Skip to content
October 8, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
UAC-0185 APT Leverages Social Engineering to Target Ukrainian Defense Industrial Base UAC-0185 - MESHAGENT RAT
  • Cyber Security
  • Malware

UAC-0185 APT Leverages Social Engineering to Target Ukrainian Defense Industrial Base

Do Son December 10, 2024 0
Read More Read more about UAC-0185 APT Leverages Social Engineering to Target Ukrainian Defense Industrial Base
Ivanti Connect Secure and Policy Secure Updates Address Critical Vulnerabilities Ivanti EPMM security updates Ivanti ITSM vulnerability authenticated privilege escalation Ivanti Xtraction vulnerability CVE-2026-8043 Ivanti EPM RCE, SQL Injection Ivanti EPM, remote code execution CVE-2024-50330 - CVE-2025-0282 and CVE-2025-0283
  • Vulnerability

Ivanti Connect Secure and Policy Secure Updates Address Critical Vulnerabilities

Do Son December 10, 2024 0
Read More Read more about Ivanti Connect Secure and Policy Secure Updates Address Critical Vulnerabilities
Researcher Details CVE-2024-44131 – A Critical TCC Bypass in macOS and iOS Apple Background Security CVE-2026-20643 Apple Background Security Improvement Apple Backdoor Apple Lawsuit, Data Exfiltration CVE-2024-44131 - CVE-2025-24118 PoC
  • Vulnerability

Researcher Details CVE-2024-44131 – A Critical TCC Bypass in macOS and iOS

Do Son December 10, 2024 0
Read More Read more about Researcher Details CVE-2024-44131 – A Critical TCC Bypass in macOS and iOS
Microsoft Strengthens Default Security Posture Against NTLM Relay Attacks NTLM Relay Attacks
  • Technology

Microsoft Strengthens Default Security Posture Against NTLM Relay Attacks

Do Son December 10, 2024 0
Read More Read more about Microsoft Strengthens Default Security Posture Against NTLM Relay Attacks
CVE-2024-52335 (CVSS 9.8): Siemens Healthineers Addresses Critical Flaw in Medical Imaging Software CVE-2024-52335 HylaFAX, AvantFAX vulnerability
  • Vulnerability

CVE-2024-52335 (CVSS 9.8): Siemens Healthineers Addresses Critical Flaw in Medical Imaging Software

Do Son December 10, 2024 0
Read More Read more about CVE-2024-52335 (CVSS 9.8): Siemens Healthineers Addresses Critical Flaw in Medical Imaging Software
Exploiting CDN Integrations: A WAF Bypass Threatening Global Web Applications Foomuuri Vulnerability CVE-2025-67603 bypass WAF protections
  • Vulnerability

Exploiting CDN Integrations: A WAF Bypass Threatening Global Web Applications

Do Son December 10, 2024 0
Read More Read more about Exploiting CDN Integrations: A WAF Bypass Threatening Global Web Applications
No Warning, No Data: Hetzner Terminates Kiwix Account Abruptly Hetzner Terminates Kiwix
  • Technology

No Warning, No Data: Hetzner Terminates Kiwix Account Abruptly

Do Son December 10, 2024 0
Read More Read more about No Warning, No Data: Hetzner Terminates Kiwix Account Abruptly
Apache Superset Patches Multi Security Flaws in Latest Release CVE-2024-53947, CVE-2024-53948, and CVE-2024-53949
  • Vulnerability

Apache Superset Patches Multi Security Flaws in Latest Release

Do Son December 10, 2024 0
Read More Read more about Apache Superset Patches Multi Security Flaws in Latest Release
Schneider Electric Warns of Critical Flaw in Modicon Controllers – CVE-2024-11737 (CVSS 9.8) CVE-2024-8884 & CVE-2024-11737 Schneider Electric, Critical Vulnerabilities
  • Vulnerability

Schneider Electric Warns of Critical Flaw in Modicon Controllers – CVE-2024-11737 (CVSS 9.8)

Do Son December 10, 2024 0
Read More Read more about Schneider Electric Warns of Critical Flaw in Modicon Controllers – CVE-2024-11737 (CVSS 9.8)
Artivion Discloses Cybersecurity Incident, Impacts Operations and Financial Outlook Artivion cybersecurity - Zero-Day Attacks
  • Cyber Security

Artivion Discloses Cybersecurity Incident, Impacts Operations and Financial Outlook

Do Son December 10, 2024 0
Read More Read more about Artivion Discloses Cybersecurity Incident, Impacts Operations and Financial Outlook
Microsoft Addresses Critical Zero-Day CVE-2024-49138 & 72 Additional Flaws in December Patch Tuesday Driver Cleanup CVE-2024-49138 - December Patch Tuesday Windows update errors, Windows update troubleshooting
  • Vulnerability
  • Windows

Microsoft Addresses Critical Zero-Day CVE-2024-49138 & 72 Additional Flaws in December Patch Tuesday

Do Son December 10, 2024 0
Read More Read more about Microsoft Addresses Critical Zero-Day CVE-2024-49138 & 72 Additional Flaws in December Patch Tuesday
Google Chrome Patches High-Severity Vulnerabilities – CVE-2024-12381 & CVE-2024-12382 CVE-2024-12381 & CVE-2024-12382
  • Vulnerability

Google Chrome Patches High-Severity Vulnerabilities – CVE-2024-12381 & CVE-2024-12382

Do Son December 10, 2024 0
Read More Read more about Google Chrome Patches High-Severity Vulnerabilities – CVE-2024-12381 & CVE-2024-12382
Patchwork APT Targets Chinese Scientific Research in Renewed Campaign Exploited VMware
  • Cyber Security

