Skip to content
July 21, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
CrySome RAT Spread Through Fake Freight Rate Confirmation Phishing NATS-as-C2 Sysdig CVE-2026-33017 Langflow RCE Microsoft Phone Link Hijack CloudZ Pheno Plugin Insider Threat BlackCat (ALPHV) OFAC Sanctions DPRK IT Workers Transparent Tribe APT36 React2Shell, EtherRAT SideWinder Espionage, Netlify Phishing DDNS Abuse, C2 Infrastructure Hacking Health Club
  • Malware

CrySome RAT Spread Through Fake Freight Rate Confirmation Phishing

Do Son July 15, 2026 0
Read More Read more about CrySome RAT Spread Through Fake Freight Rate Confirmation Phishing
RedWing Android Malware Rents Out Spyware and Bank Theft on Telegram RedWing Android malware panel sold as malware-as-a-service on Telegram with banking overlays
  • Malware

RedWing Android Malware Rents Out Spyware and Bank Theft on Telegram

Do Son July 15, 2026 0
Read More Read more about RedWing Android Malware Rents Out Spyware and Bank Theft on Telegram
CVE-2026-10577: CVSS 10 Access Control Vulnerability Hits Rockwell Automation 1715 Redundant I/O Modules Rockwell Automation vulnerability CVE-2026-10577 access control flaw in 1715 Redundant I/O
  • Vulnerability Report

CVE-2026-10577: CVSS 10 Access Control Vulnerability Hits Rockwell Automation 1715 Redundant I/O Modules

Do Son July 15, 2026 0
Read More Read more about CVE-2026-10577: CVSS 10 Access Control Vulnerability Hits Rockwell Automation 1715 Redundant I/O Modules
Malicious Go Module Exposes a 222-Repository GitHub Lure Network Malicious Go module exposing GitHub lure network of 222 repositories in Operation Muck and Load
  • Cybercriminals

Malicious Go Module Exposes a 222-Repository GitHub Lure Network

Do Son July 15, 2026 0
Read More Read more about Malicious Go Module Exposes a 222-Repository GitHub Lure Network
GodDamn Ransomware Rebrands Beast and Uses a Malicious Signed Driver to Disable Defenses digital-hacker
  • Malware

GodDamn Ransomware Rebrands Beast and Uses a Malicious Signed Driver to Disable Defenses

Do Son July 15, 2026 0
Read More Read more about GodDamn Ransomware Rebrands Beast and Uses a Malicious Signed Driver to Disable Defenses
Notepad++ v8.9.7 Fixes 5 Vulnerabilities, All With Public Details and PoC Exploit Code Notepad++ vulnerabilities public PoC exploit code path traversal CVE-2026-52886
  • Vulnerability Report

Notepad++ v8.9.7 Fixes 5 Vulnerabilities, All With Public Details and PoC Exploit Code

Do Son July 15, 2026 0
Read More Read more about Notepad++ v8.9.7 Fixes 5 Vulnerabilities, All With Public Details and PoC Exploit Code
Chrome 150 Security Update Fixes 15 Flaws, Including Two Critical Use-After-Free Bugs Chrome security update 150 fixing critical use-after-free flaws CVE-2026-15764 and CVE-2026-15765
  • Vulnerability Report

Chrome 150 Security Update Fixes 15 Flaws, Including Two Critical Use-After-Free Bugs

Do Son July 15, 2026 0
Read More Read more about Chrome 150 Security Update Fixes 15 Flaws, Including Two Critical Use-After-Free Bugs
Passkey Phishing Campaign Uses Vishing Calls to Hijack Microsoft Entra Accounts Passkey phishing vishing attack targeting Microsoft Entra passkey enrollment by O-UNC-066
  • Cybercriminals

Passkey Phishing Campaign Uses Vishing Calls to Hijack Microsoft Entra Accounts

Do Son July 15, 2026 0
Read More Read more about Passkey Phishing Campaign Uses Vishing Calls to Hijack Microsoft Entra Accounts
CISA Warns Three SharePoint Server Vulnerabilities Are Exploited in the Wild, Urges Hardening CISA alert on SharePoint vulnerabilities exploited in the wild including CVE-2026-56164
  • Vulnerability Report

