Skip to content
September 14, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
RedWing Android Malware Rents Out Spyware and Bank Theft on Telegram RedWing Android malware panel sold as malware-as-a-service on Telegram with banking overlays
  • Malware

RedWing Android Malware Rents Out Spyware and Bank Theft on Telegram

Do Son July 15, 2026 0
Read More Read more about RedWing Android Malware Rents Out Spyware and Bank Theft on Telegram
CVE-2026-10577: CVSS 10 Access Control Vulnerability Hits Rockwell Automation 1715 Redundant I/O Modules Rockwell Automation vulnerability CVE-2026-10577 access control flaw in 1715 Redundant I/O
  • Vulnerability Report

CVE-2026-10577: CVSS 10 Access Control Vulnerability Hits Rockwell Automation 1715 Redundant I/O Modules

Do Son July 15, 2026 0
Read More Read more about CVE-2026-10577: CVSS 10 Access Control Vulnerability Hits Rockwell Automation 1715 Redundant I/O Modules
Malicious Go Module Exposes a 222-Repository GitHub Lure Network Malicious Go module exposing GitHub lure network of 222 repositories in Operation Muck and Load
  • Cybercriminals

Malicious Go Module Exposes a 222-Repository GitHub Lure Network

Do Son July 15, 2026 0
Read More Read more about Malicious Go Module Exposes a 222-Repository GitHub Lure Network
GodDamn Ransomware Rebrands Beast and Uses a Malicious Signed Driver to Disable Defenses North Korean hackers behind open-source supply chain attacks on axios, debug, and chalk NPM packages
  • Malware

GodDamn Ransomware Rebrands Beast and Uses a Malicious Signed Driver to Disable Defenses

Do Son July 15, 2026 0
Read More Read more about GodDamn Ransomware Rebrands Beast and Uses a Malicious Signed Driver to Disable Defenses
Notepad++ v8.9.7 Fixes 5 Vulnerabilities, All With Public Details and PoC Exploit Code Notepad++ vulnerabilities public PoC exploit code path traversal CVE-2026-52886
  • Vulnerability Report

Notepad++ v8.9.7 Fixes 5 Vulnerabilities, All With Public Details and PoC Exploit Code

Do Son July 15, 2026 0
Read More Read more about Notepad++ v8.9.7 Fixes 5 Vulnerabilities, All With Public Details and PoC Exploit Code
Chrome 150 Security Update Fixes 15 Flaws, Including Two Critical Use-After-Free Bugs Chrome security update 150 fixing critical use-after-free flaws CVE-2026-15764 and CVE-2026-15765
  • Vulnerability Report

Chrome 150 Security Update Fixes 15 Flaws, Including Two Critical Use-After-Free Bugs

Do Son July 15, 2026 0
Read More Read more about Chrome 150 Security Update Fixes 15 Flaws, Including Two Critical Use-After-Free Bugs
Passkey Phishing Campaign Uses Vishing Calls to Hijack Microsoft Entra Accounts Passkey phishing vishing attack targeting Microsoft Entra passkey enrollment by O-UNC-066
  • Cybercriminals

Passkey Phishing Campaign Uses Vishing Calls to Hijack Microsoft Entra Accounts

Do Son July 15, 2026 0
Read More Read more about Passkey Phishing Campaign Uses Vishing Calls to Hijack Microsoft Entra Accounts
CISA Warns Three SharePoint Server Vulnerabilities Are Exploited in the Wild, Urges Hardening CISA alert on SharePoint vulnerabilities exploited in the wild including CVE-2026-56164
  • Vulnerability Report

CISA Warns Three SharePoint Server Vulnerabilities Are Exploited in the Wild, Urges Hardening

Do Son July 15, 2026 0
Read More Read more about CISA Warns Three SharePoint Server Vulnerabilities Are Exploited in the Wild, Urges Hardening
Node.js Backdoor Hides Its C2 on the TON Blockchain Mercenary Akula European Financial Targeting AI-Generated Malware React2Shell Exploit UAT-8837 Critical Infrastructure Attack APT36, BOSS Linux BRICKSTORM Malware, China Espionage Curly COMrades, MucorAgent Chinese APT - HTTP Client Tools Shuckworm Cyber Espionage
  • Malware

