Skip to content
September 28, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Iranian “Dream Job” Campaign Targets Aerospace Industry with SnailResin Malware SnailResin malware
  • Cyber Security
  • Malware

Iranian “Dream Job” Campaign Targets Aerospace Industry with SnailResin Malware

Do Son November 12, 2024 0
Read More Read more about Iranian “Dream Job” Campaign Targets Aerospace Industry with SnailResin Malware
Dell SmartFabric OS10 Receives Important Security Updates Dell DD OS Vulnerability, Authentication Bypass Dell SmartFabric OS10 Vulnerabilities
  • Vulnerability

Dell SmartFabric OS10 Receives Important Security Updates

Do Son November 12, 2024 0
Read More Read more about Dell SmartFabric OS10 Receives Important Security Updates
New PowerShell Threat: Infiltrating Networks with Advanced Techniques PowerShell Campaign
  • Malware

New PowerShell Threat: Infiltrating Networks with Advanced Techniques

Do Son November 12, 2024 0
Read More Read more about New PowerShell Threat: Infiltrating Networks with Advanced Techniques
CVE-2024-50330 (CVSS 9.8): Unpatched Ivanti Endpoint Manager Vulnerable to RCE Attacks Ivanti EPMM security updates Ivanti ITSM vulnerability authenticated privilege escalation Ivanti Xtraction vulnerability CVE-2026-8043 Ivanti EPM RCE, SQL Injection Ivanti EPM, remote code execution CVE-2024-50330 - CVE-2025-0282 and CVE-2025-0283
  • Vulnerability

CVE-2024-50330 (CVSS 9.8): Unpatched Ivanti Endpoint Manager Vulnerable to RCE Attacks

Do Son November 12, 2024 0
Read More Read more about CVE-2024-50330 (CVSS 9.8): Unpatched Ivanti Endpoint Manager Vulnerable to RCE Attacks
CVE-2024-8068 & CVE-2024-8069: Citrix Session Recording Manager Unauthenticated RCE Exploits Publicly Available CVE-2024-8068 & CVE-2024-8069 - Citrix Session Recording Manager
  • Vulnerability

CVE-2024-8068 & CVE-2024-8069: Citrix Session Recording Manager Unauthenticated RCE Exploits Publicly Available

Do Son November 12, 2024 0
Read More Read more about CVE-2024-8068 & CVE-2024-8069: Citrix Session Recording Manager Unauthenticated RCE Exploits Publicly Available
Citrix NetScaler ADC and Gateway Vulnerabilities Put Organizations at Risk NetScaler Vulnerability CVE-2026-3055 Citrix VDA, Privilege Escalation NetScaler Vulnerabilities, Access Bypass CVE-2024-8534 and CVE-2024-8535
  • Vulnerability

Citrix NetScaler ADC and Gateway Vulnerabilities Put Organizations at Risk

Do Son November 12, 2024 0
Read More Read more about Citrix NetScaler ADC and Gateway Vulnerabilities Put Organizations at Risk
CVE-2024-44102 (CVSS 10) Found in Siemens TeleControl Server Basic: Urgent Update Required Siemens SIMATIC S7 Vulnerability Industrial PLC XSS CVE-2024-44102 - Siemens TeleControl Server Basic
  • Vulnerability

CVE-2024-44102 (CVSS 10) Found in Siemens TeleControl Server Basic: Urgent Update Required

Do Son November 12, 2024 0
Read More Read more about CVE-2024-44102 (CVSS 10) Found in Siemens TeleControl Server Basic: Urgent Update Required
Schneider Electric Warns of Multiple Vulnerabilities in Modicon Controllers CVE-2024-8937 & CVE-2024-8938
  • Vulnerability

Schneider Electric Warns of Multiple Vulnerabilities in Modicon Controllers

Do Son November 12, 2024 0
Read More Read more about Schneider Electric Warns of Multiple Vulnerabilities in Modicon Controllers
SAP Patches Multiple Vulnerabilities in November 2024 Security Patch Day CVE-2024-41730 - SAP Security Patch Day SAP S/4HANA Vulnerability CVE-2026-0501
  • Vulnerability

SAP Patches Multiple Vulnerabilities in November 2024 Security Patch Day

Do Son November 12, 2024 0
Read More Read more about SAP Patches Multiple Vulnerabilities in November 2024 Security Patch Day
Broadcom’s Game-Changing Move: VMware Fusion and Workstation Now Free for All Users VMware Fusion and Workstation Now Free CVE-2025-22231
  • Technology

Broadcom’s Game-Changing Move: VMware Fusion and Workstation Now Free for All Users

Do Son November 12, 2024 0
Read More Read more about Broadcom’s Game-Changing Move: VMware Fusion and Workstation Now Free for All Users
The Future of Cybersecurity: Trends Shaping the Industry Employees Risk
  • Technique

The Future of Cybersecurity: Trends Shaping the Industry

Do Son November 12, 2024 0
Read More Read more about The Future of Cybersecurity: Trends Shaping the Industry
CVE-2024-11068 (CVSS 9.8): Critical D-Link DSL-6740C Flaw, Immediate Replacement Advised D-Link DSL-6740C - CVE-2024-11068
  • Vulnerability

CVE-2024-11068 (CVSS 9.8): Critical D-Link DSL-6740C Flaw, Immediate Replacement Advised

