Skip to content
October 7, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
CVE-2025-23006 (CVSS 9.8): SonicWall Warns of Active Exploits, Issues Urgent Update for SMA1000 Users SonicWall Security Advisory SonicOS Patch 2026 CVE-2025-23006 SonicWall, SMA 100 Vulnerabilities
  • Vulnerability

CVE-2025-23006 (CVSS 9.8): SonicWall Warns of Active Exploits, Issues Urgent Update for SMA1000 Users

Do Son January 23, 2025 0
Read More Read more about CVE-2025-23006 (CVSS 9.8): SonicWall Warns of Active Exploits, Issues Urgent Update for SMA1000 Users
CVE-2025-0314: GitLab Releases Patch for XSS Exploit GitLab AI Gateway Vulnerability CVE-2026-1868 CVE-2025-0314 GitLab Security Update CVE-2025-9222
  • Vulnerability

CVE-2025-0314: GitLab Releases Patch for XSS Exploit

Do Son January 23, 2025 0
Read More Read more about CVE-2025-0314: GitLab Releases Patch for XSS Exploit
CISA and FBI Warn of Exploited Ivanti CSA Vulnerabilities in Joint Security Advisory OCRFix Botnet EtherHiding CrowdStrike supply chain attack Ivanti CSA Vulnerabilities
  • Vulnerability

CISA and FBI Warn of Exploited Ivanti CSA Vulnerabilities in Joint Security Advisory

Do Son January 22, 2025 0
Read More Read more about CISA and FBI Warn of Exploited Ivanti CSA Vulnerabilities in Joint Security Advisory
CVE-2025-20156 (CVSS 9.9): Cisco Meeting Management Flaw Allows for Privilege Escalation CVE-2025-20156
  • Vulnerability

CVE-2025-20156 (CVSS 9.9): Cisco Meeting Management Flaw Allows for Privilege Escalation

Do Son January 22, 2025 0
Read More Read more about CVE-2025-20156 (CVSS 9.9): Cisco Meeting Management Flaw Allows for Privilege Escalation
Purrglar: Emerging Stealer Targets Chrome and Exodus Wallet Data on macOS shell-quote command injection AI-Driven Vulnerabilities Q1 2026 Cyber Threats vm2 Sandbox Escape Node.js RCE upKeeper Privilege Escalation CVE-2026-2449 Pharos Controls Vulnerability Root Access Exploit Cybersecurity Vulnerability Roundup CVSS 10.0 Flaws Shadow Archives CVE-2026-0866 MS-Agent Prompt Injection CVE-2026-2256 basic-ftp Path Traversal CVE-2026-27699 telnetd Root Vulnerability CVE-1999-0073 Regression USR-W610 Vulnerabilities End-of-Life IoT Security IceWarp Security Update IceWarp Vulnerabilities Airleader Master Vulnerability CVE-2026-1358 ZLAN5143D Vulnerability CISA ICS Advisory Acronis Cyber Protect Vulnerability CVE-2025-30411 WAGO 852 Vulnerability OT Network Security SandboxJS Vulnerability Sandbox Escape (CVSS 10.0) Kubernetes Local Path Provisioner CVE-2025-62878 CISA Unresponsive Vendors Avation & RISS Vulnerabilities KiloView Vulnerability CVE-2026-1453 OpenClaw RCE vulnerability Johnson Controls Vulnerability CVE-2025-26385 SandboxJS Vulnerability CVE-2026-23830 ibaPDA Vulnerability CVE-2025-14988 Protobuf Vulnerability CVE-2026-0994 AVEVA Process Optimization Vulnerability CVE-2025-61937 ConnectWise PSA Vulnerability CVE-2026-0695 Aruba VIA Vulnerability CVE-2025-37186 aiohttp v3.13.3, Denial of Service (DoS) SmarterMail RCE, CVE-2025-52691 Airoha RACE, Headphone Jacking HPE OneView RCE CVE-2025-37164 FreePBX Auth Bypass, PBX Takeover ScreenConnect Config Flaw, Untrusted Extensions Ruby SAML Auth Bypass, XML Parser Differential Devolutions SQL Injection, Password Manager Flaw Vivotek Unauthenticated RCE, EOL IP Camera Flaw Lynx+ Critical Flaw, Unauthenticated Reset Firebox Default Credentials, CVE-2025-59396 Veeder-Root RCE, Critical ATG Flaw ArcGIS Server SQLi Watchdoc RCE, CVE-2025-58384 Delta DIALink Daikin Security Gateway, authentication bypass Frostbyte10, industrial controller security SunPower, vulnerability Ubiquiti UniFi Connect, EV Station Vulnerabilities Adobe Experience Manager, RCE Vulnerability UniFi Access, Command Injection LDAPNightmare - CVE-2025-1316
  • Malware

