreads Through ClickFix Lures in Two Attack Chains
LG Disables McAfee Ad Popups on Monitors After Backlash LG monitor adware warning showing unwanted McAfee pop-ups and bloatware installation
  • Technology

LG Disables McAfee Ad Popups on Monitors After Backlash

Do Son July 24, 2026 0
Read More Read more about LG Disables McAfee Ad Popups on Monitors After Backlash
ADAudit Plus Flaw CVE-2026-6516 Allows Unauthenticated Remote Code Execution at CVSS 10 ADAudit Plus vulnerability CVE-2026-6516 enabling unauthenticated remote code execution on Active Directory audit servers
  • Vulnerability Report

ADAudit Plus Flaw CVE-2026-6516 Allows Unauthenticated Remote Code Execution at CVSS 10

Do Son July 24, 2026 0
Read More Read more about ADAudit Plus Flaw CVE-2026-6516 Allows Unauthenticated Remote Code Execution at CVSS 10
Public Exploit Code Released for Knot Resolver DNS-over-QUIC Remote Code Execution Flaw Knot Resolver RCE through a DNS-over-QUIC heap overflow with publicly disclosed PoC exploit code
  • Vulnerability Report

Public Exploit Code Released for Knot Resolver DNS-over-QUIC Remote Code Execution Flaw

Do Son July 24, 2026 0
Read More Read more about Public Exploit Code Released for Knot Resolver DNS-over-QUIC Remote Code Execution Flaw
CERT/CC Warns of Six Logto Vulnerabilities in SSO and MFA Handling Logto vulnerabilities enabling SSO authentication bypass across OIDC, OAuth 2.1, and SAML sign-in flows
  • Vulnerability Report

CERT/CC Warns of Six Logto Vulnerabilities in SSO and MFA Handling

Do Son July 24, 2026 0
Read More Read more about CERT/CC Warns of Six Logto Vulnerabilities in SSO and MFA Handling
DOJ Indicts Chinese National Over Gift Card Fraud Scheme in New Hampshire Gift card fraud conspiracy indictment tied to a wire fraud conspiracy charge and a New Hampshire electronics warehouse
  • Cybercriminals

DOJ Indicts Chinese National Over Gift Card Fraud Scheme in New Hampshire

Do Son July 24, 2026 0
Read More Read more about DOJ Indicts Chinese National Over Gift Card Fraud Scheme in New Hampshire
Google Ships Chrome 150 Update Fixing Four High-Severity Memory Bugs Chrome security update patching a Codecs sandbox escape and use-after-free flaws in Chrome 150
  • Vulnerability Report

Google Ships Chrome 150 Update Fixing Four High-Severity Memory Bugs

Do Son July 24, 2026 0
Read More Read more about Google Ships Chrome 150 Update Fixing Four High-Severity Memory Bugs
Google Selfie Video Sign-In Recovers Locked Accounts Google selfie video sign-in setup screen showing guided head movements for account recovery and liveness verification
  • Technology

Google Selfie Video Sign-In Recovers Locked Accounts

Do Son July 23, 2026 0
Read More Read more about Google Selfie Video Sign-In Recovers Locked Accounts
HTTP/2 DoS Vulnerability Lets Attackers Exhaust Server Memory via Stalled Flow Control HTTP/2 DoS vulnerability caused by stalled flow control exhausting server memory across multiple HTTP/2 implementations
  • Vulnerability Report

HTTP/2 DoS Vulnerability Lets Attackers Exhaust Server Memory via Stalled Flow Control

Do Son July 23, 2026 0
Read More Read more about HTTP/2 DoS Vulnerability Lets Attackers Exhaust Server Memory via Stalled Flow Control
TA488 and TA458 Steal Government Email Using Half-Click Webmail Exploits Half-click exploits chain showing webmail zero-days used by TA488 and TA458 against Zimbra, SOGo and Roundcube mailservers
  • Cyber Security

