Skip to content
September 25, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Apache OpenMeetings Users Urged to Patch Critical Flaw – CVE-2024-54676 (CVSS 9.8) CVE-2024-54676
  • Vulnerability

Apache OpenMeetings Users Urged to Patch Critical Flaw – CVE-2024-54676 (CVSS 9.8)

Do Son January 8, 2025 0
Read More Read more about Apache OpenMeetings Users Urged to Patch Critical Flaw – CVE-2024-54676 (CVSS 9.8)
MirrorFace: Unmasking the Chinese Cyber Espionage Group Targeting Japan AccountDumpling Phishing Google AppSheet Abuse AI-Generated Malware PureRAT Campaign RondoDoX Botnet, Next.js React2Shell EchoGather, Paper Werewolf Salt Typhoon, Telecom Espionage BreachForums, Conor Fitzpatrick Ransomware Negotiation, DOJ Investigation MirrorFace group - Earth Kasha Emperor Dragonfly
  • Cyber Security
  • Vulnerability

MirrorFace: Unmasking the Chinese Cyber Espionage Group Targeting Japan

Do Son January 8, 2025 0
Read More Read more about MirrorFace: Unmasking the Chinese Cyber Espionage Group Targeting Japan
CVE-2024-54006 & CVE-2024-54007: Command Injection Flaws in HPE Aruba Devices, PoC Publicly Available CVE-2024-54006 & CVE-2024-54007 Aruba AOS Vulnerabilities CVE-2025-37168
  • Vulnerability

CVE-2024-54006 & CVE-2024-54007: Command Injection Flaws in HPE Aruba Devices, PoC Publicly Available

Do Son January 8, 2025 0
Read More Read more about CVE-2024-54006 & CVE-2024-54007: Command Injection Flaws in HPE Aruba Devices, PoC Publicly Available
CVE-2024-5594 (CVSS 9.1): Critical Vulnerability in OpenVPN Enables Code Execution CVE-2023-7235 - CVE-2024-5594 OpenVPN Buffer Over-read, HMAC Bypass
  • Vulnerability

CVE-2024-5594 (CVSS 9.1): Critical Vulnerability in OpenVPN Enables Code Execution

Do Son January 8, 2025 0
Read More Read more about CVE-2024-5594 (CVSS 9.1): Critical Vulnerability in OpenVPN Enables Code Execution
CVE-2024-46622 (CVSS 9.8): SecureAge Security Suite Patches Critical Privilege Escalation Flaw CVE-2024-46622
  • Vulnerability

CVE-2024-46622 (CVSS 9.8): SecureAge Security Suite Patches Critical Privilege Escalation Flaw

Do Son January 8, 2025 0
Read More Read more about CVE-2024-46622 (CVSS 9.8): SecureAge Security Suite Patches Critical Privilege Escalation Flaw
Fraudsters Exploit Trust with Fake Refund Schemes in the Middle East EU Education Scams, .edu.eu Domain App Store security Refund Schemes - Texas Pharmacist's Fraudulent
  • Cyber Security

Fraudsters Exploit Trust with Fake Refund Schemes in the Middle East

Do Son January 8, 2025 0
Read More Read more about Fraudsters Exploit Trust with Fake Refund Schemes in the Middle East
CVE-2025-0282 (CVSS 9.0): Ivanti Confirms Active Exploitation of Critical Flaw Ivanti EPMM security updates Ivanti ITSM vulnerability authenticated privilege escalation Ivanti Xtraction vulnerability CVE-2026-8043 Ivanti EPM RCE, SQL Injection Ivanti EPM, remote code execution CVE-2024-50330 - CVE-2025-0282 and CVE-2025-0283
  • Vulnerability

CVE-2025-0282 (CVSS 9.0): Ivanti Confirms Active Exploitation of Critical Flaw

Do Son January 8, 2025 0
Read More Read more about CVE-2025-0282 (CVSS 9.0): Ivanti Confirms Active Exploitation of Critical Flaw
DNA Sequencer BIOS Vulnerabilities Pose Significant Supply Chain Risks DNA Sequencer Vulnerabilities
  • Vulnerability

