Skip to content
September 25, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
CVE-2024-12847 (CVSS 9.8): NETGEAR Router Flaw Exploited in the Wild for Years, PoC Published CVE-2024-12847 - CVE-2022-41545
  • Vulnerability

CVE-2024-12847 (CVSS 9.8): NETGEAR Router Flaw Exploited in the Wild for Years, PoC Published

Do Son January 10, 2025 0
Read More Read more about CVE-2024-12847 (CVSS 9.8): NETGEAR Router Flaw Exploited in the Wild for Years, PoC Published
Cracked Software: A Gateway to Malware and Data Theft ahost.exe DLL Sideloading Signed Application Abuse PS1Bot, malware ransomware attacks bill
  • Malware

Cracked Software: A Gateway to Malware and Data Theft

Do Son January 10, 2025 0
Read More Read more about Cracked Software: A Gateway to Malware and Data Theft
Ivanti Connect Secure Zero-Day Threat: 2,048 Vulnerable Devices and Critical Exploitation Details Unveiled NATS-as-C2 Sysdig CVE-2026-33017 Langflow RCE Microsoft Phone Link Hijack CloudZ Pheno Plugin Insider Threat BlackCat (ALPHV) OFAC Sanctions DPRK IT Workers Transparent Tribe APT36 React2Shell, EtherRAT SideWinder Espionage, Netlify Phishing DDNS Abuse, C2 Infrastructure Hacking Health Club
  • Vulnerability

Ivanti Connect Secure Zero-Day Threat: 2,048 Vulnerable Devices and Critical Exploitation Details Unveiled

Do Son January 10, 2025 0
Read More Read more about Ivanti Connect Secure Zero-Day Threat: 2,048 Vulnerable Devices and Critical Exploitation Details Unveiled
Recruitment Scam Targets Job Seekers with Fake CrowdStrike Branding CrowdStrike phishing campaign
  • Cyber Security

Recruitment Scam Targets Job Seekers with Fake CrowdStrike Branding

Do Son January 10, 2025 0
Read More Read more about Recruitment Scam Targets Job Seekers with Fake CrowdStrike Branding
Microsoft to Cut 2,200 Jobs in Performance-Based Layoffs Microsoft Developer Account Suspension Microsoft Web Activation Portal Driver Signing Account Suspension Windows 11 Smart App Control Windows 11 SE end of support, Microsoft education hardware pivot Microsoft Product Activation Portal 2025, Windows telephone activation discontinued Windows Update Naming, Microsoft Update Microsoft earnings, OpenAI valuation VBScript deprecation Microsoft Pakistan, Office Closure Microsoft job cuts Microsoft Own AI Models
  • Technology

Microsoft to Cut 2,200 Jobs in Performance-Based Layoffs

Do Son January 9, 2025 0
Read More Read more about Microsoft to Cut 2,200 Jobs in Performance-Based Layoffs
Node.js to Issue CVE for End-of-Life Versions CVE-2024-36138 - Node.js vulnerability
  • Technology
  • Vulnerability

Node.js to Issue CVE for End-of-Life Versions

Do Son January 9, 2025 0
Read More Read more about Node.js to Issue CVE for End-of-Life Versions
Stealthy Malware Hides in WordPress Database, Steals Payment Data Credit Card Skimmer
  • Malware

