Skip to content
September 25, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Android Boosts Anti-Theft Measures with AI and Biometric Security Android security, anti-theft backup Android Identity Check & Theft Detection Lock
  • Android
  • Technology

Android Boosts Anti-Theft Measures with AI and Biometric Security

Do Son January 24, 2025 0
Read More Read more about Android Boosts Anti-Theft Measures with AI and Biometric Security
Social Media Marketing: Definition, Significance, and Strategic Insights email-4284157_1280
  • Technique

Social Media Marketing: Definition, Significance, and Strategic Insights

Do Son January 24, 2025 0
Read More Read more about Social Media Marketing: Definition, Significance, and Strategic Insights
CVE-2024-43468 (CVSS 9.8): Microsoft Configuration Manager Exploit Revealed with PoC Code CVE-2024-43468 PoC exploit
  • Vulnerability

CVE-2024-43468 (CVSS 9.8): Microsoft Configuration Manager Exploit Revealed with PoC Code

Do Son January 23, 2025 0
Read More Read more about CVE-2024-43468 (CVSS 9.8): Microsoft Configuration Manager Exploit Revealed with PoC Code
CVE-2025-21535 (CVSS 9.8): Vulnerability in Oracle WebLogic Server Could Lead to Remote Code Execution CVE-2025-21535 Oracle EBS RCE, CVE-2025-61882
  • Vulnerability

CVE-2025-21535 (CVSS 9.8): Vulnerability in Oracle WebLogic Server Could Lead to Remote Code Execution

Do Son January 23, 2025 0
Read More Read more about CVE-2025-21535 (CVSS 9.8): Vulnerability in Oracle WebLogic Server Could Lead to Remote Code Execution
Malicious VS Code Extension Masquerades as Zoom to Steal Chrome Cookies Malicious VS Code Extension
  • Malware

Malicious VS Code Extension Masquerades as Zoom to Steal Chrome Cookies

Do Son January 23, 2025 0
Read More Read more about Malicious VS Code Extension Masquerades as Zoom to Steal Chrome Cookies
CVE-2024-43707: Kibana Patches High Severity Vulnerability Exposing Sensitive Information CVE-2024-43707 Kibana vulnerability Prototype pollution CVE-2025-25014
  • Vulnerability

CVE-2024-43707: Kibana Patches High Severity Vulnerability Exposing Sensitive Information

Do Son January 23, 2025 0
Read More Read more about CVE-2024-43707: Kibana Patches High Severity Vulnerability Exposing Sensitive Information
Beyond DocuSign: Credential Harvesting Now Targets a Wider Range of Cloud Apps Credential Harvesting
  • Cyber Security

Beyond DocuSign: Credential Harvesting Now Targets a Wider Range of Cloud Apps

Do Son January 23, 2025 0
Read More Read more about Beyond DocuSign: Credential Harvesting Now Targets a Wider Range of Cloud Apps
Donot APT Group Targets Android Devices with Malicious Chat Apps Donot APT Group - Android zero-day
  • Malware

Donot APT Group Targets Android Devices with Malicious Chat Apps

Do Son January 23, 2025 0
Read More Read more about Donot APT Group Targets Android Devices with Malicious Chat Apps
2024 Payment Fraud Report: E-Skimming, Check Fraud, and Threat Actor Sophistication Soar Payment Fraud Report
  • Cyber Security

2024 Payment Fraud Report: E-Skimming, Check Fraud, and Threat Actor Sophistication Soar

Do Son January 23, 2025 0
Read More Read more about 2024 Payment Fraud Report: E-Skimming, Check Fraud, and Threat Actor Sophistication Soar
phpMyAdmin Patches XSS Vulnerabilities in Latest Release phpMyAdmin Vulnerabilities
  • Vulnerability

phpMyAdmin Patches XSS Vulnerabilities in Latest Release

Do Son January 23, 2025 0
Read More Read more about phpMyAdmin Patches XSS Vulnerabilities in Latest Release
CVE-2024-7029 and CVE-2017-17215 Exploited in Latest Murdoc Botnet Attacks FortiClient EMS exploitation Cisco FIRESTARTER Backdoor Arcane Door Campaign Dell RecoverPoint Zero-Day UNC6201 Espionage Notepad++ Compromise Supply Chain Attack Magento SessionReaper CVE-2025-54236 ShadowRay 2.0, AI-Generated Malware WordPress Auth Bypass, CVE-2025-5947 Exploited EcoStruxure Vulnerabilities, Industrial Control System UNC5820 - CVE-2014-2120 - CVE-2021-44207
  • Malware
  • Vulnerability