DNA Sequencer BIOS Vulnerabilities Pose Significant Supply Chain Risks

Do Son January 8, 2025 0
Read More Read more about DNA Sequencer BIOS Vulnerabilities Pose Significant Supply Chain Risks
10 Tips to Protect Your Organization’s Most Critical Assets from Cyber Threats Vulnerability Digest Zero-Day Exploits Seedworm APT Dindoor Backdoor RedKitten Campaign AI-Generated Malware WSUS RCE ShadowPad CVE-2025-59287
  • Technique

10 Tips to Protect Your Organization’s Most Critical Assets from Cyber Threats

Do Son January 8, 2025 0
Read More Read more about 10 Tips to Protect Your Organization’s Most Critical Assets from Cyber Threats
Breaking News: 1 Simple Passive Income Idea to Help You Increase Your Wealth in 2025 Docker Swarm Strategic Bitcoin Reserve
  • Technique

Breaking News: 1 Simple Passive Income Idea to Help You Increase Your Wealth in 2025

Do Son January 8, 2025 0
Read More Read more about Breaking News: 1 Simple Passive Income Idea to Help You Increase Your Wealth in 2025
CVE-2024-52875: KerioControl Firewall Flaw Under Active Exploit, Urgent Patching Required WHILL Wheelchair Hijacking, CVE-2025-14346 MAS typosquatting malware, get.activate.win vs get.activated.win OpenShift GitOps RCE, Cluster Takeover Flaw Twonky Server, CVE-2025-13315 AI agents CVE-2024-52875 PoC
  • Vulnerability

CVE-2024-52875: KerioControl Firewall Flaw Under Active Exploit, Urgent Patching Required

Do Son January 7, 2025 0
Read More Read more about CVE-2024-52875: KerioControl Firewall Flaw Under Active Exploit, Urgent Patching Required
Casio Discloses Data Leak Following Ransomware Attack Casio Network Breach - data leak
  • Cyber Security
  • Data Leak

Casio Discloses Data Leak Following Ransomware Attack

Do Son January 7, 2025 0
Read More Read more about Casio Discloses Data Leak Following Ransomware Attack
CVE-2024-50603 (CVSS 10): Critical Command Injection Vulnerability in Aviatrix Controller CVE-2024-50603
  • Vulnerability

CVE-2024-50603 (CVSS 10): Critical Command Injection Vulnerability in Aviatrix Controller

Do Son January 7, 2025 0
Read More Read more about CVE-2024-50603 (CVSS 10): Critical Command Injection Vulnerability in Aviatrix Controller
“Gayfemboy” Botnet Leveraging 0-Day Exploit in Four-Faith Industrial Routers Gayfemboy botnet
  • Malware
  • Vulnerability

“Gayfemboy” Botnet Leveraging 0-Day Exploit in Four-Faith Industrial Routers

Do Son January 7, 2025 0
Read More Read more about “Gayfemboy” Botnet Leveraging 0-Day Exploit in Four-Faith Industrial Routers
SonicWall Issues Important Security Advisory for Multiple Vulnerabilities in SonicOS SonicWall SMA 1000 MFA Bypass SonicWall SSLVPN Flaw CVE-2025-40601 SonicOS vulnerability - CVE-2024-53704
  • Vulnerability

SonicWall Issues Important Security Advisory for Multiple Vulnerabilities in SonicOS

Do Son January 7, 2025 0
Read More Read more about SonicWall Issues Important Security Advisory for Multiple Vulnerabilities in SonicOS
CISA Alerts on Actively Exploited Vulnerabilities in Mitel MiCollab and Oracle WebLogic Server n8n RCE Vulnerability CVE-2025-68613 CISA KEV WinRAR Zero-Day, Cloud Files UAF OpenPLC ScadaBR, CVE-2021-26829 CISA KEV, Gladinet LFI RCE XWiki RCE, VMware EoP CISA KEV CISA, Known Exploited Vulnerabilities CVE-2020-2883 CISA, Trend Micro
  • Vulnerability

CISA Alerts on Actively Exploited Vulnerabilities in Mitel MiCollab and Oracle WebLogic Server

