Skip to content
September 24, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
CVE-2024-48510 (CVSS 9.8): Critical Flaw in ABB Drive Composer Enables File System Access ABB T-MAC Plus vulnerabilities terminal system flaws ABB OPTIMAX Vulnerability CVE-2025-14510 ABB Edgenius Auth Bypass, Critical RCE ABB, ASPECT BMS CVE-2024-48841, CVE-2024-48849, and CVE-2024-48852 CVE-2024-48510
  • Vulnerability

CVE-2024-48510 (CVSS 9.8): Critical Flaw in ABB Drive Composer Enables File System Access

Do Son February 9, 2025 0
Read More Read more about CVE-2024-48510 (CVSS 9.8): Critical Flaw in ABB Drive Composer Enables File System Access
Publicly Disclosed ASP.NET Machine Keys Used in Code Injection Attacks ViewState code injection attacks
  • Cyber Security

Publicly Disclosed ASP.NET Machine Keys Used in Code Injection Attacks

Do Son February 9, 2025 0
Read More Read more about Publicly Disclosed ASP.NET Machine Keys Used in Code Injection Attacks
CVE-2025-0896 (CVSS 9.8): Orthanc DICOM Server Flaw Exposes Medical Images to Unauthorized Access CVE-2025-0896
  • Vulnerability

CVE-2025-0896 (CVSS 9.8): Orthanc DICOM Server Flaw Exposes Medical Images to Unauthorized Access

Do Son February 9, 2025 0
Read More Read more about CVE-2025-0896 (CVSS 9.8): Orthanc DICOM Server Flaw Exposes Medical Images to Unauthorized Access
Abyss Locker Ransomware: Inside the Stealthy Network Intrusions and Destructive Attacks INC Ransom Pacific Cyber Threats OysterLoader Malware Rhysida Ransomware Black Basta Ransomware BYOVD Technique Velociraptor Abuse, Storm-2603 Ransomware Crypto24, Ransomware Ransomware Payments, UK Legislation ZACROS data breach
  • Malware
  • Vulnerability

Abyss Locker Ransomware: Inside the Stealthy Network Intrusions and Destructive Attacks

Do Son February 9, 2025 0
Read More Read more about Abyss Locker Ransomware: Inside the Stealthy Network Intrusions and Destructive Attacks
Massive Indian Mobile Banking Heist Uncovered: FatBoyPanel’s Trojan Network Exposes 50,000 Users’ Data FatBoyPanel
  • Data Leak
  • Malware

Massive Indian Mobile Banking Heist Uncovered: FatBoyPanel’s Trojan Network Exposes 50,000 Users’ Data

Do Son February 9, 2025 0
Read More Read more about Massive Indian Mobile Banking Heist Uncovered: FatBoyPanel’s Trojan Network Exposes 50,000 Users’ Data
CVE-2025-24786 (CVSS 10) & CVE-2025-24787: Critical WhoDB Vulnerabilities CVE-2025-24786 & CVE-2025-24787
  • Vulnerability

CVE-2025-24786 (CVSS 10) & CVE-2025-24787: Critical WhoDB Vulnerabilities

Do Son February 9, 2025 0
Read More Read more about CVE-2025-24786 (CVSS 10) & CVE-2025-24787: Critical WhoDB Vulnerabilities
Flesh Stealer Malware Targets Browsers and Cryptocurrency Wallets Flesh Stealer
  • Malware

Flesh Stealer Malware Targets Browsers and Cryptocurrency Wallets

Do Son February 9, 2025 0
Read More Read more about Flesh Stealer Malware Targets Browsers and Cryptocurrency Wallets
Sophos Uncovers Rising Threat of SVG-Based Phishing Attacks SVG Phishing Attacks
  • Cyber Security

Sophos Uncovers Rising Threat of SVG-Based Phishing Attacks

Do Son February 8, 2025 0
Read More Read more about Sophos Uncovers Rising Threat of SVG-Based Phishing Attacks
CVE-2024-51547 (CVSS 9.8): Hard-Coded Credentials in ABB ASPECT CVE-2024-51547
  • Vulnerability