CISA Warns Three SharePoint Server Vulnerabilities Are Exploited in the Wild, Urges Hardening

Do Son July 15, 2026 0
Read More Read more about CISA Warns Three SharePoint Server Vulnerabilities Are Exploited in the Wild, Urges Hardening
Node.js Backdoor Hides Its C2 on the TON Blockchain Mercenary Akula European Financial Targeting AI-Generated Malware React2Shell Exploit UAT-8837 Critical Infrastructure Attack APT36, BOSS Linux BRICKSTORM Malware, China Espionage Curly COMrades, MucorAgent Chinese APT - HTTP Client Tools Shuckworm Cyber Espionage
  • Malware

Node.js Backdoor Hides Its C2 on the TON Blockchain

Do Son July 15, 2026 0
Read More Read more about Node.js Backdoor Hides Its C2 on the TON Blockchain
CVE-2026-15409: SonicWall SMA1000 SSRF Vulnerability (CVSS 10.0) Exploited in the Wild SonicWall SMA1000 SSRF vulnerability CVE-2026-15409 and CVE-2026-15410
  • Vulnerability Report

CVE-2026-15409: SonicWall SMA1000 SSRF Vulnerability (CVSS 10.0) Exploited in the Wild

Do Son July 15, 2026 0
Read More Read more about CVE-2026-15409: SonicWall SMA1000 SSRF Vulnerability (CVSS 10.0) Exploited in the Wild
LegacyHive: Exploit Code and Full Details Publicly Disclosed for Unpatched Windows Privilege Escalation Flaw LegacyHive exploit public disclosure Windows privilege escalation flaw by Nightmare-Eclipse
  • Vulnerability Report

LegacyHive: Exploit Code and Full Details Publicly Disclosed for Unpatched Windows Privilege Escalation Flaw

Do Son July 14, 2026 0
Read More Read more about LegacyHive: Exploit Code and Full Details Publicly Disclosed for Unpatched Windows Privilege Escalation Flaw
Microsoft July 2026 Patch Tuesday Fixes 570 Flaws, Two Zero-Days Exploited in the Wild Microsoft July 2026 Patch Tuesday zero-day vulnerabilities CVE-2026-56155 and CVE-2026-56164
  • Vulnerability Report

Microsoft July 2026 Patch Tuesday Fixes 570 Flaws, Two Zero-Days Exploited in the Wild

Do Son July 14, 2026 0
Read More Read more about Microsoft July 2026 Patch Tuesday Fixes 570 Flaws, Two Zero-Days Exploited in the Wild
Tego AI Finds Claude Tag Slack Integration Can Trigger Unauthorized Enterprise Actions watermarked_img_2256307174777406298_1784021571yc2c34V8Fl
  • Press Release

Tego AI Finds Claude Tag Slack Integration Can Trigger Unauthorized Enterprise Actions

cybernewswire July 14, 2026 0
Read More Read more about Tego AI Finds Claude Tag Slack Integration Can Trigger Unauthorized Enterprise Actions
CVE-2026-53481 & CVE-2026-53483: Dell PowerProtect Full Takeover (9.8) Image showing a hacker taking complete control of system using CVE-2026-53483 and Dell vulnerabilities
  • Vulnerability Report

CVE-2026-53481 & CVE-2026-53483: Dell PowerProtect Full Takeover (9.8)

Do Son July 14, 2026 0
Read More Read more about CVE-2026-53481 & CVE-2026-53483: Dell PowerProtect Full Takeover (9.8)
Exploited in the Wild? Debian Webhost Rooted as Public PoCs Land for Bad Epoll (CVE-2026-46242) and IPv6 Frag Escape Bad Epoll CVE-2026-46242 Linux kernel privilege escalation use-after-free public PoC exploit
  • Vulnerability Report

Exploited in the Wild? Debian Webhost Rooted as Public PoCs Land for Bad Epoll (CVE-2026-46242) and IPv6 Frag Escape

Do Son July 14, 2026 0
Read More Read more about Exploited in the Wild? Debian Webhost Rooted as Public PoCs Land for Bad Epoll (CVE-2026-46242) and IPv6 Frag Escape
CVE-2026-56000: Use-After-Free Flaw Hits X.Org Server and Xwayland X.Org Server use-after-free vulnerability CVE-2026-56000 patched in xorg-server 21.1.24
  • Vulnerability Report