CVE-2024-7029 and CVE-2017-17215 Exploited in Latest Murdoc Botnet Attacks

Do Son January 23, 2025 0
Read More Read more about CVE-2024-7029 and CVE-2017-17215 Exploited in Latest Murdoc Botnet Attacks
Stealthy and Persistent: New Ransomware Tactics Target VMware ESXi SonicWall Reconnaissance Akira Ransomware residential proxy malware TraderTraitor BreachForums Honeypot, French Interior Ministry Leak
  • Malware

Stealthy and Persistent: New Ransomware Tactics Target VMware ESXi

Do Son January 23, 2025 0
Read More Read more about Stealthy and Persistent: New Ransomware Tactics Target VMware ESXi
STAC5143 and STAC5777: New Ransomware Campaigns Target Microsoft Office 365 Users NATS-as-C2 Sysdig CVE-2026-33017 Langflow RCE Microsoft Phone Link Hijack CloudZ Pheno Plugin Insider Threat BlackCat (ALPHV) OFAC Sanctions DPRK IT Workers Transparent Tribe APT36 React2Shell, EtherRAT SideWinder Espionage, Netlify Phishing DDNS Abuse, C2 Infrastructure Hacking Health Club
  • Cyber Security

STAC5143 and STAC5777: New Ransomware Campaigns Target Microsoft Office 365 Users

Do Son January 23, 2025 0
Read More Read more about STAC5143 and STAC5777: New Ransomware Campaigns Target Microsoft Office 365 Users
CVE-2025-23006 (CVSS 9.8): SonicWall Warns of Active Exploits, Issues Urgent Update for SMA1000 Users SonicWall Security Advisory SonicOS Patch 2026 CVE-2025-23006 SonicWall, SMA 100 Vulnerabilities
  • Vulnerability

CVE-2025-23006 (CVSS 9.8): SonicWall Warns of Active Exploits, Issues Urgent Update for SMA1000 Users

Do Son January 23, 2025 0
Read More Read more about CVE-2025-23006 (CVSS 9.8): SonicWall Warns of Active Exploits, Issues Urgent Update for SMA1000 Users
CVE-2025-0314: GitLab Releases Patch for XSS Exploit GitLab AI Gateway Vulnerability CVE-2026-1868 CVE-2025-0314 GitLab Security Update CVE-2025-9222
  • Vulnerability

CVE-2025-0314: GitLab Releases Patch for XSS Exploit

Do Son January 23, 2025 0
Read More Read more about CVE-2025-0314: GitLab Releases Patch for XSS Exploit
CISA and FBI Warn of Exploited Ivanti CSA Vulnerabilities in Joint Security Advisory OCRFix Botnet EtherHiding CrowdStrike supply chain attack Ivanti CSA Vulnerabilities
  • Vulnerability

CISA and FBI Warn of Exploited Ivanti CSA Vulnerabilities in Joint Security Advisory

Do Son January 22, 2025 0
Read More Read more about CISA and FBI Warn of Exploited Ivanti CSA Vulnerabilities in Joint Security Advisory
CVE-2025-20156 (CVSS 9.9): Cisco Meeting Management Flaw Allows for Privilege Escalation CVE-2025-20156
  • Vulnerability

CVE-2025-20156 (CVSS 9.9): Cisco Meeting Management Flaw Allows for Privilege Escalation

