Skip to content
October 7, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
15,000 FortiGate Firewalls Exposed: Massive Leak Includes VPN Credentials LY Corporation Data Breach
  • Data Leak

15,000 FortiGate Firewalls Exposed: Massive Leak Includes VPN Credentials

Do Son January 15, 2025 0
Read More Read more about 15,000 FortiGate Firewalls Exposed: Massive Leak Includes VPN Credentials
Microsoft Patches Outlook Zero-Click: CVE-2025-21298 Exploits RCE via Emails Smart App Control blocking Armoury Crate, ROG Ally Defender false positive 2026 Microsoft Zero-Day, Cloud Files UAF Microsoft Access end of life CVE-2025-21298 Azure Vulnerabilities
  • Vulnerability

Microsoft Patches Outlook Zero-Click: CVE-2025-21298 Exploits RCE via Emails

Do Son January 15, 2025 0
Read More Read more about Microsoft Patches Outlook Zero-Click: CVE-2025-21298 Exploits RCE via Emails
ECOVACS Patches Critical WiFi RCE Vulnerability CVE-2024-42911 in Deebot Robot Vacuums CVE-2024-42911
  • Vulnerability

ECOVACS Patches Critical WiFi RCE Vulnerability CVE-2024-42911 in Deebot Robot Vacuums

Do Son January 15, 2025 0
Read More Read more about ECOVACS Patches Critical WiFi RCE Vulnerability CVE-2024-42911 in Deebot Robot Vacuums
Critical Vulnerability in Rasa Framework Enables Remote Code Execution (CVE-2024-49375) CVE-2024-49375
  • Vulnerability

Critical Vulnerability in Rasa Framework Enables Remote Code Execution (CVE-2024-49375)

Do Son January 15, 2025 0
Read More Read more about Critical Vulnerability in Rasa Framework Enables Remote Code Execution (CVE-2024-49375)
Why MFA is Critical for Securing Cloud-Native SaaS in Enterprise Environments Privacy
  • Technique

Why MFA is Critical for Securing Cloud-Native SaaS in Enterprise Environments

Do Son January 15, 2025 0
Read More Read more about Why MFA is Critical for Securing Cloud-Native SaaS in Enterprise Environments
CVE-2025-23042 (CVSS 9.1): Gradio Patches Critical ACL Bypass Flaw in Popular Machine Learning Platform CVE-2025-23042
  • Vulnerability

CVE-2025-23042 (CVSS 9.1): Gradio Patches Critical ACL Bypass Flaw in Popular Machine Learning Platform

Do Son January 15, 2025 0
Read More Read more about CVE-2025-23042 (CVSS 9.1): Gradio Patches Critical ACL Bypass Flaw in Popular Machine Learning Platform
CVE-2024-9042: Code Execution Vulnerability Found in Kubernetes Windows Nodes CVE-2024-9042 ingress-nginx Vulnerability CVE-2026-4342
  • Vulnerability

CVE-2024-9042: Code Execution Vulnerability Found in Kubernetes Windows Nodes

Do Son January 15, 2025 0
Read More Read more about CVE-2024-9042: Code Execution Vulnerability Found in Kubernetes Windows Nodes
CVE-2024-7344: Howyar Reloader Vulnerability Exposes UEFI Systems to Unsigned Software Threats CVE-2024-7344
  • Vulnerability

CVE-2024-7344: Howyar Reloader Vulnerability Exposes UEFI Systems to Unsigned Software Threats

Do Son January 15, 2025 0
Read More Read more about CVE-2024-7344: Howyar Reloader Vulnerability Exposes UEFI Systems to Unsigned Software Threats
13,000 MikroTik Routers Hijacked for Global Malspam Operation CloudComputating - QSC framework
  • Vulnerability