Stealthy Malware Hides in WordPress Database, Steals Payment Data

Do Son January 9, 2025 0
Read More Read more about Stealthy Malware Hides in WordPress Database, Steals Payment Data
Fake LDAPNightmare PoC Exploit Conceals Information-Stealing Malware shell-quote command injection AI-Driven Vulnerabilities Q1 2026 Cyber Threats vm2 Sandbox Escape Node.js RCE upKeeper Privilege Escalation CVE-2026-2449 Pharos Controls Vulnerability Root Access Exploit Cybersecurity Vulnerability Roundup CVSS 10.0 Flaws Shadow Archives CVE-2026-0866 MS-Agent Prompt Injection CVE-2026-2256 basic-ftp Path Traversal CVE-2026-27699 telnetd Root Vulnerability CVE-1999-0073 Regression USR-W610 Vulnerabilities End-of-Life IoT Security IceWarp Security Update IceWarp Vulnerabilities Airleader Master Vulnerability CVE-2026-1358 ZLAN5143D Vulnerability CISA ICS Advisory Acronis Cyber Protect Vulnerability CVE-2025-30411 WAGO 852 Vulnerability OT Network Security SandboxJS Vulnerability Sandbox Escape (CVSS 10.0) Kubernetes Local Path Provisioner CVE-2025-62878 CISA Unresponsive Vendors Avation & RISS Vulnerabilities KiloView Vulnerability CVE-2026-1453 OpenClaw RCE vulnerability Johnson Controls Vulnerability CVE-2025-26385 SandboxJS Vulnerability CVE-2026-23830 ibaPDA Vulnerability CVE-2025-14988 Protobuf Vulnerability CVE-2026-0994 AVEVA Process Optimization Vulnerability CVE-2025-61937 ConnectWise PSA Vulnerability CVE-2026-0695 Aruba VIA Vulnerability CVE-2025-37186 aiohttp v3.13.3, Denial of Service (DoS) SmarterMail RCE, CVE-2025-52691 Airoha RACE, Headphone Jacking HPE OneView RCE CVE-2025-37164 FreePBX Auth Bypass, PBX Takeover ScreenConnect Config Flaw, Untrusted Extensions Ruby SAML Auth Bypass, XML Parser Differential Devolutions SQL Injection, Password Manager Flaw Vivotek Unauthenticated RCE, EOL IP Camera Flaw Lynx+ Critical Flaw, Unauthenticated Reset Firebox Default Credentials, CVE-2025-59396 Veeder-Root RCE, Critical ATG Flaw ArcGIS Server SQLi Watchdoc RCE, CVE-2025-58384 Delta DIALink Daikin Security Gateway, authentication bypass Frostbyte10, industrial controller security SunPower, vulnerability Ubiquiti UniFi Connect, EV Station Vulnerabilities Adobe Experience Manager, RCE Vulnerability UniFi Access, Command Injection LDAPNightmare - CVE-2025-1316
  • Malware

Fake LDAPNightmare PoC Exploit Conceals Information-Stealing Malware

Do Son January 9, 2025 0
Read More Read more about Fake LDAPNightmare PoC Exploit Conceals Information-Stealing Malware
New PayPal Phishing Scam Bypasses Security Measures PayPal Industrial Bank, Fintech Crypto Lending PayPal, Hotel Booking Perplexity AI, PayPal
  • Cyber Security

New PayPal Phishing Scam Bypasses Security Measures

Do Son January 9, 2025 0
Read More Read more about New PayPal Phishing Scam Bypasses Security Measures
The Linux Foundation to Manage New Chromium Fund Chrome 14-day update cycle Chromium JPEG-XL Image Format Debate Chromium DoS, document.title Browser Muting, iframe Media Supporters of Chromium-based Browsers
  • Technology

The Linux Foundation to Manage New Chromium Fund

Do Son January 9, 2025 0
Read More Read more about The Linux Foundation to Manage New Chromium Fund
Malicious npm Packages Target Solana Developers, Stealing Private Keys via Gmail XCharge C6 vulnerabilities EV charger security flaws GNU libtasn1 Vulnerability CVE-2025-13151 Credit Card Skimmer Malware CVE-2024-13892
  • Malware

Malicious npm Packages Target Solana Developers, Stealing Private Keys via Gmail

Do Son January 9, 2025 0
Read More Read more about Malicious npm Packages Target Solana Developers, Stealing Private Keys via Gmail
Unmasking Play Ransomware: Tactics, Techniques, and Mitigation Strategies Play Ransomware Tactics
  • Malware

Unmasking Play Ransomware: Tactics, Techniques, and Mitigation Strategies

Do Son January 9, 2025 0
Read More Read more about Unmasking Play Ransomware: Tactics, Techniques, and Mitigation Strategies
Muddling Malspam: Unveiling the Use of Spoofed Domains in Malicious Spam Campaigns Gmail Scam
  • Cyber Security

Muddling Malspam: Unveiling the Use of Spoofed Domains in Malicious Spam Campaigns

Do Son January 9, 2025 0
Read More Read more about Muddling Malspam: Unveiling the Use of Spoofed Domains in Malicious Spam Campaigns
Unpatched Vulnerabilities in Fancy Product Designer Plugin Put 20,000+ Websites at Risk CVE-2024-51919 & CVE-2024-51918
  • Vulnerability

Unpatched Vulnerabilities in Fancy Product Designer Plugin Put 20,000+ Websites at Risk

Do Son January 9, 2025 0
Read More Read more about Unpatched Vulnerabilities in Fancy Product Designer Plugin Put 20,000+ Websites at Risk
Malware Alert: Banshee Stealer Targets macOS Users macOS malware 2024 XCSSET
  • Malware

Malware Alert: Banshee Stealer Targets macOS Users

Do Son January 9, 2025 0
Read More Read more about Malware Alert: Banshee Stealer Targets macOS Users
Tails 6.11 Fixes Exploitable Vulnerabilities with Critical Security Patches Tails vulnerability - Tails 6.11
  • Linux
  • Vulnerability