Purrglar: Emerging Stealer Targets Chrome and Exodus Wallet Data on macOS

Do Son January 22, 2025 0
Read More Read more about Purrglar: Emerging Stealer Targets Chrome and Exodus Wallet Data on macOS
Signal and Discord Vulnerabilities Exposed: 0-Click Deanonymization Attack Revealed deanonymization attack - cache geolocation attack
  • Data Leak
  • Vulnerability

Signal and Discord Vulnerabilities Exposed: 0-Click Deanonymization Attack Revealed

Do Son January 22, 2025 0
Read More Read more about Signal and Discord Vulnerabilities Exposed: 0-Click Deanonymization Attack Revealed
ApateWeb Campaign Hijacks Blogspot, Spreads Phishing and Malware ApateWeb operation
  • Cyber Security

ApateWeb Campaign Hijacks Blogspot, Spreads Phishing and Malware

Do Son January 22, 2025 0
Read More Read more about ApateWeb Campaign Hijacks Blogspot, Spreads Phishing and Malware
Mercedes-Benz MBUX Vulnerabilities: User Data and Safety at Risk mercedes-benz-2692776_1280
  • Vulnerability

Mercedes-Benz MBUX Vulnerabilities: User Data and Safety at Risk

Do Son January 22, 2025 0
Read More Read more about Mercedes-Benz MBUX Vulnerabilities: User Data and Safety at Risk
New Bruteforce Campaign Exploits fasthttp Library to Target Azure Environments Azure Bruteforce Campaign
  • Cyber Security

New Bruteforce Campaign Exploits fasthttp Library to Target Azure Environments

Do Son January 22, 2025 0
Read More Read more about New Bruteforce Campaign Exploits fasthttp Library to Target Azure Environments
Proof-of-Concept Found for ClamAV DoS Flaw: CVE-2025-20128 New_ClamAV_Logo.svg
  • Vulnerability

Proof-of-Concept Found for ClamAV DoS Flaw: CVE-2025-20128

Do Son January 22, 2025 0
Read More Read more about Proof-of-Concept Found for ClamAV DoS Flaw: CVE-2025-20128
GamaCopy: A New Cyber Espionage Group Imitating Gamaredon to Target Russia Mercenary Akula European Financial Targeting AI-Generated Malware React2Shell Exploit UAT-8837 Critical Infrastructure Attack APT36, BOSS Linux BRICKSTORM Malware, China Espionage Curly COMrades, MucorAgent Chinese APT - HTTP Client Tools Shuckworm Cyber Espionage
  • Cyber Security

GamaCopy: A New Cyber Espionage Group Imitating Gamaredon to Target Russia

Do Son January 22, 2025 0
Read More Read more about GamaCopy: A New Cyber Espionage Group Imitating Gamaredon to Target Russia
Security Update for Chrome: Protect Against CVE-2025-0611 and CVE-2025-0612 CVE-2025-0611 and CVE-2025-0612
  • Vulnerability

Security Update for Chrome: Protect Against CVE-2025-0611 and CVE-2025-0612

Do Son January 22, 2025 0
Read More Read more about Security Update for Chrome: Protect Against CVE-2025-0611 and CVE-2025-0612
Operation (Giα»— Tα»• HΓΉng VΖ°Ζ‘ng) Hurricane: New OceanLotus Group Revealed in Espionage Campaigns CVE-2024-36072 Water Gamayun, MSC EvilTwin
  • Cyber Security

Operation (Giα»— Tα»• HΓΉng VΖ°Ζ‘ng) Hurricane: New OceanLotus Group Revealed in Espionage Campaigns

Do Son January 22, 2025 0
Read More Read more about Operation (Giα»— Tα»• HΓΉng VΖ°Ζ‘ng) Hurricane: New OceanLotus Group Revealed in Espionage Campaigns
Cybercriminals Exploit AnyDesk to Impersonate CERT-UA in Sophisticated Phishing Campaign BlueNoroff macOS Attack GhostCall Campaign Carding Underground Bulletproof Hosting DPRK Contagious Interview, npm Flood Stonefly group -HiatusRAT Actors
  • Cyber Security

Cybercriminals Exploit AnyDesk to Impersonate CERT-UA in Sophisticated Phishing Campaign