Patchwork APT Targets Chinese Scientific Research in Renewed Campaign

Do Son December 10, 2024 0
Read More Read more about Patchwork APT Targets Chinese Scientific Research in Renewed Campaign
MoqHao Malware Targets Apple IDs and Android Devices Using iCloud and VK Platforms MoqHao malware
  • Cyber Security
  • Malware

MoqHao Malware Targets Apple IDs and Android Devices Using iCloud and VK Platforms

Do Son December 10, 2024 0
Read More Read more about MoqHao Malware Targets Apple IDs and Android Devices Using iCloud and VK Platforms
The evolution of lending: how AI is revolutionizing loan origination 3ctirf4kk00qeXp
  • Technique

The evolution of lending: how AI is revolutionizing loan origination

Do Son December 10, 2024 0
Read More Read more about The evolution of lending: how AI is revolutionizing loan origination
CVE-2024-47578 (CVSS 9.1): SAP Issues Critical Patch for NetWeaver AS for JAVA SAP Security Patches CVE-2026-27685 SAP Security Update CVE-2026-0488 CVE-2024-47578 - CVE-2025-0070 and CVE-2025-0066
  • Vulnerability

CVE-2024-47578 (CVSS 9.1): SAP Issues Critical Patch for NetWeaver AS for JAVA

Do Son December 10, 2024 0
Read More Read more about CVE-2024-47578 (CVSS 9.1): SAP Issues Critical Patch for NetWeaver AS for JAVA
CVE-2024-50623: Critical Vulnerability in Cleo Software Actively Exploited in the Wild PAN-OS Root RCE CL-STA-1132 Exploitation Tianxin RCE CVE-2021-4473 React Native Supply Chain Attack AstrOOnauta Malware Gladinet Zero-Day, LFI RCE Chain WordPress Theme, Account Takeover CVE-2024-50623 - European Space Agency cyberattack
  • Vulnerability

CVE-2024-50623: Critical Vulnerability in Cleo Software Actively Exploited in the Wild

Do Son December 10, 2024 0
Read More Read more about CVE-2024-50623: Critical Vulnerability in Cleo Software Actively Exploited in the Wild
How Can You Unblock Your IP Address in 5 Easy Ways? 67344006c9d78
  • Technique

How Can You Unblock Your IP Address in 5 Easy Ways?

Do Son December 10, 2024 0
Read More Read more about How Can You Unblock Your IP Address in 5 Easy Ways?
CVE-2024-54143: Critical Vulnerability in OpenWrt’s Attended SysUpgrade Server Allows for Firmware Poisoning SysUpgrade Server - CVE-2024-54143
  • Vulnerability

CVE-2024-54143: Critical Vulnerability in OpenWrt’s Attended SysUpgrade Server Allows for Firmware Poisoning

Do Son December 9, 2024 0
Read More Read more about CVE-2024-54143: Critical Vulnerability in OpenWrt’s Attended SysUpgrade Server Allows for Firmware Poisoning
Let’s Encrypt to Deprecate OCSP in Favor of CRLs, Enhancing User Privacy Merkle Tree Certificates Let's Encrypt 45-Day Certificates ACME Profile Updates 2026 Let’s Encrypt Generation Y, 45-Day TLS Certificates Let's Encrypt, IP Certificates Certificate Revocation Lists
  • Technology

Let’s Encrypt to Deprecate OCSP in Favor of CRLs, Enhancing User Privacy

Do Son December 9, 2024 0
Read More Read more about Let’s Encrypt to Deprecate OCSP in Favor of CRLs, Enhancing User Privacy
International Operation Dismantles Phone Phishing Ring Targeting Vulnerable Individuals Across Europe Crypto Drain Conspiracy, Malicious MobileConfig phone phishing Cryptocurrency Phishing
  • Cyber Security

International Operation Dismantles Phone Phishing Ring Targeting Vulnerable Individuals Across Europe

Do Son December 9, 2024 0
Read More Read more about International Operation Dismantles Phone Phishing Ring Targeting Vulnerable Individuals Across Europe
Bulletproof Hosting: The Dark Infrastructure Behind Global Cybercrime bulletproof hosting
  • Cyber Security

Bulletproof Hosting: The Dark Infrastructure Behind Global Cybercrime

Do Son December 9, 2024 0
Read More Read more about Bulletproof Hosting: The Dark Infrastructure Behind Global Cybercrime
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-93836CVSS 7.2
    The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \'qty\'...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-21589CVSS 9.3
    This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-12260CVSS 10.0
    SQL injection in the NetBoard CRM demo platform; specifically, the vulnerable component is the ‘user-name’ POST parameter in...
    📅 Updated: Oct 8, 2026
  • CVE-2026-85097CVSS 9.8
    The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in versions up to, and including,...
    📅 Updated: Oct 8, 2026
  • CVE-2026-107459CVSS 9.3
    The SecuShare Pro developed by Openfind has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary...
    📅 Updated: Oct 8, 2026
  • CVE-2026-17609CVSS 9.1
    The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory Deletion...
    📅 Updated: Oct 8, 2026
  • CVE-2026-102782CVSS 9.3
    Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Simple Membership < 7.4.0 - site/simplemembership.php dispatches task=checkLoginPass...
    📅 Updated: Oct 8, 2026
  • CVE-2026-48908CVSS 10.0
    A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in...
    CISA KEV📅 Added to KEV: Jul 7, 2026📅 Updated: Oct 8, 2026
  • CVE-2026-56290CVSS 10.0
    Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla...
    CISA KEV📅 Added to KEV: Jul 7, 2026📅 Updated: Oct 8, 2026
  • CVE-2026-93674CVSS 9.8
    IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper...
    📅 Updated: Oct 8, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.