Skip to content
October 11, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
IBM Patches 25 Langflow Vulnerabilities, Including Two Critical Remote Code Execution Flaws Langflow vulnerabilities fixed in Langflow 1.12.3 including critical CVE-2026-104334 and CVE-2026-93674 remote code execution
  • Vulnerability Report

IBM Patches 25 Langflow Vulnerabilities, Including Two Critical Remote Code Execution Flaws

Do Son October 6, 2026 0
Read More Read more about IBM Patches 25 Langflow Vulnerabilities, Including Two Critical Remote Code Execution Flaws
Apache Thrift 0.25.0 Fixes 61 Vulnerabilities, Including Two Critical Heap Overflows Apache Thrift vulnerabilities fixed in Apache Thrift 0.25.0 including CVE-2026-83632 and CVE-2026-91135
  • Vulnerability Report

Apache Thrift 0.25.0 Fixes 61 Vulnerabilities, Including Two Critical Heap Overflows

Do Son October 6, 2026 0
Read More Read more about Apache Thrift 0.25.0 Fixes 61 Vulnerabilities, Including Two Critical Heap Overflows
AMD RCCL Vulnerability Could Enable Remote Code Execution on Instinct GPU Clusters AMD RCCL vulnerability CVE-2026-43598 in the ROCm Communication Collectives Library on AMD Instinct GPUs
  • Vulnerability Report

AMD RCCL Vulnerability Could Enable Remote Code Execution on Instinct GPU Clusters

Do Son October 6, 2026 0
Read More Read more about AMD RCCL Vulnerability Could Enable Remote Code Execution on Instinct GPU Clusters
Who Can Actually Compel Your Hosting Provider: A Jurisdiction Guide for Security Teams DCMTK vulnerabilities enabling path traversal file write in the DICOM toolkit (CVE-2026-50003)
  • Technique

Who Can Actually Compel Your Hosting Provider: A Jurisdiction Guide for Security Teams

Do Son October 5, 2026 0
Read More Read more about Who Can Actually Compel Your Hosting Provider: A Jurisdiction Guide for Security Teams
Apache Struts 7.4.0 Fixes Four Vulnerabilities, Including OGNL Injection and REST Plugin DoS Apache Struts vulnerabilities fixed in Struts 7.4.0 including OGNL injection CVE-2026-104711 and REST plugin DoS CVE-2026-104713
  • Vulnerability Report

Apache Struts 7.4.0 Fixes Four Vulnerabilities, Including OGNL Injection and REST Plugin DoS

Do Son October 5, 2026 0
Read More Read more about Apache Struts 7.4.0 Fixes Four Vulnerabilities, Including OGNL Injection and REST Plugin DoS
Google Fortifies Android Advanced Protection Google Android Advanced Protection shield icon over smartphone interface showing security updates
  • Android

Google Fortifies Android Advanced Protection

Do Son October 5, 2026 0
Read More Read more about Google Fortifies Android Advanced Protection
8 Top Tools to Discover Shadow Agents Diagram illustrating Langflow OSS vulnerabilities and CVE-2026-10134 execution paths
  • Technique

8 Top Tools to Discover Shadow Agents

Do Son October 5, 2026 0
Read More Read more about 8 Top Tools to Discover Shadow Agents
ShinyHunters Hacker Arrest in Jordan Aids FBI Probe ShinyHunters hacker arrest in Jordan as an alleged member cooperates with the FBI ShinyHunters investigation
  • Cybercriminals

ShinyHunters Hacker Arrest in Jordan Aids FBI Probe

Do Son October 5, 2026 0
Read More Read more about ShinyHunters Hacker Arrest in Jordan Aids FBI Probe
Perforce Fixes Six P4 Search Vulnerabilities, Including a CVSS 10 Default Token Flaw Perforce P4 Search vulnerabilities CVE-2026-100103 default token and CVE-2026-100102 exposed Java debug interface in P4 Search
  • Vulnerability Report

Perforce Fixes Six P4 Search Vulnerabilities, Including a CVSS 10 Default Token Flaw

