Skip to content
July 24, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Ecosystem Poisoned: Mini Shai-Hulud Worm Hijacks @antv npm Packages to Target CI/CD Pipelines AntV npm Supply Chain Attack Mini Shai-Hulud npm Worm
  • Malware

Ecosystem Poisoned: Mini Shai-Hulud Worm Hijacks @antv npm Packages to Target CI/CD Pipelines

Do Son May 21, 2026 0
Read More Read more about Ecosystem Poisoned: Mini Shai-Hulud Worm Hijacks @antv npm Packages to Target CI/CD Pipelines
Hundreds of Millions Affected: New “nginx-poolslip” Zero-Day Weaponizes ASLR Bypass for Remote Code Execution nginx-poolslip zero-day Nginx 1.31.0 RCE
  • Vulnerability Report

Hundreds of Millions Affected: New “nginx-poolslip” Zero-Day Weaponizes ASLR Bypass for Remote Code Execution

Do Son May 21, 2026 0
Read More Read more about Hundreds of Millions Affected: New “nginx-poolslip” Zero-Day Weaponizes ASLR Bypass for Remote Code Execution
Signature Bypass Alert: Critical Coder Flaw (CVE-2026-46354) Exposes Git Keys and Developer Tokens Coder Token Theft Vulnerability CVE-2026-46354 Azure Identity
  • Vulnerability Report

Signature Bypass Alert: Critical Coder Flaw (CVE-2026-46354) Exposes Git Keys and Developer Tokens

Do Son May 21, 2026 0
Read More Read more about Signature Bypass Alert: Critical Coder Flaw (CVE-2026-46354) Exposes Git Keys and Developer Tokens
CVSS 10.0 Alert: Critical Cisco Secure Workload Exploit Grants Unauthenticated Site Admin Access Cisco Secure Workload Vulnerability CVE-2026-20223 CVSS 10
  • Vulnerability Report

CVSS 10.0 Alert: Critical Cisco Secure Workload Exploit Grants Unauthenticated Site Admin Access

Do Son May 21, 2026 0
Read More Read more about CVSS 10.0 Alert: Critical Cisco Secure Workload Exploit Grants Unauthenticated Site Admin Access
Unpatched CVSS 10 Alert: ChromaDB Python Server Grants Pre-Auth RCE via Malicious Hugging Face Models ChromaDB Pre-Auth RCE CVE-2026-45829
  • Vulnerability Report

Unpatched CVSS 10 Alert: ChromaDB Python Server Grants Pre-Auth RCE via Malicious Hugging Face Models

Do Son May 21, 2026 0
Read More Read more about Unpatched CVSS 10 Alert: ChromaDB Python Server Grants Pre-Auth RCE via Malicious Hugging Face Models
Double Critical Threat: Google Chrome Rushes Out Urgent Fixes for WebRTC and UI Sandbox Flaws Google Chrome Security Update CVE-2026-9111 Critical Patch
  • Vulnerability Report

Double Critical Threat: Google Chrome Rushes Out Urgent Fixes for WebRTC and UI Sandbox Flaws

Do Son May 21, 2026 0
Read More Read more about Double Critical Threat: Google Chrome Rushes Out Urgent Fixes for WebRTC and UI Sandbox Flaws
Exploited in the Wild: Critical Drupal SQL Injection (CVE-2026-9082) Grants Attacker Root Access CVE-2022-39261 Drupal SQL Injection Vulnerability CVE-2026-9082 PostgreSQL Flaw
  • Vulnerability Report

Exploited in the Wild: Critical Drupal SQL Injection (CVE-2026-9082) Grants Attacker Root Access

Do Son May 21, 2026 0
Read More Read more about Exploited in the Wild: Critical Drupal SQL Injection (CVE-2026-9082) Grants Attacker Root Access
Unpatched SGLang Vulnerabilities (CVE-2026-7301) Expose AI Inference Pipelines to RCE SGLang RCE Vulnerability CVE-2026-7301 Zero-Day SGLang RCE AI Infrastructure Vulnerability
  • Vulnerability Report

Unpatched SGLang Vulnerabilities (CVE-2026-7301) Expose AI Inference Pipelines to RCE

Do Son May 21, 2026 0
Read More Read more about Unpatched SGLang Vulnerabilities (CVE-2026-7301) Expose AI Inference Pipelines to RCE
Critical RCE Exploits Exposed: Apache OFBiz Patches Severe Authentication Bypass Flaws CVE-2022-25371 - CVE-2025-26865 Apache OFBiz RCE Vulnerability CVE-2026-45434 Authentication Bypass
  • Vulnerability Report

Critical RCE Exploits Exposed: Apache OFBiz Patches Severe Authentication Bypass Flaws

Do Son May 21, 2026 0
Read More Read more about Critical RCE Exploits Exposed: Apache OFBiz Patches Severe Authentication Bypass Flaws
Public Exploit Exposes Root Privilege Escalation Flaw in VMware Fusion VMware Fusion TOCTOU Exploit CVE-2026-41702 PoC
  • Vulnerability

Public Exploit Exposes Root Privilege Escalation Flaw in VMware Fusion

Do Son May 21, 2026 0
Read More Read more about Public Exploit Exposes Root Privilege Escalation Flaw in VMware Fusion
Secret Blizzard Transforms Kazuar into a Modular P2P Botnet Ecosystem Kazuar P2P Botnet Secret Blizzard Malware Evolution
  • Malware