Do Son January 22, 2025 0
Read More Read more about Cybercriminals Exploit AnyDesk to Impersonate CERT-UA in Sophisticated Phishing Campaign
Breaking News: Introducing the Stargate Project – OpenAI’s Transformative AI Infrastructure Yoshua Bengio AI sycophancy, reverse deception AI feedback AI chatbots, FTC investigation AI-generated content Trump AI Policy, AI Deregulation Military AI, DoD Funding Stargate Project AI Art Restoration
  • Technology

Breaking News: Introducing the Stargate Project – OpenAI’s Transformative AI Infrastructure

Do Son January 22, 2025 0
Read More Read more about Breaking News: Introducing the Stargate Project – OpenAI’s Transformative AI Infrastructure
Mirai Botnet Unleashes Record-Breaking DDoS Attack, Cloudflare Thwarts Threat MadeYouReset, HTTP/2 vulnerability FSF, AI Scraping Attacks OracleIV botnet
  • Cyber Security

Mirai Botnet Unleashes Record-Breaking DDoS Attack, Cloudflare Thwarts Threat

Do Son January 22, 2025 0
Read More Read more about Mirai Botnet Unleashes Record-Breaking DDoS Attack, Cloudflare Thwarts Threat
ASUS and AdGuard Team Up to Deliver Ad-Free Wi-Fi 7 Experience AdGuard DNS
  • Technology

ASUS and AdGuard Team Up to Deliver Ad-Free Wi-Fi 7 Experience

Do Son January 22, 2025 0
Read More Read more about ASUS and AdGuard Team Up to Deliver Ad-Free Wi-Fi 7 Experience
CVE-2024-12857: Critical Flaw in AdForest Theme Allows Complete Account Takeover, Thousands of Sites at Risk CVE-2024-12857
  • Vulnerability

CVE-2024-12857: Critical Flaw in AdForest Theme Allows Complete Account Takeover, Thousands of Sites at Risk

Do Son January 21, 2025 0
Read More Read more about CVE-2024-12857: Critical Flaw in AdForest Theme Allows Complete Account Takeover, Thousands of Sites at Risk
CVE-2025-23083: Node.js Vulnerability Exposes Sensitive Data and Resources CVE-2025-23083 - Node.js EOL
  • Vulnerability

CVE-2025-23083: Node.js Vulnerability Exposes Sensitive Data and Resources

Do Son January 21, 2025 0
Read More Read more about CVE-2025-23083: Node.js Vulnerability Exposes Sensitive Data and Resources
400,000+ Systems Infected: DigitalPulse Proxyware Returns with New Tricks DigitalPulse Proxyware malware
  • Malware

400,000+ Systems Infected: DigitalPulse Proxyware Returns with New Tricks

Do Son January 21, 2025 0
Read More Read more about 400,000+ Systems Infected: DigitalPulse Proxyware Returns with New Tricks
Critical Apache Ambari Security Vulnerabilities Discovered: What You Need to Know CVE-2025-23195, CVE-2025-23196, and CVE-2024-51941
  • Vulnerability

Critical Apache Ambari Security Vulnerabilities Discovered: What You Need to Know

Do Son January 21, 2025 0
Read More Read more about Critical Apache Ambari Security Vulnerabilities Discovered: What You Need to Know
Zendesk Infrastructure Exploited in Phishing and Pig Butchering Schemes BitoPro Hack, Lazarus Group
  • Cyber Security

Zendesk Infrastructure Exploited in Phishing and Pig Butchering Schemes

Do Son January 21, 2025 0
Read More Read more about Zendesk Infrastructure Exploited in Phishing and Pig Butchering Schemes
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
πŸ“ˆ

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

πŸ›‘οΈ

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

πŸ™

GitHub Issues
Auto-create alert tickets without duplication.

πŸ“¬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

πŸ”€

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days β†’

🚨 Active Exploits in the Wild

  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-93836CVSS 7.2
    The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \'qty\'...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-21589CVSS 9.3
    This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-106446CVSS 9.8
    Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.compile() and Handlebars.precompile()...
    📅 Updated: Oct 7, 2026
  • CVE-2026-106501CVSS 9.6
    Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend...
    📅 Updated: Oct 7, 2026
  • CVE-2026-102115CVSS 9.8
    Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who...
    📅 Updated: Oct 7, 2026
  • CVE-2026-107194CVSS 9.2
    Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading...
    📅 Updated: Oct 7, 2026
  • CVE-2026-106239CVSS 9.6
    Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to...
    📅 Updated: Oct 7, 2026
  • CVE-2026-106241CVSS 9.6
    Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging...
    📅 Updated: Oct 7, 2026
  • CVE-2026-62874CVSS 10.0
    Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.
    📅 Updated: Oct 7, 2026
  • CVE-2026-106372CVSS 9.6
    Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary...
    📅 Updated: Oct 7, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
Β© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.