CVE-2024-51547 (CVSS 9.8): Hard-Coded Credentials in ABB ASPECT

Do Son February 8, 2025 0
Read More Read more about CVE-2024-51547 (CVSS 9.8): Hard-Coded Credentials in ABB ASPECT
Malicious Cisco AnyConnect Ads Target Users with NetSupport RAT shell-quote command injection AI-Driven Vulnerabilities Q1 2026 Cyber Threats vm2 Sandbox Escape Node.js RCE upKeeper Privilege Escalation CVE-2026-2449 Pharos Controls Vulnerability Root Access Exploit Cybersecurity Vulnerability Roundup CVSS 10.0 Flaws Shadow Archives CVE-2026-0866 MS-Agent Prompt Injection CVE-2026-2256 basic-ftp Path Traversal CVE-2026-27699 telnetd Root Vulnerability CVE-1999-0073 Regression USR-W610 Vulnerabilities End-of-Life IoT Security IceWarp Security Update IceWarp Vulnerabilities Airleader Master Vulnerability CVE-2026-1358 ZLAN5143D Vulnerability CISA ICS Advisory Acronis Cyber Protect Vulnerability CVE-2025-30411 WAGO 852 Vulnerability OT Network Security SandboxJS Vulnerability Sandbox Escape (CVSS 10.0) Kubernetes Local Path Provisioner CVE-2025-62878 CISA Unresponsive Vendors Avation & RISS Vulnerabilities KiloView Vulnerability CVE-2026-1453 OpenClaw RCE vulnerability Johnson Controls Vulnerability CVE-2025-26385 SandboxJS Vulnerability CVE-2026-23830 ibaPDA Vulnerability CVE-2025-14988 Protobuf Vulnerability CVE-2026-0994 AVEVA Process Optimization Vulnerability CVE-2025-61937 ConnectWise PSA Vulnerability CVE-2026-0695 Aruba VIA Vulnerability CVE-2025-37186 aiohttp v3.13.3, Denial of Service (DoS) SmarterMail RCE, CVE-2025-52691 Airoha RACE, Headphone Jacking HPE OneView RCE CVE-2025-37164 FreePBX Auth Bypass, PBX Takeover ScreenConnect Config Flaw, Untrusted Extensions Ruby SAML Auth Bypass, XML Parser Differential Devolutions SQL Injection, Password Manager Flaw Vivotek Unauthenticated RCE, EOL IP Camera Flaw Lynx+ Critical Flaw, Unauthenticated Reset Firebox Default Credentials, CVE-2025-59396 Veeder-Root RCE, Critical ATG Flaw ArcGIS Server SQLi Watchdoc RCE, CVE-2025-58384 Delta DIALink Daikin Security Gateway, authentication bypass Frostbyte10, industrial controller security SunPower, vulnerability Ubiquiti UniFi Connect, EV Station Vulnerabilities Adobe Experience Manager, RCE Vulnerability UniFi Access, Command Injection LDAPNightmare - CVE-2025-1316
  • Malware

Malicious Cisco AnyConnect Ads Target Users with NetSupport RAT

Do Son February 8, 2025 0
Read More Read more about Malicious Cisco AnyConnect Ads Target Users with NetSupport RAT
Lazarus Group Lures Victims with Fake LinkedIn Job Offers, Warns Bitdefender North Korean Laptop Farm DPRK Insider Threat North Korea WMD Cyber Funding, Australia Sanctions Insider threat, North Korean hackers Kimsuky, cyber-espionage NPM Malware, North Korea Cyber-espionage North Korea, Remote IT Job Scam Laptop Farm - DriverEasy - Kimsuky Watering Hole Attack
  • Cyber Security

Lazarus Group Lures Victims with Fake LinkedIn Job Offers, Warns Bitdefender

Do Son February 7, 2025 0
Read More Read more about Lazarus Group Lures Victims with Fake LinkedIn Job Offers, Warns Bitdefender
IBM Security Verify Directory Vulnerable to Critical Security Flaw – CVE-2024-51450 (CVSS 9.1) IBM API Connect, CVE-2025-13915 IBM Privilege Escalation, CVE-2025-36356 IBM Power Systems - CVE-2024-45656 CVE-2024-49814 and CVE-2024-51450 CVE-2024-56346 and CVE-2024-56347 CVE-2025-1302
  • Vulnerability

IBM Security Verify Directory Vulnerable to Critical Security Flaw – CVE-2024-51450 (CVSS 9.1)

Do Son February 7, 2025 0
Read More Read more about IBM Security Verify Directory Vulnerable to Critical Security Flaw – CVE-2024-51450 (CVSS 9.1)
AsyncRAT Rises Again: Malware Abuses Legitimate Services for Stealthy Delivery AsyncRAT Delivery
  • Malware

AsyncRAT Rises Again: Malware Abuses Legitimate Services for Stealthy Delivery

Do Son February 7, 2025 0
Read More Read more about AsyncRAT Rises Again: Malware Abuses Legitimate Services for Stealthy Delivery
CVE-2025-0994: Critical Vulnerability in Trimble Cityworks Exploited in the Wild CVE-2025-0994
  • Vulnerability

CVE-2025-0994: Critical Vulnerability in Trimble Cityworks Exploited in the Wild

Do Son February 7, 2025 0
Read More Read more about CVE-2025-0994: Critical Vulnerability in Trimble Cityworks Exploited in the Wild
Arm Drops NUVIA Lawsuit Against Qualcomm CVE-2023-4211 - Arm Lawsuit
  • Technology