Node.js Backdoor Hides Its C2 on the TON Blockchain

Do Son July 15, 2026 0
Read More Read more about Node.js Backdoor Hides Its C2 on the TON Blockchain
CVE-2026-15409: SonicWall SMA1000 SSRF Vulnerability (CVSS 10.0) Exploited in the Wild SonicWall SMA1000 SSRF vulnerability CVE-2026-15409 and CVE-2026-15410
  • Vulnerability Report

CVE-2026-15409: SonicWall SMA1000 SSRF Vulnerability (CVSS 10.0) Exploited in the Wild

Do Son July 15, 2026 0
Read More Read more about CVE-2026-15409: SonicWall SMA1000 SSRF Vulnerability (CVSS 10.0) Exploited in the Wild
LegacyHive: Exploit Code and Full Details Publicly Disclosed for Unpatched Windows Privilege Escalation Flaw LegacyHive exploit public disclosure Windows privilege escalation flaw by Nightmare-Eclipse
  • Vulnerability Report

LegacyHive: Exploit Code and Full Details Publicly Disclosed for Unpatched Windows Privilege Escalation Flaw

Do Son July 14, 2026 0
Read More Read more about LegacyHive: Exploit Code and Full Details Publicly Disclosed for Unpatched Windows Privilege Escalation Flaw
Microsoft July 2026 Patch Tuesday Fixes 570 Flaws, Two Zero-Days Exploited in the Wild Microsoft July 2026 Patch Tuesday zero-day vulnerabilities CVE-2026-56155 and CVE-2026-56164
  • Vulnerability Report

Microsoft July 2026 Patch Tuesday Fixes 570 Flaws, Two Zero-Days Exploited in the Wild

Do Son July 14, 2026 0
Read More Read more about Microsoft July 2026 Patch Tuesday Fixes 570 Flaws, Two Zero-Days Exploited in the Wild
Tego AI Finds Claude Tag Slack Integration Can Trigger Unauthorized Enterprise Actions watermarked_img_2256307174777406298_1784021571yc2c34V8Fl
  • Press Release

Tego AI Finds Claude Tag Slack Integration Can Trigger Unauthorized Enterprise Actions

cybernewswire July 14, 2026 0
Read More Read more about Tego AI Finds Claude Tag Slack Integration Can Trigger Unauthorized Enterprise Actions
CVE-2026-53481 & CVE-2026-53483: Dell PowerProtect Full Takeover (9.8) Image showing a hacker taking complete control of system using CVE-2026-53483 and Dell vulnerabilities
  • Vulnerability Report

CVE-2026-53481 & CVE-2026-53483: Dell PowerProtect Full Takeover (9.8)

Do Son July 14, 2026 0
Read More Read more about CVE-2026-53481 & CVE-2026-53483: Dell PowerProtect Full Takeover (9.8)
Exploited in the Wild? Debian Webhost Rooted as Public PoCs Land for Bad Epoll (CVE-2026-46242) and IPv6 Frag Escape Bad Epoll CVE-2026-46242 Linux kernel privilege escalation use-after-free public PoC exploit
  • Vulnerability Report

Exploited in the Wild? Debian Webhost Rooted as Public PoCs Land for Bad Epoll (CVE-2026-46242) and IPv6 Frag Escape

Do Son July 14, 2026 0
Read More Read more about Exploited in the Wild? Debian Webhost Rooted as Public PoCs Land for Bad Epoll (CVE-2026-46242) and IPv6 Frag Escape
CVE-2026-56000: Use-After-Free Flaw Hits X.Org Server and Xwayland X.Org Server use-after-free vulnerability CVE-2026-56000 patched in xorg-server 21.1.24
  • Vulnerability Report

CVE-2026-56000: Use-After-Free Flaw Hits X.Org Server and Xwayland

Do Son July 14, 2026 0
Read More Read more about CVE-2026-56000: Use-After-Free Flaw Hits X.Org Server and Xwayland
CVE-2026-59948: PHP Composer Flaw Lets Packages Execute Code Outside the Project Context PHP Composer arbitrary file write vulnerability CVE-2026-59948 patched in version 2.10.2
  • Vulnerability Report

