Skip to content
September 28, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Emmenhtal Loader’s Stealthy Tactics for Delivering Lumma and Other Malware Emmenhtal Loader
  • Malware

Emmenhtal Loader’s Stealthy Tactics for Delivering Lumma and Other Malware

Do Son November 14, 2024 0
Read More Read more about Emmenhtal Loader’s Stealthy Tactics for Delivering Lumma and Other Malware
Right-Click to Hack: Zero-Day CVE-2024-43451 Vulnerability Targets Windows Users CVE-2024-43451
  • Cyber Security
  • Vulnerability

Right-Click to Hack: Zero-Day CVE-2024-43451 Vulnerability Targets Windows Users

Do Son November 13, 2024 0
Read More Read more about Right-Click to Hack: Zero-Day CVE-2024-43451 Vulnerability Targets Windows Users
RustyAttr Trojan: Lazarus Group’s New macOS Malware Evades Antivirus with Ease RustyAttr Trojan
  • Cyber Security
  • Malware

RustyAttr Trojan: Lazarus Group’s New macOS Malware Evades Antivirus with Ease

Do Son November 13, 2024 0
Read More Read more about RustyAttr Trojan: Lazarus Group’s New macOS Malware Evades Antivirus with Ease
Strela Stealer Surge: Hive0145 Targets European Email Credentials Zyxel security - Mitel MiCollab Vulnerability
  • Cyber Security
  • Malware

Strela Stealer Surge: Hive0145 Targets European Email Credentials

Do Son November 13, 2024 0
Read More Read more about Strela Stealer Surge: Hive0145 Targets European Email Credentials
2023’s Most Exploited Vulnerabilities: A Global Cybersecurity Advisory Fortinet patch bypass 2026, FortiGate SSO authentication exploit SharePoint Zero-Day, China APTs Exploited Vulnerabilities 2023
  • Vulnerability

2023’s Most Exploited Vulnerabilities: A Global Cybersecurity Advisory

Do Son November 13, 2024 0
Read More Read more about 2023’s Most Exploited Vulnerabilities: A Global Cybersecurity Advisory
WIRTE: Hamas-Linked Cyber Espionage Group Now Wielding SameCoin Wiper Malware Wiper malware - WIRTE threat actor group
  • Cyber Security
  • Malware

WIRTE: Hamas-Linked Cyber Espionage Group Now Wielding SameCoin Wiper Malware

Do Son November 13, 2024 0
Read More Read more about WIRTE: Hamas-Linked Cyber Espionage Group Now Wielding SameCoin Wiper Malware
Trusted Name Weaponized: Sliver and Ligolo-ng Attack Leverages Y Combinator Brand Y Combinator
  • Cyber Security

Trusted Name Weaponized: Sliver and Ligolo-ng Attack Leverages Y Combinator Brand

Do Son November 13, 2024 0
Read More Read more about Trusted Name Weaponized: Sliver and Ligolo-ng Attack Leverages Y Combinator Brand
CVE-2024-9693: GitLab Issues Critical Patch for Kubernetes Agent GitLab security updates Duo AI flaw fixed GitLab Runner Hijack, DoS Fix GitLab GraphQL Flaws, CVE-2025-11340 CVE-2024-9693 GitLab vulnerability, XSS
  • Vulnerability

CVE-2024-9693: GitLab Issues Critical Patch for Kubernetes Agent

Do Son November 13, 2024 0
Read More Read more about CVE-2024-9693: GitLab Issues Critical Patch for Kubernetes Agent
North Korean APT Group Targets macOS with Flutter-based Malware in Cryptocurrency Apps Flutter malware
  • Malware

North Korean APT Group Targets macOS with Flutter-based Malware in Cryptocurrency Apps

Do Son November 13, 2024 0
Read More Read more about North Korean APT Group Targets macOS with Flutter-based Malware in Cryptocurrency Apps
ModeLeak Flaw: Researcher Uncovers Privilege Escalation & Model Exfiltration Threats in Google Vertex AI ModeLeak - Google Vertex AI
  • Vulnerability

ModeLeak Flaw: Researcher Uncovers Privilege Escalation & Model Exfiltration Threats in Google Vertex AI

Do Son November 13, 2024 0
Read More Read more about ModeLeak Flaw: Researcher Uncovers Privilege Escalation & Model Exfiltration Threats in Google Vertex AI
CVE-2024-10914: Critical Flaw in D-Link NAS Devices Actively Exploited, No Patch! CVE-2024-10914 exploit
  • Vulnerability

CVE-2024-10914: Critical Flaw in D-Link NAS Devices Actively Exploited, No Patch!