Arm Drops NUVIA Lawsuit Against Qualcomm

Do Son February 7, 2025 0
Read More Read more about Arm Drops NUVIA Lawsuit Against Qualcomm
CVE-2024-21413 (CVSS 9.8): Critical Outlook Flaw Under Active Attack, PoC Available CVE-2024-21413 exploit
  • Vulnerability

CVE-2024-21413 (CVSS 9.8): Critical Outlook Flaw Under Active Attack, PoC Available

Do Son February 7, 2025 0
Read More Read more about CVE-2024-21413 (CVSS 9.8): Critical Outlook Flaw Under Active Attack, PoC Available
Google’s SynthID Now in Magic Editor: AI Image Detection SynthID Magic Editor
  • Technology

Google’s SynthID Now in Magic Editor: AI Image Detection

Do Son February 7, 2025 0
Read More Read more about Google’s SynthID Now in Magic Editor: AI Image Detection
MMS “VidSpam”: A New Bitcoin Scam Using Old Tech Crypto Drain Conspiracy, Malicious MobileConfig phone phishing Cryptocurrency Phishing
  • Cyber Security

MMS “VidSpam”: A New Bitcoin Scam Using Old Tech

Do Son February 7, 2025 0
Read More Read more about MMS “VidSpam”: A New Bitcoin Scam Using Old Tech
NETGEAR Patches Critical Security Vulnerabilities in WiFi Routers (CVE-2025-25246) and Access Points CVE-2022-48196 NETGEAR Security Vulnerabilities
  • Vulnerability

NETGEAR Patches Critical Security Vulnerabilities in WiFi Routers (CVE-2025-25246) and Access Points

Do Son February 6, 2025 0
Read More Read more about NETGEAR Patches Critical Security Vulnerabilities in WiFi Routers (CVE-2025-25246) and Access Points
Kimsuky Group Leverages RDP Wrapper for Persistent Cyber Espionage North Korean Laptop Farm DPRK Insider Threat North Korea WMD Cyber Funding, Australia Sanctions Insider threat, North Korean hackers Kimsuky, cyber-espionage NPM Malware, North Korea Cyber-espionage North Korea, Remote IT Job Scam Laptop Farm - DriverEasy - Kimsuky Watering Hole Attack
  • Cyber Security
  • Malware

Kimsuky Group Leverages RDP Wrapper for Persistent Cyber Espionage

Do Son February 6, 2025 0
Read More Read more about Kimsuky Group Leverages RDP Wrapper for Persistent Cyber Espionage
CVE-2024-9643 & CVE-2024-9644: Authentication Bypass in Four-Faith F3x36 Routers Puts Networks at Risk CVE-2024-9643 & CVE-2024-9644
  • Vulnerability

CVE-2024-9643 & CVE-2024-9644: Authentication Bypass in Four-Faith F3x36 Routers Puts Networks at Risk

Do Son February 6, 2025 0
Read More Read more about CVE-2024-9643 & CVE-2024-9644: Authentication Bypass in Four-Faith F3x36 Routers Puts Networks at Risk
Apache James Mail Server Hit by Double Denial-of-Service Vulnerabilities CVE-2024-45626 and CVE-2024-37358
  • Vulnerability

Apache James Mail Server Hit by Double Denial-of-Service Vulnerabilities

Do Son February 6, 2025 0
Read More Read more about Apache James Mail Server Hit by Double Denial-of-Service Vulnerabilities
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-94127CVSS 9.8
    When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-85102CVSS 9.8
    Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93616CVSS 9.8
    A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93952CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-32996CVSS 7.3
    A vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.
    Admin intel📅 Updated: Sep 22, 2026
  • CVE-2026-7273CVSS 8.8
    A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a...
    CISA KEV📅 Added to KEV: Sep 21, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-61741CVSS 9.3
    http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. Prior to versions 0.24.1 and 1.0.0-M39, these decoders...
    📅 Updated: Sep 24, 2026
  • CVE-2026-61732CVSS 10.0
    Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results —...
    📅 Updated: Sep 24, 2026
  • CVE-2026-69843CVSS 10.0
    No description available
    📅 Updated: Sep 24, 2026
  • CVE-2026-62874CVSS 10.0
    No description available
    📅 Updated: Sep 24, 2026
  • CVE-2026-79766CVSS 9.1
    Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.4.1 until...
    📅 Updated: Sep 24, 2026
  • CVE-2026-66792CVSS 9.9
    A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to...
    📅 Updated: Sep 24, 2026
  • CVE-2026-69399CVSS 10.0
    No description available
    📅 Updated: Sep 24, 2026
  • CVE-2026-58822CVSS 9.8
    In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could...
    📅 Updated: Sep 24, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.