Do Son November 11, 2024 0
Read More Read more about CVE-2024-11068 (CVSS 9.8): Critical D-Link DSL-6740C Flaw, Immediate Replacement Advised
VPNs and Clouds: New Tools in the APT Arsenal, ESET Warns APT Activity
  • Cyber Security
  • Malware

VPNs and Clouds: New Tools in the APT Arsenal, ESET Warns

Do Son November 11, 2024 0
Read More Read more about VPNs and Clouds: New Tools in the APT Arsenal, ESET Warns
Dell Enterprise SONIC OS Patches Critical Security Vulnerabilities CVE-2024-45763, CVE-2024-45764, and CVE-2024-45765
  • Vulnerability

Dell Enterprise SONIC OS Patches Critical Security Vulnerabilities

Do Son November 11, 2024 0
Read More Read more about Dell Enterprise SONIC OS Patches Critical Security Vulnerabilities
JavaScript Drive-By Attacks: New Exploits without 0-Day in Google Chrome Google Chrome Helper
  • Vulnerability

JavaScript Drive-By Attacks: New Exploits without 0-Day in Google Chrome

Do Son November 11, 2024 0
Read More Read more about JavaScript Drive-By Attacks: New Exploits without 0-Day in Google Chrome
Mozi Botnet Re-Emerges as Androxgh0st in New Wave of IoT Exploits
  • Malware
  • Vulnerability

Mozi Botnet Re-Emerges as Androxgh0st in New Wave of IoT Exploits

Do Son November 11, 2024 0
Read More Read more about Mozi Botnet Re-Emerges as Androxgh0st in New Wave of IoT Exploits
Ghostscript Update Patches Six Critical Vulnerabilities: Code Execution, Buffer Overflow, and Path Traversal Risks CVE-2024-46951- Ghostscript vulnerability
  • Vulnerability

Ghostscript Update Patches Six Critical Vulnerabilities: Code Execution, Buffer Overflow, and Path Traversal Risks

Do Son November 11, 2024 0
Read More Read more about Ghostscript Update Patches Six Critical Vulnerabilities: Code Execution, Buffer Overflow, and Path Traversal Risks
Wish Stealer: New Malware Targets Discord, Browsers, and Cryptocurrency Wallets Wish Stealer
  • Malware

Wish Stealer: New Malware Targets Discord, Browsers, and Cryptocurrency Wallets

Do Son November 11, 2024 0
Read More Read more about Wish Stealer: New Malware Targets Discord, Browsers, and Cryptocurrency Wallets
XStream Security Advisory: Denial-of-Service Vulnerability (CVE-2024-47072) CVE-2024-47072
  • Vulnerability

XStream Security Advisory: Denial-of-Service Vulnerability (CVE-2024-47072)

Do Son November 11, 2024 0
Read More Read more about XStream Security Advisory: Denial-of-Service Vulnerability (CVE-2024-47072)
Earth Estries’ Evolving Toolkit: A Deep Dive into Their Advanced Techniques BlueNoroff macOS Attack GhostCall Campaign Carding Underground Bulletproof Hosting DPRK Contagious Interview, npm Flood Stonefly group -HiatusRAT Actors
  • Cyber Security
  • Malware

Earth Estries’ Evolving Toolkit: A Deep Dive into Their Advanced Techniques

Do Son November 11, 2024 0
Read More Read more about Earth Estries’ Evolving Toolkit: A Deep Dive into Their Advanced Techniques
Trojan Malware Delivered via ZIP Concatenation: A New Threat to Windows Users ZIP concatenation
  • Malware

Trojan Malware Delivered via ZIP Concatenation: A New Threat to Windows Users

Do Son November 11, 2024 0
Read More Read more about Trojan Malware Delivered via ZIP Concatenation: A New Threat to Windows Users
SEO Poisoning: Unmasking the Malware Networks Behind Fake E-Commerce Japanese keyword hack
  • Cyber Security
  • Malware

SEO Poisoning: Unmasking the Malware Networks Behind Fake E-Commerce

Do Son November 11, 2024 0
Read More Read more about SEO Poisoning: Unmasking the Malware Networks Behind Fake E-Commerce
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-88771
    Remote code execution due to improper input validation that can allow an unauthenticated attacker to execute arbitrary commands.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 23, 2026
  • CVE-2026-94127CVSS 9.8
    When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-101187CVSS 9.4
    A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function pop_usb_device of the...
    📅 Updated: Sep 28, 2026
  • CVE-2026-102268CVSS 9.1
    PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/utils.py is affected...
    📅 Updated: Sep 28, 2026
  • CVE-2026-46649CVSS 9.1
    Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to...
    📅 Updated: Sep 28, 2026
  • CVE-2026-19759CVSS 9.4
    An Incorrect Authorization vulnerability in the task configuration in Google Cloud Application Integration versions prior to 2026-06-17 on Google...
    📅 Updated: Sep 28, 2026
  • CVE-2026-100606CVSS 9.2
    Flowise through 3.1.4 (Enterprise/platform mode with SSO enabled) contains an authentication bypass in the SSO login path. When...
    📅 Updated: Sep 28, 2026
  • CVE-2026-101110CVSS 9.3
    Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 - site/booklibrary.php’s books() function...
    📅 Updated: Sep 28, 2026
  • CVE-2026-100752CVSS 9.3
    Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds...
    📅 Updated: Sep 28, 2026
  • CVE-2026-101108CVSS 9.3
    Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 - site/vehiclemanager.php reads the...
    📅 Updated: Sep 28, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.