Do Son January 22, 2025 0
Read More Read more about CVE-2025-20156 (CVSS 9.9): Cisco Meeting Management Flaw Allows for Privilege Escalation
Purrglar: Emerging Stealer Targets Chrome and Exodus Wallet Data on macOS shell-quote command injection AI-Driven Vulnerabilities Q1 2026 Cyber Threats vm2 Sandbox Escape Node.js RCE upKeeper Privilege Escalation CVE-2026-2449 Pharos Controls Vulnerability Root Access Exploit Cybersecurity Vulnerability Roundup CVSS 10.0 Flaws Shadow Archives CVE-2026-0866 MS-Agent Prompt Injection CVE-2026-2256 basic-ftp Path Traversal CVE-2026-27699 telnetd Root Vulnerability CVE-1999-0073 Regression USR-W610 Vulnerabilities End-of-Life IoT Security IceWarp Security Update IceWarp Vulnerabilities Airleader Master Vulnerability CVE-2026-1358 ZLAN5143D Vulnerability CISA ICS Advisory Acronis Cyber Protect Vulnerability CVE-2025-30411 WAGO 852 Vulnerability OT Network Security SandboxJS Vulnerability Sandbox Escape (CVSS 10.0) Kubernetes Local Path Provisioner CVE-2025-62878 CISA Unresponsive Vendors Avation & RISS Vulnerabilities KiloView Vulnerability CVE-2026-1453 OpenClaw RCE vulnerability Johnson Controls Vulnerability CVE-2025-26385 SandboxJS Vulnerability CVE-2026-23830 ibaPDA Vulnerability CVE-2025-14988 Protobuf Vulnerability CVE-2026-0994 AVEVA Process Optimization Vulnerability CVE-2025-61937 ConnectWise PSA Vulnerability CVE-2026-0695 Aruba VIA Vulnerability CVE-2025-37186 aiohttp v3.13.3, Denial of Service (DoS) SmarterMail RCE, CVE-2025-52691 Airoha RACE, Headphone Jacking HPE OneView RCE CVE-2025-37164 FreePBX Auth Bypass, PBX Takeover ScreenConnect Config Flaw, Untrusted Extensions Ruby SAML Auth Bypass, XML Parser Differential Devolutions SQL Injection, Password Manager Flaw Vivotek Unauthenticated RCE, EOL IP Camera Flaw Lynx+ Critical Flaw, Unauthenticated Reset Firebox Default Credentials, CVE-2025-59396 Veeder-Root RCE, Critical ATG Flaw ArcGIS Server SQLi Watchdoc RCE, CVE-2025-58384 Delta DIALink Daikin Security Gateway, authentication bypass Frostbyte10, industrial controller security SunPower, vulnerability Ubiquiti UniFi Connect, EV Station Vulnerabilities Adobe Experience Manager, RCE Vulnerability UniFi Access, Command Injection LDAPNightmare - CVE-2025-1316
  • Malware

Purrglar: Emerging Stealer Targets Chrome and Exodus Wallet Data on macOS

Do Son January 22, 2025 0
Read More Read more about Purrglar: Emerging Stealer Targets Chrome and Exodus Wallet Data on macOS
Signal and Discord Vulnerabilities Exposed: 0-Click Deanonymization Attack Revealed deanonymization attack - cache geolocation attack
  • Data Leak
  • Vulnerability

Signal and Discord Vulnerabilities Exposed: 0-Click Deanonymization Attack Revealed

Do Son January 22, 2025 0
Read More Read more about Signal and Discord Vulnerabilities Exposed: 0-Click Deanonymization Attack Revealed
ApateWeb Campaign Hijacks Blogspot, Spreads Phishing and Malware ApateWeb operation
  • Cyber Security

ApateWeb Campaign Hijacks Blogspot, Spreads Phishing and Malware

Do Son January 22, 2025 0
Read More Read more about ApateWeb Campaign Hijacks Blogspot, Spreads Phishing and Malware
Mercedes-Benz MBUX Vulnerabilities: User Data and Safety at Risk mercedes-benz-2692776_1280
  • Vulnerability

Mercedes-Benz MBUX Vulnerabilities: User Data and Safety at Risk

Do Son January 22, 2025 0
Read More Read more about Mercedes-Benz MBUX Vulnerabilities: User Data and Safety at Risk
New Bruteforce Campaign Exploits fasthttp Library to Target Azure Environments Azure Bruteforce Campaign
  • Cyber Security

New Bruteforce Campaign Exploits fasthttp Library to Target Azure Environments

Do Son January 22, 2025 0
Read More Read more about New Bruteforce Campaign Exploits fasthttp Library to Target Azure Environments
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-94127CVSS 9.8
    When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-85102CVSS 9.8
    Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93616CVSS 9.8
    A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93952CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-78445CVSS 9.8
    Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code...
    📅 Updated: Sep 24, 2026
  • CVE-2026-77493CVSS 9.8
    Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
    📅 Updated: Sep 24, 2026
  • CVE-2026-73025CVSS 9.8
    Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.
    📅 Updated: Sep 24, 2026
  • CVE-2026-73009CVSS 9.8
    Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over...
    📅 Updated: Sep 24, 2026
  • CVE-2026-72979CVSS 9.8
    Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
    📅 Updated: Sep 24, 2026
  • CVE-2026-72982CVSS 9.8
    Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
    📅 Updated: Sep 24, 2026
  • CVE-2026-72983CVSS 9.8
    Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a...
    📅 Updated: Sep 24, 2026
  • CVE-2026-70296CVSS 9.8
    Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
    📅 Updated: Sep 24, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.