TA488 and TA458 Steal Government Email Using Half-Click Webmail Exploits

Do Son July 23, 2026 0
Read More Read more about TA488 and TA458 Steal Government Email Using Half-Click Webmail Exploits
JetBrains Patches 18 Flaws, Including Two CVSS 10 Bugs in IntelliJ IDEA Remote Development JetBrains vulnerabilities across IntelliJ IDEA, WebStorm and TeamCity, including CVE-2026-64812 remote development flaws enabling arbitrary code execution
  • Vulnerability Report

JetBrains Patches 18 Flaws, Including Two CVSS 10 Bugs in IntelliJ IDEA Remote Development

Do Son July 23, 2026 0
Read More Read more about JetBrains Patches 18 Flaws, Including Two CVSS 10 Bugs in IntelliJ IDEA Remote Development
Apache Syncope Patches SQL Injection and Privilege Escalation Flaws Apache Syncope vulnerabilities including a privilege escalation flaw fixed in CVE-2026-57308 and CVE-2026-62183
  • Vulnerability Report

Apache Syncope Patches SQL Injection and Privilege Escalation Flaws

Do Son July 23, 2026 0
Read More Read more about Apache Syncope Patches SQL Injection and Privilege Escalation Flaws
CVE-2026-57239: Public PoC Exploits Foxit PDF Reader Vulnerability for SYSTEM Privileges Foxit PDF Reader vulnerability CVE-2026-57239 exploited for SYSTEM privileges via local privilege escalation
  • Vulnerability Report

CVE-2026-57239: Public PoC Exploits Foxit PDF Reader Vulnerability for SYSTEM Privileges

Do Son July 23, 2026 0
Read More Read more about CVE-2026-57239: Public PoC Exploits Foxit PDF Reader Vulnerability for SYSTEM Privileges
Next.js Patches Three CVSS 8.3 Flaws in Rewrites, Server Actions, and Middleware Next.js vulnerabilities diagram showing Server-Side Request Forgery through rewrites and Server Actions in CVE-2026-64645 and CVE-2026-64649
  • Vulnerability Report

Next.js Patches Three CVSS 8.3 Flaws in Rewrites, Server Actions, and Middleware

Do Son July 23, 2026 0
Read More Read more about Next.js Patches Three CVSS 8.3 Flaws in Rewrites, Server Actions, and Middleware
Unpatched SGLang Flaw CVE-2026-14890 Allows Unauthenticated Remote Code Execution SGLang vulnerability CVE-2026-14890 enabling unauthenticated remote code execution via pickle deserialization
  • Vulnerability Report

Unpatched SGLang Flaw CVE-2026-14890 Allows Unauthenticated Remote Code Execution

Do Son July 23, 2026 0
Read More Read more about Unpatched SGLang Flaw CVE-2026-14890 Allows Unauthenticated Remote Code Execution
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-51990
    A critical remote code execution vulnerability in Sogou Input Method, one of the most widely used Chinese-language input...
    Admin intel📅 Updated: Sep 12, 2026
  • CVE-2026-85706CVSS 10.0
    GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42016CVSS 8.1
    JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42018CVSS 7.5
    JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-84869CVSS 9.9
    A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote...
    CISA KEV📅 Added to KEV: Sep 11, 2026
  • CVE-2026-20079CVSS 10.0
    A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated,...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2025-25249CVSS 8.1
    A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2026-87491
    Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-90937CVSS 9.9
    froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect...
  • CVE-2026-90919CVSS 9.8
    LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config...
  • CVE-2026-90898CVSS 9.8
    Bifrost registers MCP clients through its management API. A stdio client is...
  • CVE-2026-90703CVSS 9.1
    A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element...
  • CVE-2026-90702CVSS 9.1
    A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the...
  • CVE-2026-90699CVSS 9.9
    A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects...
  • CVE-2026-90693CVSS 9.9
    A flaw has been found in D-Link DIR-878 120B05. This impacts the...
  • CVE-2026-90692CVSS 9.9
    A vulnerability was detected in D-Link DIR-878 120B05. This affects the function...
  • CVE-2026-82787CVSS 9.8
    Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability...
  • CVE-2026-90680CVSS 9.9
    A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted...
Powered by CVE WATCHTOWER

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.