13,000 MikroTik Routers Hijacked for Global Malspam Operation

Do Son January 15, 2025 0
Read More Read more about 13,000 MikroTik Routers Hijacked for Global Malspam Operation
CVE-2025-20055 (CVSS 9.8): Critical Vulnerability Threatens STEALTHONE Storage CVE-2025-20055
  • Vulnerability

CVE-2025-20055 (CVSS 9.8): Critical Vulnerability Threatens STEALTHONE Storage

Do Son January 15, 2025 0
Read More Read more about CVE-2025-20055 (CVSS 9.8): Critical Vulnerability Threatens STEALTHONE Storage
CVE-2024-12365: Popular WordPress Caching Plugin Exposes Millions of Sites to Attack CVE-2024-12365
  • Vulnerability

CVE-2024-12365: Popular WordPress Caching Plugin Exposes Millions of Sites to Attack

Do Son January 15, 2025 0
Read More Read more about CVE-2024-12365: Popular WordPress Caching Plugin Exposes Millions of Sites to Attack
Unveiling Zero-Day Behavior in PDF Samples: The Risk of NTLM Information Leaks NTLM Information Leaks
  • Vulnerability

Unveiling Zero-Day Behavior in PDF Samples: The Risk of NTLM Information Leaks

Do Son January 15, 2025 0
Read More Read more about Unveiling Zero-Day Behavior in PDF Samples: The Risk of NTLM Information Leaks
Veeam Releases Patch for High-Risk SSRF Vulnerability CVE-2025-23082 in Azure Backup Solution CVE-2024-29212 - CVE-2025-23082 Veeam Backup & Replication CVE-2025-59470
  • Vulnerability

Veeam Releases Patch for High-Risk SSRF Vulnerability CVE-2025-23082 in Azure Backup Solution

Do Son January 15, 2025 0
Read More Read more about Veeam Releases Patch for High-Risk SSRF Vulnerability CVE-2025-23082 in Azure Backup Solution
CVE-2023-37936 (CVSS 9.6): Urgent Patch Needed for FortiSwitch Vulnerability FortiSandbox Vulnerability Unauthenticated RCE FortiClient EMS Vulnerability CVE-2026-21643 FortiClient EMS Vulnerability CVE-2026-21643 CVE-2023-34992 - CVE-2023-37936 Fortinet Vulnerabilities CVE-2025-64155
  • Vulnerability

CVE-2023-37936 (CVSS 9.6): Urgent Patch Needed for FortiSwitch Vulnerability

Do Son January 15, 2025 0
Read More Read more about CVE-2023-37936 (CVSS 9.6): Urgent Patch Needed for FortiSwitch Vulnerability
Millions Stolen: North Korea Hackers Target Blockchain Industry Google Play, Crypto Wallets Cryptocurrency Thefts
  • Cyber Security

Millions Stolen: North Korea Hackers Target Blockchain Industry

Do Son January 14, 2025 0
Read More Read more about Millions Stolen: North Korea Hackers Target Blockchain Industry
CVE-2024-12084 (CVSS 9.8) – Code Execution Risk: Rsync Vulnerability Demands Immediate Patching CVE-2024-12084
  • Vulnerability

CVE-2024-12084 (CVSS 9.8) – Code Execution Risk: Rsync Vulnerability Demands Immediate Patching

Do Son January 14, 2025 0
Read More Read more about CVE-2024-12084 (CVSS 9.8) – Code Execution Risk: Rsync Vulnerability Demands Immediate Patching
“PlugX” Malware Deleted from Thousands of Computers in Global Operation Seedworm Espionage Campaign 2026 ChromElevator Stealer DLL Sideloading SIM Swapping Crypto Theft Lazarus Comebacker, Aerospace Espionage Delete PlugX Malware
  • Malware
  • Vulnerability

“PlugX” Malware Deleted from Thousands of Computers in Global Operation

Do Son January 14, 2025 0
Read More Read more about “PlugX” Malware Deleted from Thousands of Computers in Global Operation
Ivanti Endpoint Manager Patches Critical Security Vulnerabilities CVE-2023-38036 - CVE-2024-10811
  • Vulnerability

