Skip to content
October 7, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
SonicWall Issues Important Security Advisory for Multiple Vulnerabilities in SonicOS SonicWall SMA 1000 MFA Bypass SonicWall SSLVPN Flaw CVE-2025-40601 SonicOS vulnerability - CVE-2024-53704
  • Vulnerability

SonicWall Issues Important Security Advisory for Multiple Vulnerabilities in SonicOS

Do Son January 7, 2025 0
Read More Read more about SonicWall Issues Important Security Advisory for Multiple Vulnerabilities in SonicOS
CISA Alerts on Actively Exploited Vulnerabilities in Mitel MiCollab and Oracle WebLogic Server n8n RCE Vulnerability CVE-2025-68613 CISA KEV WinRAR Zero-Day, Cloud Files UAF OpenPLC ScadaBR, CVE-2021-26829 CISA KEV, Gladinet LFI RCE XWiki RCE, VMware EoP CISA KEV CISA, Known Exploited Vulnerabilities CVE-2020-2883 CISA, Trend Micro
  • Vulnerability

CISA Alerts on Actively Exploited Vulnerabilities in Mitel MiCollab and Oracle WebLogic Server

Do Son January 7, 2025 0
Read More Read more about CISA Alerts on Actively Exploited Vulnerabilities in Mitel MiCollab and Oracle WebLogic Server
Trio of Critical Vulnerabilities in Netis Routers Enables Unauthenticated RCE CVE-2024-48455, CVE-2024-48456, and CVE-2024-48457
  • Vulnerability

Trio of Critical Vulnerabilities in Netis Routers Enables Unauthenticated RCE

Do Son January 7, 2025 0
Read More Read more about Trio of Critical Vulnerabilities in Netis Routers Enables Unauthenticated RCE
Chrome Update Addresses High-Severity Vulnerability: CVE-2025-0291 CVE-2025-0291
  • Vulnerability

Chrome Update Addresses High-Severity Vulnerability: CVE-2025-0291

Do Son January 7, 2025 0
Read More Read more about Chrome Update Addresses High-Severity Vulnerability: CVE-2025-0291
Authentication Bypass Vulnerability Found in Dell OpenManage Server Administrator Dell ECS Security Update CVE-2026-40636 Hard-coded Credentials Dell Business Price Increase, RAM and SSD Shortage 2025 Dell Data Lakehouse, Critical Privilege Escalation Authentication Bypass Vulnerability CVE-2025-22398
  • Vulnerability

Authentication Bypass Vulnerability Found in Dell OpenManage Server Administrator

Do Son January 7, 2025 0
Read More Read more about Authentication Bypass Vulnerability Found in Dell OpenManage Server Administrator
Secure Your Repos: go-git Patches Critical Vulnerability – CVE-2025-21613 (CVSS 9.8) CVE-2025-21613 & CVE-2025-21614
  • Vulnerability

Secure Your Repos: go-git Patches Critical Vulnerability – CVE-2025-21613 (CVSS 9.8)

Do Son January 7, 2025 0
Read More Read more about Secure Your Repos: go-git Patches Critical Vulnerability – CVE-2025-21613 (CVSS 9.8)
CVE-2024-51741 and CVE-2024-46981: Redis Flaws Expose Millions to DoS and RCE Risks Redis RCE, HyperLogLog Vulnerability CVE-2024-51741 - CVE-2024-46981
  • Vulnerability

CVE-2024-51741 and CVE-2024-46981: Redis Flaws Expose Millions to DoS and RCE Risks

Do Son January 6, 2025 0
Read More Read more about CVE-2024-51741 and CVE-2024-46981: Redis Flaws Expose Millions to DoS and RCE Risks
CVE-2024-43096 and More: Critical RCE Flaws Patched in Android Security Update Android Zero-Click RCE CVE-2026-0073 Android sideloading CVE-2024-43096, CVE-2024-43770, CVE-2024-43771, CVE-2024-49747 and, CVE-2024-49748
  • Android
  • Vulnerability