Tails 6.11 Fixes Exploitable Vulnerabilities with Critical Security Patches

Do Son January 9, 2025 0
Read More Read more about Tails 6.11 Fixes Exploitable Vulnerabilities with Critical Security Patches
Breaking News: How to Achieve Financial Freedom and Make Money with DDB Miner CVE-2024-55563 - transaction-relay jamming attack
  • Technique

Breaking News: How to Achieve Financial Freedom and Make Money with DDB Miner

Do Son January 9, 2025 0
Read More Read more about Breaking News: How to Achieve Financial Freedom and Make Money with DDB Miner
Zero-Day Alert: UNC5337 Exploits Ivanti VPN Vulnerability CVE-2025-0282 for Espionage Operations Check Point VPN vulnerability exploited in the wild Check Point VPN exploit CVE-2026-50751 zero-day Checkmarx Breach Supply Chain Attack Ivanti EPMM RCE CVE-2026-1281 Modular DS Vulnerability CVE-2026-23550 D-Link RCE Vulnerability CVE-2026-0625 Christmas 2025 GreyNoise Campaign, Japan-Based Initial Access Broker React2Shell Zero-Day, APT Active Exploitation WordPress vulnerability, authentication bypass FreePBX, zero-day Trend Micro Apex One, Remote Code Execution BitoPro Hack, Crypto Theft UNC5337 - CVE-2022-47945 Safe{Wallet} hack Fortinet vulnerability, CVE-2024-21762, FortiGate attack Balloonfly, Play ransomware Ivanti EPMM CVE-2025-4427 and CVE-2025-4428
  • Cyber Security
  • Malware
  • Vulnerability

Zero-Day Alert: UNC5337 Exploits Ivanti VPN Vulnerability CVE-2025-0282 for Espionage Operations

Do Son January 8, 2025 0
Read More Read more about Zero-Day Alert: UNC5337 Exploits Ivanti VPN Vulnerability CVE-2025-0282 for Espionage Operations
macOS Vulnerability CVE-2024-54527 Unveiled: TCC Bypass PoC Exploit Code Released Apple Zero-Day CVE-2025-43529 WebKit Zero-Day, Targeted iOS Spyware Apple spyware alerts, zero-click attacks Apple, trademark lawsuit CVE-2024-54527 PoC exploit Apple, App Store
  • Vulnerability

macOS Vulnerability CVE-2024-54527 Unveiled: TCC Bypass PoC Exploit Code Released

Do Son January 8, 2025 0
Read More Read more about macOS Vulnerability CVE-2024-54527 Unveiled: TCC Bypass PoC Exploit Code Released
Mutiple Vulnerabilities Found in Palo Alto Networks Expedition Tool CVE-2024-5921 - CVE-2025-0103 CVE-2025-0110 PoC
  • Vulnerability

Mutiple Vulnerabilities Found in Palo Alto Networks Expedition Tool

Do Son January 8, 2025 0
Read More Read more about Mutiple Vulnerabilities Found in Palo Alto Networks Expedition Tool
GitLab Tackles Critical Security Flaws in Latest Patch Release GitLab security CVE-2025-25291 and CVE-2025-25292
  • Vulnerability

GitLab Tackles Critical Security Flaws in Latest Patch Release

Do Son January 8, 2025 0
Read More Read more about GitLab Tackles Critical Security Flaws in Latest Patch Release
Apache OpenMeetings Users Urged to Patch Critical Flaw – CVE-2024-54676 (CVSS 9.8) CVE-2024-54676
  • Vulnerability

Apache OpenMeetings Users Urged to Patch Critical Flaw – CVE-2024-54676 (CVSS 9.8)

Do Son January 8, 2025 0
Read More Read more about Apache OpenMeetings Users Urged to Patch Critical Flaw – CVE-2024-54676 (CVSS 9.8)
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intel📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-94127CVSS 9.8
    When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-85102CVSS 9.8
    Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93616CVSS 9.8
    A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-93399CVSS 9.1
    The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including,...
    📅 Updated: Sep 25, 2026
  • CVE-2026-89055CVSS 9.1
    The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to,...
    📅 Updated: Sep 25, 2026
  • CVE-2026-14281CVSS 9.8
    The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable...
    📅 Updated: Sep 25, 2026
  • CVE-2026-97413CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Fix integer underflow in process_read and process_write...
    📅 Updated: Sep 25, 2026
  • CVE-2026-93228CVSS 9.1
    In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject Write/Reply chunks with segcount 0 A...
    📅 Updated: Sep 25, 2026
  • CVE-2026-93207CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry svcauth_gss_decode_credbody() writes...
    📅 Updated: Sep 25, 2026
  • CVE-2026-93577CVSS 9.9
    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3,...
    📅 Updated: Sep 25, 2026
  • CVE-2026-89078CVSS 9.9
    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3,...
    📅 Updated: Sep 25, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.