Skip to content
September 27, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
CVE-2024-41779 (CVSS 9.8): IBM Rhapsody Model Manager Vulnerability Puts Systems at Risk CVE-2024-41779 - CVE-2025-0159 IBM HashiCorp Acquisition
  • Vulnerability

CVE-2024-41779 (CVSS 9.8): IBM Rhapsody Model Manager Vulnerability Puts Systems at Risk

Do Son November 26, 2024 0
Read More Read more about CVE-2024-41779 (CVSS 9.8): IBM Rhapsody Model Manager Vulnerability Puts Systems at Risk
Cybersecurity Alert: MUT-8694 Supply Chain Attack Targets npm and PyPI Ecosystems MUT-8694 threat actor
  • Cyber Security
  • Malware

Cybersecurity Alert: MUT-8694 Supply Chain Attack Targets npm and PyPI Ecosystems

Do Son November 26, 2024 0
Read More Read more about Cybersecurity Alert: MUT-8694 Supply Chain Attack Targets npm and PyPI Ecosystems
Keycloak Patches Multiple Vulnerabilities in Latest Update Keycloak vulnerabilities Keycloak Security MFA Bypass
  • Vulnerability

Keycloak Patches Multiple Vulnerabilities in Latest Update

Do Son November 26, 2024 0
Read More Read more about Keycloak Patches Multiple Vulnerabilities in Latest Update
Kansas City Man Indicted for Hacking into Nonprofit and Health Club NATS-as-C2 Sysdig CVE-2026-33017 Langflow RCE Microsoft Phone Link Hijack CloudZ Pheno Plugin Insider Threat BlackCat (ALPHV) OFAC Sanctions DPRK IT Workers Transparent Tribe APT36 React2Shell, EtherRAT SideWinder Espionage, Netlify Phishing DDNS Abuse, C2 Infrastructure Hacking Health Club
  • Cyber Security

Kansas City Man Indicted for Hacking into Nonprofit and Health Club

Do Son November 26, 2024 0
Read More Read more about Kansas City Man Indicted for Hacking into Nonprofit and Health Club
Palo Alto Networks Warns of GlobalProtect App Flaw with Public Exploit Code (CVE-2024-5921) CVE-2024-5921 - CVE-2025-0103 CVE-2025-0110 PoC
  • Vulnerability

Palo Alto Networks Warns of GlobalProtect App Flaw with Public Exploit Code (CVE-2024-5921)

Do Son November 25, 2024 0
Read More Read more about Palo Alto Networks Warns of GlobalProtect App Flaw with Public Exploit Code (CVE-2024-5921)
PHP Patches Multi Flaws, Including CVE-2024-8932 (CVSS 9.8), Urges Immediate Update PHP Vulnerabilities, SQLi DoS CVE-2024-8932 & CVE-2024-8929
  • Vulnerability

PHP Patches Multi Flaws, Including CVE-2024-8932 (CVSS 9.8), Urges Immediate Update

Do Son November 25, 2024 0
Read More Read more about PHP Patches Multi Flaws, Including CVE-2024-8932 (CVSS 9.8), Urges Immediate Update
Critical Vulnerabilities in QNAP Notes Station 3: Update Now to Protect Your Data CVE-2024-38643 - CVE-2024-38645 & Notes Station 3
  • Vulnerability

Critical Vulnerabilities in QNAP Notes Station 3: Update Now to Protect Your Data

Do Son November 25, 2024 0
Read More Read more about Critical Vulnerabilities in QNAP Notes Station 3: Update Now to Protect Your Data
CVE-2024-10542 & CVE-2024-10781: Critical WordPress Plugin Flaw Exposes 200,000 Sites CVE-2024-10542 and CVE-2024-10781
  • Vulnerability

CVE-2024-10542 & CVE-2024-10781: Critical WordPress Plugin Flaw Exposes 200,000 Sites

Do Son November 25, 2024 0
Read More Read more about CVE-2024-10542 & CVE-2024-10781: Critical WordPress Plugin Flaw Exposes 200,000 Sites
Infostealers VietCredCare and DuckTail Fuel Facebook Business Account Exploitation VietCredCare
  • Cyber Security

Infostealers VietCredCare and DuckTail Fuel Facebook Business Account Exploitation

Do Son November 25, 2024 0
Read More Read more about Infostealers VietCredCare and DuckTail Fuel Facebook Business Account Exploitation
North Korean and Chinese Threat Actors Target Crypto, Aerospace, and Government Agencies Storm-2077
  • Cyber Security

North Korean and Chinese Threat Actors Target Crypto, Aerospace, and Government Agencies

Do Son November 25, 2024 0
Read More Read more about North Korean and Chinese Threat Actors Target Crypto, Aerospace, and Government Agencies
CVE-2023-28461 (CVSS 9.8): Critical Array Networks Vulnerability Added to KEV Catalog CVE-2023-28461
  • Vulnerability

CVE-2023-28461 (CVSS 9.8): Critical Array Networks Vulnerability Added to KEV Catalog

Do Son November 25, 2024 0
Read More Read more about CVE-2023-28461 (CVSS 9.8): Critical Array Networks Vulnerability Added to KEV Catalog
Lazarus Group Exploits xattr with “RustyAttr” to Evade Detection RustyAttr
  • Malware