CVE-2024-43096 and More: Critical RCE Flaws Patched in Android Security Update

Do Son January 6, 2025 0
Read More Read more about CVE-2024-43096 and More: Critical RCE Flaws Patched in Android Security Update
CVE-2024-20154: Critical RCE Flaw in MediaTek Chipsets Impacts Millions MediaTek Modem Vulnerabilities, January 2026 Security Bulletin MediaTek Vulnerabilities, Chipset Security CVE-2024-20103 & CVE-2024-20100 - CVE-2024-20154 - February 2025 Product Security Bulletin
  • Vulnerability

CVE-2024-20154: Critical RCE Flaw in MediaTek Chipsets Impacts Millions

Do Son January 6, 2025 0
Read More Read more about CVE-2024-20154: Critical RCE Flaw in MediaTek Chipsets Impacts Millions
Thousands of SonicWall Devices Remain Vulnerable to CVE-2024-40766 PyPI Packages Leak
  • Malware
  • Vulnerability

Thousands of SonicWall Devices Remain Vulnerable to CVE-2024-40766

Do Son January 6, 2025 0
Read More Read more about Thousands of SonicWall Devices Remain Vulnerable to CVE-2024-40766
Exploiting Misconfigurations in Argo Workflows for Kubernetes Cluster Takeover Argo CD Secret Leak CVE-2026-42880 CVE-2024-28175 Argo CD DoS, Webhook Flaws
  • Vulnerability

Exploiting Misconfigurations in Argo Workflows for Kubernetes Cluster Takeover

Do Son January 6, 2025 0
Read More Read more about Exploiting Misconfigurations in Argo Workflows for Kubernetes Cluster Takeover
CVE-2024-8474: OpenVPN Connect Vulnerability Leaks Private Keys CVE-2023-46850 - CVE-2024-8474
  • Vulnerability Report

CVE-2024-8474: OpenVPN Connect Vulnerability Leaks Private Keys

Do Son January 6, 2025 0
Read More Read more about CVE-2024-8474: OpenVPN Connect Vulnerability Leaks Private Keys
Vulnerability Overload: 40,000+ CVEs in 2024 CVE 2024
  • Vulnerability

Vulnerability Overload: 40,000+ CVEs in 2024

Do Son January 6, 2025 0
Read More Read more about Vulnerability Overload: 40,000+ CVEs in 2024
Beware of PhishWP: New WordPress Plugin Targets Online Shoppers WordPress Backdoor
  • Cyber Security

Beware of PhishWP: New WordPress Plugin Targets Online Shoppers

Do Son January 6, 2025 0
Read More Read more about Beware of PhishWP: New WordPress Plugin Targets Online Shoppers
EAGERBEE: Advanced Backdoor Targets Middle Eastern ISPs and Government Entities EAGERBEE backdoor
  • Cyber Security
  • Malware

EAGERBEE: Advanced Backdoor Targets Middle Eastern ISPs and Government Entities

Do Son January 6, 2025 0
Read More Read more about EAGERBEE: Advanced Backdoor Targets Middle Eastern ISPs and Government Entities
Windows 11’s TPM 2.0: Free Software Foundation Fights Forced Upgrades and E-Waste Windows 11's TPM 2.0
  • Technology
  • Windows

Windows 11’s TPM 2.0: Free Software Foundation Fights Forced Upgrades and E-Waste

Do Son January 6, 2025 0
Read More Read more about Windows 11’s TPM 2.0: Free Software Foundation Fights Forced Upgrades and E-Waste
CVE-2024-43452: PoC Exploit Released for Windows Elevation of Privilege Bug CVE-2024-43452 PoC exploit
  • Vulnerability
  • Windows