CVE-2026-56000: Use-After-Free Flaw Hits X.Org Server and Xwayland

Do Son July 14, 2026 0
Read More Read more about CVE-2026-56000: Use-After-Free Flaw Hits X.Org Server and Xwayland
CVE-2026-59948: PHP Composer Flaw Lets Packages Execute Code Outside the Project Context PHP Composer arbitrary file write vulnerability CVE-2026-59948 patched in version 2.10.2
  • Vulnerability Report

CVE-2026-59948: PHP Composer Flaw Lets Packages Execute Code Outside the Project Context

Do Son July 14, 2026 0
Read More Read more about CVE-2026-59948: PHP Composer Flaw Lets Packages Execute Code Outside the Project Context
Public Exploit and Details Released for Bad Epoll Root Flaw (CVE-2026-46242) Bad Epoll CVE-2026-46242 Linux kernel use-after-free enabling root privilege escalation
  • Vulnerability Report

Public Exploit and Details Released for Bad Epoll Root Flaw (CVE-2026-46242)

Do Son July 14, 2026 0
Read More Read more about Public Exploit and Details Released for Bad Epoll Root Flaw (CVE-2026-46242)
Anthropic API Billing Error Hits Developer for $16M Anthropic API billing error notification, Claude API incorrect charge screenshot
  • Technology

Anthropic API Billing Error Hits Developer for $16M

Do Son July 14, 2026 0
Read More Read more about Anthropic API Billing Error Hits Developer for $16M
VMware Avi Load Balancer Authentication Bypass (CVE-2026-47865, CVSS 9.8) Headlines Seven-Flaw Patch VMware Avi Load Balancer authentication bypass vulnerability CVE-2026-47865 CVSS 9.8 critical patch
  • Vulnerability Report

VMware Avi Load Balancer Authentication Bypass (CVE-2026-47865, CVSS 9.8) Headlines Seven-Flaw Patch

Do Son July 14, 2026 0
Read More Read more about VMware Avi Load Balancer Authentication Bypass (CVE-2026-47865, CVSS 9.8) Headlines Seven-Flaw Patch
Meta Louisiana Data Center: A $50 Billion AI Gamble Meta Louisiana data center facility, Project Hyperion AI infrastructure investment, 5GW computing capacity server farm
  • Technology

Meta Louisiana Data Center: A $50 Billion AI Gamble

Do Son July 14, 2026 0
Read More Read more about Meta Louisiana Data Center: A $50 Billion AI Gamble
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intel📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intel📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intel📅 Updated: Jul 21, 2026
  • CVE-2026-6875CVSS 9.5
    ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability...
    Admin intel📅 Updated: Jul 18, 2026
  • CVE-2026-39808CVSS 9.8
    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox...
    CISA KEV📅 Added to KEV: Jul 16, 2026
  • CVE-2026-25089CVSS 9.8
    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox...
    CISA KEV📅 Added to KEV: Jul 16, 2026
  • CVE-2026-58644CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    CISA KEV📅 Added to KEV: Jul 16, 2026
  • CVE-2023-4346CVSS 7.5
    KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to...
    CISA KEV📅 Added to KEV: Jul 15, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-13439CVSS 9.8
    The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to...
  • CVE-2026-64625CVSS 9.8
    AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps...
  • CVE-2026-53595CVSS 9.4
    FreeScout is a free help desk and shared inbox built with PHP's...
  • CVE-2026-44231CVSS 9.1
    RT is an open source, enterprise-grade issue and ticket tracking system. Versions...
  • CVE-2026-63766CVSS 9.8
    GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where...
  • CVE-2026-63767CVSS 9.8
    ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization...
  • CVE-2026-39878CVSS 9.3
    Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability...
  • CVE-2026-54051CVSS 9.9
    Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent...
  • CVE-2026-41252CVSS 9.8
    xrdp is an open source RDP server. Versions 0.10.6 and prior contain...
  • CVE-2026-35048CVSS 9.8
    The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.