Do Son November 13, 2024 0
Read More Read more about CVE-2024-10914: Critical Flaw in D-Link NAS Devices Actively Exploited, No Patch!
Google Cloud Enhances Transparency with Expanded CVE Reporting Google Cloud CVE
  • Technology

Google Cloud Enhances Transparency with Expanded CVE Reporting

Do Son November 13, 2024 0
Read More Read more about Google Cloud Enhances Transparency with Expanded CVE Reporting
Chrome 131 Rolls Out with Security Fixes and Performance Enhancements Chrome 131 - CVE-2024-11110
  • Vulnerability

Chrome 131 Rolls Out with Security Fixes and Performance Enhancements

Do Son November 13, 2024 0
Read More Read more about Chrome 131 Rolls Out with Security Fixes and Performance Enhancements
CISA Adds Five Actively Exploited Vulnerabilities to KEV Catalog CISA KEV Update Versa Concerto Vulnerability KEV Catalog Vulnerability Patch CVE-2025-30406
  • Vulnerability

CISA Adds Five Actively Exploited Vulnerabilities to KEV Catalog

Do Son November 12, 2024 0
Read More Read more about CISA Adds Five Actively Exploited Vulnerabilities to KEV Catalog
Ivanti Connect Secure, Policy Secure and Secure Access Client Affected by Critical Vulnerabilities Ivanti Connect Secure
  • Vulnerability

Ivanti Connect Secure, Policy Secure and Secure Access Client Affected by Critical Vulnerabilities

Do Son November 12, 2024 0
Read More Read more about Ivanti Connect Secure, Policy Secure and Secure Access Client Affected by Critical Vulnerabilities
Researcher Finds Trojanized Apps with 2 Million Downloads on Google Play FakeApp trojan
  • Malware

Researcher Finds Trojanized Apps with 2 Million Downloads on Google Play

Do Son November 12, 2024 0
Read More Read more about Researcher Finds Trojanized Apps with 2 Million Downloads on Google Play
CVE-2024-10575 (CVSS 10): Critical Flaw in Schneider Electric’s EcoStruxure IT Gateway CVE-2024-10575 CVE-2025-1960 Schneider Electric Vulnerability CVE-2026-0667
  • Vulnerability

CVE-2024-10575 (CVSS 10): Critical Flaw in Schneider Electric’s EcoStruxure IT Gateway

Do Son November 12, 2024 0
Read More Read more about CVE-2024-10575 (CVSS 10): Critical Flaw in Schneider Electric’s EcoStruxure IT Gateway
Apache CloudStack Releases Security Update for KVM Infrastructure Vulnerability – CVE-2024-50386 CVE-2024-50386 Apache CloudStack, Critical Vulnerabilities
  • Vulnerability

Apache CloudStack Releases Security Update for KVM Infrastructure Vulnerability – CVE-2024-50386

Do Son November 12, 2024 0
Read More Read more about Apache CloudStack Releases Security Update for KVM Infrastructure Vulnerability – CVE-2024-50386
Zoom Issues Security Update Addressing Vulnerabilities in Workplace and SDK Apps Zoom Node Vulnerability CVE-2026-22844 CVE-2024-45421 & CVE-2024-45419 CVE-2025-27440
  • Vulnerability

Zoom Issues Security Update Addressing Vulnerabilities in Workplace and SDK Apps

Do Son November 12, 2024 0
Read More Read more about Zoom Issues Security Update Addressing Vulnerabilities in Workplace and SDK Apps
New Critical Vulnerabilities in Kanboard Project Management Software: Admins Urged to Patch CVE-2024-51747 & CVE-2024-51748
  • Vulnerability

New Critical Vulnerabilities in Kanboard Project Management Software: Admins Urged to Patch

Do Son November 12, 2024 0
Read More Read more about New Critical Vulnerabilities in Kanboard Project Management Software: Admins Urged to Patch
NAKIVO Backup & Replication: Optimize Backup Management and Streamline Administration NAKIVO-Backup-Management-Dashboard
  • Technique

NAKIVO Backup & Replication: Optimize Backup Management and Streamline Administration

Do Son November 12, 2024 0
Read More Read more about NAKIVO Backup & Replication: Optimize Backup Management and Streamline Administration
Microsoft Addresses Critical Zero-Day Vulnerabilities in November Patch Tuesday Microsoft Patch Tuesday May 2026 Netlogon RCE CVE-2026-41089 SharePoint Exploit Patch Tuesday Windows DWM Zero-Day CVE-2026-21519 CVE-2024-49039 Microsoft Patch Tuesday March 2025
  • Vulnerability

Microsoft Addresses Critical Zero-Day Vulnerabilities in November Patch Tuesday

Do Son November 12, 2024 0
Read More Read more about Microsoft Addresses Critical Zero-Day Vulnerabilities in November Patch Tuesday
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-88771
    Remote code execution due to improper input validation that can allow an unauthenticated attacker to execute arbitrary commands.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 23, 2026
  • CVE-2026-94127CVSS 9.8
    When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-101187CVSS 9.4
    A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function pop_usb_device of the...
    📅 Updated: Sep 28, 2026
  • CVE-2026-102268CVSS 9.1
    PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/utils.py is affected...
    📅 Updated: Sep 28, 2026
  • CVE-2026-46649CVSS 9.1
    Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to...
    📅 Updated: Sep 28, 2026
  • CVE-2026-19759CVSS 9.4
    An Incorrect Authorization vulnerability in the task configuration in Google Cloud Application Integration versions prior to 2026-06-17 on Google...
    📅 Updated: Sep 28, 2026
  • CVE-2026-100606CVSS 9.2
    Flowise through 3.1.4 (Enterprise/platform mode with SSO enabled) contains an authentication bypass in the SSO login path. When...
    📅 Updated: Sep 28, 2026
  • CVE-2026-101110CVSS 9.3
    Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 - site/booklibrary.php’s books() function...
    📅 Updated: Sep 28, 2026
  • CVE-2026-100752CVSS 9.3
    Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds...
    📅 Updated: Sep 28, 2026
  • CVE-2026-101108CVSS 9.3
    Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 - site/vehiclemanager.php reads the...
    📅 Updated: Sep 28, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.