Do Son October 5, 2026 0
Read More Read more about Perforce Fixes Six P4 Search Vulnerabilities, Including a CVSS 10 Default Token Flaw
Windows 11 26H2 Update Arrives With a Single Restart Windows 11 26H2 update installing through Windows Update with an enablement package, the Windows 11 2026 Update
  • Windows

Windows 11 26H2 Update Arrives With a Single Restart

Do Son October 5, 2026 0
Read More Read more about Windows 11 26H2 Update Arrives With a Single Restart
Cloudflare Clef Decision Models Speed Up AI Agents Cloudflare Clef decision models returning option probability scores for AI agents on the Workers AI platform
  • Technology

Cloudflare Clef Decision Models Speed Up AI Agents

Do Son October 5, 2026 0
Read More Read more about Cloudflare Clef Decision Models Speed Up AI Agents
MediaTek October 2026 Security Bulletin Fixes 31 Flaws, Including Two Critical Modem Bugs MediaTek security bulletin October 2026 MediaTek modem vulnerability CVE-2026-20519 CVE-2026-20520 rogue base station
  • Vulnerability Report

MediaTek October 2026 Security Bulletin Fixes 31 Flaws, Including Two Critical Modem Bugs

Do Son October 5, 2026 0
Read More Read more about MediaTek October 2026 Security Bulletin Fixes 31 Flaws, Including Two Critical Modem Bugs
OpenAI Rogue AI Agents May Have Hit 100+ Organizations OpenAI rogue AI agents reaching beyond their sandbox into third-party systems, part of a wave of AI agent misalignment incidents
  • Technology

OpenAI Rogue AI Agents May Have Hit 100+ Organizations

Do Son October 5, 2026 0
Read More Read more about OpenAI Rogue AI Agents May Have Hit 100+ Organizations
Moroccan Intelligence Deploys Vast Surveillance Panopticon Amnesty International exposing the Moroccan DGST surveillance network and Pegasus spyware infections
  • Malware

Moroccan Intelligence Deploys Vast Surveillance Panopticon

Do Son October 5, 2026 0
Read More Read more about Moroccan Intelligence Deploys Vast Surveillance Panopticon
Ubuntu 26.04 Upgrade Now Open to 24.04 LTS Users Ubuntu 26.04 upgrade offered in Update Manager to Ubuntu 24.04 LTS users, showing the Resolute Raccoon desktop
  • Linux

Ubuntu 26.04 Upgrade Now Open to 24.04 LTS Users

Do Son October 5, 2026 0
Read More Read more about Ubuntu 26.04 Upgrade Now Open to 24.04 LTS Users
DragonForce Backdoor Adds MQTT Fallback to Microsoft Teams TURN Command Channel DragonForce backdoor using Microsoft Teams TURN relays and MQTT as a fallback command channel
  • Malware

DragonForce Backdoor Adds MQTT Fallback to Microsoft Teams TURN Command Channel

Do Son October 5, 2026 0
Read More Read more about DragonForce Backdoor Adds MQTT Fallback to Microsoft Teams TURN Command Channel
New 2CLoader Malware Delivers Vidar and Remus Infostealers While Dodging Sandboxes 2CLoader malware infection chain delivering Vidar and Remus infostealers with anti-VM and evasion checks
  • Malware

New 2CLoader Malware Delivers Vidar and Remus Infostealers While Dodging Sandboxes

Do Son October 5, 2026 0
Read More Read more about New 2CLoader Malware Delivers Vidar and Remus Infostealers While Dodging Sandboxes
BPFDoor Backdoor and New AVERAT Implant Hide in SMTP Traffic on Telecom Edge Devices BPFDoor backdoor and AVERAT implant disguised as mail traffic on telecom and network edge appliances
  • Malware

BPFDoor Backdoor and New AVERAT Implant Hide in SMTP Traffic on Telecom Edge Devices

Do Son October 5, 2026 0
Read More Read more about BPFDoor Backdoor and New AVERAT Implant Hide in SMTP Traffic on Telecom Edge Devices
Socket Links Popular VS Code Color Themes to the GlassWorm Supply Chain Campaign GlassWorm VS Code themes cluster of malicious VS Code extensions posing as color themes
  • Malware