CVE-2026-59948: PHP Composer Flaw Lets Packages Execute Code Outside the Project Context

Do Son July 14, 2026 0
Read More Read more about CVE-2026-59948: PHP Composer Flaw Lets Packages Execute Code Outside the Project Context
Public Exploit and Details Released for Bad Epoll Root Flaw (CVE-2026-46242) Bad Epoll CVE-2026-46242 Linux kernel use-after-free enabling root privilege escalation
  • Vulnerability Report

Public Exploit and Details Released for Bad Epoll Root Flaw (CVE-2026-46242)

Do Son July 14, 2026 0
Read More Read more about Public Exploit and Details Released for Bad Epoll Root Flaw (CVE-2026-46242)
Anthropic API Billing Error Hits Developer for $16M Anthropic API billing error notification, Claude API incorrect charge screenshot
  • Technology

Anthropic API Billing Error Hits Developer for $16M

Do Son July 14, 2026 0
Read More Read more about Anthropic API Billing Error Hits Developer for $16M
VMware Avi Load Balancer Authentication Bypass (CVE-2026-47865, CVSS 9.8) Headlines Seven-Flaw Patch VMware Avi Load Balancer authentication bypass vulnerability CVE-2026-47865 CVSS 9.8 critical patch
  • Vulnerability Report

VMware Avi Load Balancer Authentication Bypass (CVE-2026-47865, CVSS 9.8) Headlines Seven-Flaw Patch

Do Son July 14, 2026 0
Read More Read more about VMware Avi Load Balancer Authentication Bypass (CVE-2026-47865, CVSS 9.8) Headlines Seven-Flaw Patch
Meta Louisiana Data Center: A $50 Billion AI Gamble Meta Louisiana data center facility, Project Hyperion AI infrastructure investment, 5GW computing capacity server farm
  • Technology

Meta Louisiana Data Center: A $50 Billion AI Gamble

Do Son July 14, 2026 0
Read More Read more about Meta Louisiana Data Center: A $50 Billion AI Gamble
Grok Build Repository Upload Scandal: Researcher Confirms Privacy Mode Cannot Stop It Grok Build repository upload controversy, SpaceXAI privacy mode response
  • Data Leak

Grok Build Repository Upload Scandal: Researcher Confirms Privacy Mode Cannot Stop It

Do Son July 14, 2026 0
Read More Read more about Grok Build Repository Upload Scandal: Researcher Confirms Privacy Mode Cannot Stop It
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-51990
    A critical remote code execution vulnerability in Sogou Input Method, one of the most widely used Chinese-language input...
    Admin intel📅 Updated: Sep 12, 2026
  • CVE-2026-85706CVSS 10.0
    GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42016CVSS 8.1
    JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42018CVSS 7.5
    JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-84869CVSS 9.9
    A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote...
    CISA KEV📅 Added to KEV: Sep 11, 2026
  • CVE-2026-20079CVSS 10.0
    A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated,...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2025-25249CVSS 8.1
    A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2026-87491
    Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-12944CVSS 9.6
    IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary...
  • CVE-2026-16338CVSS 9.9
    IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow...
  • CVE-2026-59178CVSS 9.8
    ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management...
  • CVE-2026-90945CVSS 9.8
    Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing...
  • CVE-2026-90942CVSS 9.6
    Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private...
  • CVE-2026-76461CVSS 9.8
    A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco...
  • CVE-2026-76443CVSS 9.8
    As part of Cisco's ongoing commitment to proactive security and product quality,...
  • CVE-2026-76441CVSS 9.8
    As part of Cisco's ongoing commitment to proactive security and product quality,...
  • CVE-2026-76440CVSS 9.8
    As part of Cisco's ongoing commitment to proactive security and product quality,...
  • CVE-2026-20353CVSS 9.8
    As part of Cisco's ongoing commitment to proactive security and product quality,...
Powered by CVE WATCHTOWER

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.