Lazarus Group Exploits xattr with “RustyAttr” to Evade Detection

Do Son November 25, 2024 0
Read More Read more about Lazarus Group Exploits xattr with “RustyAttr” to Evade Detection
7 Android & Pixel Vulnerabilities Exposed: Researcher Publishes PoC Exploits Made by Google, Pixel 10 Pixel 10, Qi2 Baseband Security - CVE-2024-39343 Google Tensor TSMC Pixel 10 processor
  • Vulnerability

7 Android & Pixel Vulnerabilities Exposed: Researcher Publishes PoC Exploits

Do Son November 25, 2024 0
Read More Read more about 7 Android & Pixel Vulnerabilities Exposed: Researcher Publishes PoC Exploits
Malicious npm Packages Exploiting Typosquatting to Inject SSH Backdoors Inject SSH Backdoor
  • Malware

Malicious npm Packages Exploiting Typosquatting to Inject SSH Backdoors

Do Son November 25, 2024 0
Read More Read more about Malicious npm Packages Exploiting Typosquatting to Inject SSH Backdoors
Unveiling the “Nearest Neighbor Attack”: A Russian APT’s Covert Tactic to Weaponize Wi-Fi GruesomeLarch - Nearest Neighbor Attack
  • Cyber Security

Unveiling the “Nearest Neighbor Attack”: A Russian APT’s Covert Tactic to Weaponize Wi-Fi

Do Son November 25, 2024 0
Read More Read more about Unveiling the “Nearest Neighbor Attack”: A Russian APT’s Covert Tactic to Weaponize Wi-Fi
CVE-2024-48860 (CVSS 9.5): Critical Flaw in QNAP QuRouter, Immediate Update Recommended QNAP QVR Pro Vulnerability CVE-2026-22898 CVE-2022-27595 - CVE-2024-48860 & CVE-2024-48861
  • Vulnerability

CVE-2024-48860 (CVSS 9.5): Critical Flaw in QNAP QuRouter, Immediate Update Recommended

Do Son November 25, 2024 0
Read More Read more about CVE-2024-48860 (CVSS 9.5): Critical Flaw in QNAP QuRouter, Immediate Update Recommended
CVE-2024-11477: 7-Zip Vulnerability Allows Remote Code Execution, Update Now! CVE-2024-11477
  • Vulnerability

CVE-2024-11477: 7-Zip Vulnerability Allows Remote Code Execution, Update Now!

Do Son November 24, 2024 0
Read More Read more about CVE-2024-11477: 7-Zip Vulnerability Allows Remote Code Execution, Update Now!
Google Docs and Weebly Weaponized in New Phishing Scheme Motivated Threat Actors
  • Cyber Security

Google Docs and Weebly Weaponized in New Phishing Scheme

Do Son November 24, 2024 0
Read More Read more about Google Docs and Weebly Weaponized in New Phishing Scheme
Russia-Linked TAG-110 Launches Cyberespionage Campaign Across Asia and Europe TAG-110
  • Cyber Security
  • Malware

Russia-Linked TAG-110 Launches Cyberespionage Campaign Across Asia and Europe

Do Son November 24, 2024 0
Read More Read more about Russia-Linked TAG-110 Launches Cyberespionage Campaign Across Asia and Europe
WolfsBane: Gelsemium APT Group’s Linux Backdoor Debut Gelsemium APT group - WolfsBane
  • Cyber Security
  • Malware

WolfsBane: Gelsemium APT Group’s Linux Backdoor Debut

Do Son November 24, 2024 0
Read More Read more about WolfsBane: Gelsemium APT Group’s Linux Backdoor Debut
Asyncshell: The Evolution of APT-K-47’s Cyber Arsenal Asyncshell
  • Cyber Security
  • Malware

Asyncshell: The Evolution of APT-K-47’s Cyber Arsenal

Do Son November 24, 2024 0
Read More Read more about Asyncshell: The Evolution of APT-K-47’s Cyber Arsenal
Government IDs and Facial Recognition: A New Phishing Threat Facial Recognition
  • Cyber Security
  • Data Leak

Government IDs and Facial Recognition: A New Phishing Threat

Do Son November 24, 2024 0
Read More Read more about Government IDs and Facial Recognition: A New Phishing Threat
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 23, 2026
  • CVE-2026-94127CVSS 9.8
    When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-85102CVSS 9.8
    Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93616CVSS 9.8
    A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-100741CVSS 9.8
    Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3.3 on Windows,...
    📅 Updated: Sep 27, 2026
  • CVE-2026-94130CVSS 9.3
    Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injection...
    📅 Updated: Sep 27, 2026
  • CVE-2026-97161CVSS 9.2
    Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
    📅 Updated: Sep 27, 2026
  • CVE-2026-97163CVSS 10.0
    Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
    📅 Updated: Sep 27, 2026
  • CVE-2026-94132CVSS 9.5
    Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension <...
    📅 Updated: Sep 27, 2026
  • CVE-2026-97160CVSS 9.4
    Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
    📅 Updated: Sep 27, 2026
  • CVE-2026-100835CVSS 9.1
    Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report that verified...
    📅 Updated: Sep 27, 2026
  • CVE-2026-100721CVSS 9.5
    vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with...
    📅 Updated: Sep 27, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.