Ivanti Endpoint Manager Patches Critical Security Vulnerabilities

Do Son January 14, 2025 0
Read More Read more about Ivanti Endpoint Manager Patches Critical Security Vulnerabilities
CVE-2025-0147: Zoom Fixes High-Severity Security Flaw CVE-2025-0147
  • Vulnerability

CVE-2025-0147: Zoom Fixes High-Severity Security Flaw

Do Son January 14, 2025 0
Read More Read more about CVE-2025-0147: Zoom Fixes High-Severity Security Flaw
Malicious npm Packages Exploit Developer Tools with Hidden Kill Switch Kill Switch
  • Malware

Malicious npm Packages Exploit Developer Tools with Hidden Kill Switch

Do Son January 14, 2025 0
Read More Read more about Malicious npm Packages Exploit Developer Tools with Hidden Kill Switch
Fortinet FortiGate Firewalls Targeted in Sophisticated Campaign Exploiting Management Interfaces Weaver E-cology RCE CVE-2026-22679 CVE-2026-20127 Cisco SD-WAN Exploitation AI-Driven Cyberattack ARXON Malware React Server Components Vulnerability CVE-2025-55182 FortiWeb Auth Bypass, Unauthenticated Admin Takeover RayInitiator Bootkit, LINE VIPER CVE-2025-59689 Department of the Treasury cybersecurity - CVE-2025-0108 PoC CVE-2025-31103 Dior Data Breach SK Telecom data breach, long-term intrusion
  • Cyber Security
  • Vulnerability

Fortinet FortiGate Firewalls Targeted in Sophisticated Campaign Exploiting Management Interfaces

Do Son January 14, 2025 0
Read More Read more about Fortinet FortiGate Firewalls Targeted in Sophisticated Campaign Exploiting Management Interfaces
Over 5,000 WordPress Sites Infected in WP3.XYZ Malware Attack WP3.XYZ Malware Attack
  • Malware

Over 5,000 WordPress Sites Infected in WP3.XYZ Malware Attack

Do Son January 14, 2025 0
Read More Read more about Over 5,000 WordPress Sites Infected in WP3.XYZ Malware Attack
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
πŸ“ˆ

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

πŸ›‘οΈ

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

πŸ™

GitHub Issues
Auto-create alert tickets without duplication.

πŸ“¬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

πŸ”€

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days β†’

🚨 Active Exploits in the Wild

  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-93836CVSS 7.2
    The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \'qty\'...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-21589CVSS 9.3
    This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-105324CVSS 9.2
    An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an unauthenticated remote attacker to read arbitrary files...
    📅 Updated: Oct 7, 2026
  • CVE-2026-79796CVSS 9.8
    Vulnerabilities have been identified in the affected interface of ClearPass Policy Manager that could potentially allow an unauthenticated...
    📅 Updated: Oct 7, 2026
  • CVE-2026-76464CVSS 9.6
    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has...
    📅 Updated: Oct 7, 2026
  • CVE-2026-51862CVSS 9.1
    DB-GPT 0.8.0 contains directory traversal in skill_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:40). A remote attacker can use the validated exploitation path to...
    📅 Updated: Oct 7, 2026
  • CVE-2026-51869CVSS 9.8
    DB-GPT v0.8.0 sandbox API silently falls back to LocalRuntime and executes code on host.
    📅 Updated: Oct 7, 2026
  • CVE-2026-76501CVSS 9.8
    A vulnerability in the Segment Routing over IPv6 (SRv6) Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS...
    📅 Updated: Oct 7, 2026
  • CVE-2026-76500CVSS 9.8
    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller...
    📅 Updated: Oct 7, 2026
  • CVE-2026-102255CVSS 10.0
    A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access...
    📅 Updated: Oct 7, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
Β© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.