Do Son January 7, 2025 0
Read More Read more about CISA Alerts on Actively Exploited Vulnerabilities in Mitel MiCollab and Oracle WebLogic Server
Trio of Critical Vulnerabilities in Netis Routers Enables Unauthenticated RCE CVE-2024-48455, CVE-2024-48456, and CVE-2024-48457
  • Vulnerability

Trio of Critical Vulnerabilities in Netis Routers Enables Unauthenticated RCE

Do Son January 7, 2025 0
Read More Read more about Trio of Critical Vulnerabilities in Netis Routers Enables Unauthenticated RCE
Chrome Update Addresses High-Severity Vulnerability: CVE-2025-0291 CVE-2025-0291
  • Vulnerability

Chrome Update Addresses High-Severity Vulnerability: CVE-2025-0291

Do Son January 7, 2025 0
Read More Read more about Chrome Update Addresses High-Severity Vulnerability: CVE-2025-0291
Authentication Bypass Vulnerability Found in Dell OpenManage Server Administrator Dell ECS Security Update CVE-2026-40636 Hard-coded Credentials Dell Business Price Increase, RAM and SSD Shortage 2025 Dell Data Lakehouse, Critical Privilege Escalation Authentication Bypass Vulnerability CVE-2025-22398
  • Vulnerability

Authentication Bypass Vulnerability Found in Dell OpenManage Server Administrator

Do Son January 7, 2025 0
Read More Read more about Authentication Bypass Vulnerability Found in Dell OpenManage Server Administrator
Secure Your Repos: go-git Patches Critical Vulnerability – CVE-2025-21613 (CVSS 9.8) CVE-2025-21613 & CVE-2025-21614
  • Vulnerability

Secure Your Repos: go-git Patches Critical Vulnerability – CVE-2025-21613 (CVSS 9.8)

Do Son January 7, 2025 0
Read More Read more about Secure Your Repos: go-git Patches Critical Vulnerability – CVE-2025-21613 (CVSS 9.8)
CVE-2024-51741 and CVE-2024-46981: Redis Flaws Expose Millions to DoS and RCE Risks Redis RCE, HyperLogLog Vulnerability CVE-2024-51741 - CVE-2024-46981
  • Vulnerability

CVE-2024-51741 and CVE-2024-46981: Redis Flaws Expose Millions to DoS and RCE Risks

Do Son January 6, 2025 0
Read More Read more about CVE-2024-51741 and CVE-2024-46981: Redis Flaws Expose Millions to DoS and RCE Risks
CVE-2024-43096 and More: Critical RCE Flaws Patched in Android Security Update Android Zero-Click RCE CVE-2026-0073 Android sideloading CVE-2024-43096, CVE-2024-43770, CVE-2024-43771, CVE-2024-49747 and, CVE-2024-49748
  • Android
  • Vulnerability

CVE-2024-43096 and More: Critical RCE Flaws Patched in Android Security Update

Do Son January 6, 2025 0
Read More Read more about CVE-2024-43096 and More: Critical RCE Flaws Patched in Android Security Update
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intel📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-94127CVSS 9.8
    When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-85102CVSS 9.8
    Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93616CVSS 9.8
    A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-93399CVSS 9.1
    The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including,...
    📅 Updated: Sep 25, 2026
  • CVE-2026-89055CVSS 9.1
    The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to,...
    📅 Updated: Sep 25, 2026
  • CVE-2026-14281CVSS 9.8
    The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable...
    📅 Updated: Sep 25, 2026
  • CVE-2026-97413CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Fix integer underflow in process_read and process_write...
    📅 Updated: Sep 25, 2026
  • CVE-2026-93228CVSS 9.1
    In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject Write/Reply chunks with segcount 0 A...
    📅 Updated: Sep 25, 2026
  • CVE-2026-93207CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry svcauth_gss_decode_credbody() writes...
    📅 Updated: Sep 25, 2026
  • CVE-2026-93577CVSS 9.9
    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3,...
    📅 Updated: Sep 25, 2026
  • CVE-2026-89078CVSS 9.9
    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3,...
    📅 Updated: Sep 25, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.