CVE-2024-43452: PoC Exploit Released for Windows Elevation of Privilege Bug

Do Son January 5, 2025 0
Read More Read more about CVE-2024-43452: PoC Exploit Released for Windows Elevation of Privilege Bug
CVE-2024-9138 and CVE-2024-9140 (CVSS 9.8): Moxa Calls for Immediate Security Action Moxa Linux kernel vulnerabilities Moxa Vulnerability CVE-2024-12297 Moxa OpenSSH Vulnerability CVE-2023-38408 CVE-2023-5961 - CVE-2024-9138 and CVE-2024-9140
  • Vulnerability

CVE-2024-9138 and CVE-2024-9140 (CVSS 9.8): Moxa Calls for Immediate Security Action

Do Son January 5, 2025 0
Read More Read more about CVE-2024-9138 and CVE-2024-9140 (CVSS 9.8): Moxa Calls for Immediate Security Action
NonEuclid RAT—A Sophisticated Tool in the Cybercrime Arsenal Mercenary Akula European Financial Targeting AI-Generated Malware React2Shell Exploit UAT-8837 Critical Infrastructure Attack APT36, BOSS Linux BRICKSTORM Malware, China Espionage Curly COMrades, MucorAgent Chinese APT - HTTP Client Tools Shuckworm Cyber Espionage
  • Malware

NonEuclid RAT—A Sophisticated Tool in the Cybercrime Arsenal

Do Son January 5, 2025 0
Read More Read more about NonEuclid RAT—A Sophisticated Tool in the Cybercrime Arsenal
CryptBot Infostealer Returns with Sophisticated Tactics for Initial Access PHP RCE vulnerability
  • Malware

CryptBot Infostealer Returns with Sophisticated Tactics for Initial Access

Do Son January 5, 2025 0
Read More Read more about CryptBot Infostealer Returns with Sophisticated Tactics for Initial Access
GoCD Patches Critical Vulnerability Allowing User Privilege Escalation GoCD vulnerability
  • Vulnerability

GoCD Patches Critical Vulnerability Allowing User Privilege Escalation

Do Son January 5, 2025 0
Read More Read more about GoCD Patches Critical Vulnerability Allowing User Privilege Escalation
Malicious Packages Weaponize OAST for Stealthy Data Exfiltration and Reconnaissance GuLoader Malware CloudEye Obfuscation npm, malware Ethereum, npm supply chain OAST techniques StilachiRAT macOS Malware PasivRobber
  • Cyber Security
  • Malware

Malicious Packages Weaponize OAST for Stealthy Data Exfiltration and Reconnaissance

Do Son January 5, 2025 0
Read More Read more about Malicious Packages Weaponize OAST for Stealthy Data Exfiltration and Reconnaissance
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-93836CVSS 7.2
    The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \'qty\'...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-21589CVSS 9.3
    This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-76268CVSS 9.8
    In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user with network access to the Patroni Representational...
    📅 Updated: Oct 7, 2026
  • CVE-2026-82533CVSS 9.6
    DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability in its local HTTP control-plane API that allows attackers...
    📅 Updated: Oct 7, 2026
  • CVE-2026-63992CVSS 9.1
    In the Linux kernel, the following vulnerability has been resolved: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp()...
    📅 Updated: Oct 7, 2026
  • CVE-2026-92414CVSS 9.3
    : Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit. Jackrabbit WebDAV server attaches a cached...
    📅 Updated: Oct 7, 2026
  • CVE-2026-63994CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]()...
    📅 Updated: Oct 7, 2026
  • CVE-2026-102268CVSS 9.1
    PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/utils.py is affected...
    📅 Updated: Oct 7, 2026
  • CVE-2026-76751CVSS 9.8
    A missing integrity verification vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitation could allow...
    📅 Updated: Oct 7, 2026
  • CVE-2026-76752CVSS 9.8
    Authentication bypass vulnerabilities exist in the web-based management and API interfaces of HPE Networking ClearPass Policy Manager. Successful...
    📅 Updated: Oct 7, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.