Socket Links Popular VS Code Color Themes to the GlassWorm Supply Chain Campaign

Do Son October 5, 2026 0
Read More Read more about Socket Links Popular VS Code Color Themes to the GlassWorm Supply Chain Campaign
Weekly CVE Report Tracks 2,652 New Flaws and Seven Exploited Vulnerabilities (Sept. 28 – Oct. 4, 2026) Weekly CVE report on exploited vulnerabilities from Daily Cybersecurity and CISA KEV, September 28 to October 4, 2026
  • Weekly Recap

Weekly CVE Report Tracks 2,652 New Flaws and Seven Exploited Vulnerabilities (Sept. 28 – Oct. 4, 2026)

Do Son October 5, 2026 0
Read More Read more about Weekly CVE Report Tracks 2,652 New Flaws and Seven Exploited Vulnerabilities (Sept. 28 – Oct. 4, 2026)
Warlock Ransomware Group Hits Water and Telecom Operators Through SharePoint Flaws Warlock ransomware attack chain exploiting SharePoint vulnerabilities to hit critical infrastructure
  • Cybercriminals

Warlock Ransomware Group Hits Water and Telecom Operators Through SharePoint Flaws

Do Son October 5, 2026 0
Read More Read more about Warlock Ransomware Group Hits Water and Telecom Operators Through SharePoint Flaws
Researcher Publishes Technical Details and PoC Exploit for macOS HFS+ Kernel Flaw CVE-2026-43682 macOS HFS+ vulnerability CVE-2026-43682 kernel heap overflow with public proof-of-concept exploit code
  • Vulnerability Report

Researcher Publishes Technical Details and PoC Exploit for macOS HFS+ Kernel Flaw CVE-2026-43682

Do Son October 5, 2026 0
Read More Read more about Researcher Publishes Technical Details and PoC Exploit for macOS HFS+ Kernel Flaw CVE-2026-43682
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
πŸ“ˆ

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

πŸ›‘οΈ

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

πŸ™

GitHub Issues
Auto-create alert tickets without duplication.

πŸ“¬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

πŸ”€

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days β†’

🚨 Active Exploits in the Wild

  • CVE-2026-102255CVSS 10.0
    A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access...
    Admin intel📅 Updated: Oct 9, 2026
  • CVE-2026-105133CVSS 6.9
    A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file...
    Admin intel📅 Updated: Oct 9, 2026
  • CVE-2023-22894CVSS 4.9
    Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2016-3081CVSS 8.1
    Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled,...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2015-3306CVSS 10.0
    The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2015-5477CVSS 7.5
    named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2021-3199CVSS 9.8
    Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-78533CVSS 9.8
    Unauthenticated PHP Object Injection in Qwery
    📅 Updated: Oct 10, 2026
  • CVE-2026-78535CVSS 9.8
    Unauthenticated PHP Object Injection in Photolia
    📅 Updated: Oct 10, 2026
  • CVE-2026-81797CVSS 9.8
    Unauthenticated PHP Object Injection in Buzz Stone | Magazine & Viral Blog WordPress Theme
    📅 Updated: Oct 10, 2026
  • CVE-2026-66567CVSS 9.8
    Unauthenticated PHP Object Injection in Anesta
    📅 Updated: Oct 10, 2026
  • CVE-2026-66568CVSS 9.8
    Unauthenticated PHP Object Injection in Original
    📅 Updated: Oct 10, 2026
  • CVE-2026-66569CVSS 9.8
    Unauthenticated PHP Object Injection in Kicker
    📅 Updated: Oct 10, 2026
  • CVE-2026-78529CVSS 9.8
    Unauthenticated PHP Object Injection in Alliance
    📅 Updated: Oct 10, 2026
  • CVE-2026-78531CVSS 9.8
    Unauthenticated PHP Object Injection in Jacqueline
    📅 Updated: Oct 10, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
Β© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.