Secret Blizzard Transforms Kazuar into a Modular P2P Botnet Ecosystem

Do Son May 20, 2026 0
Read More Read more about Secret Blizzard Transforms Kazuar into a Modular P2P Botnet Ecosystem
Inside UNC6671’s “BlackFile” Cloud Extortion Campaigns UNC6671 BlackFile Cloud Attacks AiTM MFA Bypass Okta Microsoft
  • Cybercriminals

Inside UNC6671’s “BlackFile” Cloud Extortion Campaigns

Do Son May 20, 2026 0
Read More Read more about Inside UNC6671’s “BlackFile” Cloud Extortion Campaigns
Google Drops Antigravity 2.0 to Orchestrate Teams of Autonomous Coding Agents Gemini CLI deprecation notice as Google moves developers to the Antigravity CLI terminal tool Google Antigravity 2.0 release
  • Technology

Google Drops Antigravity 2.0 to Orchestrate Teams of Autonomous Coding Agents

Do Son May 20, 2026 0
Read More Read more about Google Drops Antigravity 2.0 to Orchestrate Teams of Autonomous Coding Agents
Zero-Trust Voice: Discord Finalizes Mandatory “DAVE” Encryption for All Audio and Video Streams DAVE protocol Discord DAVE protocol encryption
  • Technology

Zero-Trust Voice: Discord Finalizes Mandatory “DAVE” Encryption for All Audio and Video Streams

Do Son May 20, 2026 0
Read More Read more about Zero-Trust Voice: Discord Finalizes Mandatory “DAVE” Encryption for All Audio and Video Streams
Velvet Chollima Leaves Backend Keys Inside Critical GitLab Dead-Drop Malware Velvet Chollima GitLab Malware Tralert FX EV Certificate
  • Malware

Velvet Chollima Leaves Backend Keys Inside Critical GitLab Dead-Drop Malware

Do Son May 20, 2026 0
Read More Read more about Velvet Chollima Leaves Backend Keys Inside Critical GitLab Dead-Drop Malware
Kernel Chaos: Linus Torvalds Blasts “Drive-By” AI Bug Reports Paralyzing Linux Maintainers Linus Torvalds AI bug reports Linux Kernel 7.0 Linux EFI Zboot - CVE-2022-42719 Linux KVM Intel AMX kernel panic, KVM guest host crash 2025
  • Linux

Kernel Chaos: Linus Torvalds Blasts “Drive-By” AI Bug Reports Paralyzing Linux Maintainers

Do Son May 20, 2026 0
Read More Read more about Kernel Chaos: Linus Torvalds Blasts “Drive-By” AI Bug Reports Paralyzing Linux Maintainers
Kimsuky Core Upgrades Weaponize Rust Backdoors and VSCode Remote Tunneling Kimsuky HelloDoor Backdoor VSCode Tunneling Espionage
  • Malware

Kimsuky Core Upgrades Weaponize Rust Backdoors and VSCode Remote Tunneling

Do Son May 20, 2026 0
Read More Read more about Kimsuky Core Upgrades Weaponize Rust Backdoors and VSCode Remote Tunneling
Google Cloud Abruptly Shuts Down Railway, Sparking Catastrophic Infrastructure Outage Railway infrastructure outage GCP suspension 2026
  • Technology

Google Cloud Abruptly Shuts Down Railway, Sparking Catastrophic Infrastructure Outage

Do Son May 20, 2026 0
Read More Read more about Google Cloud Abruptly Shuts Down Railway, Sparking Catastrophic Infrastructure Outage
Inside the Breach: How TeamPCP Poisoned a VS Code Extension to Exfiltrate 3,800 GitHub Repositories GitHub source code breach TeamPCP 2026
  • Data Leak

Inside the Breach: How TeamPCP Poisoned a VS Code Extension to Exfiltrate 3,800 GitHub Repositories

Do Son May 20, 2026 0
Read More Read more about Inside the Breach: How TeamPCP Poisoned a VS Code Extension to Exfiltrate 3,800 GitHub Repositories
Multi-Stage PyInstaller Loader Weaponizes AMSI Patching to Deploy XWorm RAT NATS-as-C2 Sysdig CVE-2026-33017 Langflow RCE Microsoft Phone Link Hijack CloudZ Pheno Plugin Insider Threat BlackCat (ALPHV) OFAC Sanctions DPRK IT Workers Transparent Tribe APT36 React2Shell, EtherRAT SideWinder Espionage, Netlify Phishing DDNS Abuse, C2 Infrastructure Hacking Health Club
  • Malware

Multi-Stage PyInstaller Loader Weaponizes AMSI Patching to Deploy XWorm RAT

Do Son May 20, 2026 0
Read More Read more about Multi-Stage PyInstaller Loader Weaponizes AMSI Patching to Deploy XWorm RAT
The Missed Token: Grafana Labs Suffers Source Code Theft via Shai-Hulud npm Worm Campaign CVE-2023-1550 Grafana Labs Cyberattack Mini Shai-Hulud npm Worm
  • Data Leak

The Missed Token: Grafana Labs Suffers Source Code Theft via Shai-Hulud npm Worm Campaign

Do Son May 20, 2026 0
Read More Read more about The Missed Token: Grafana Labs Suffers Source Code Theft via Shai-Hulud npm Worm Campaign
Critical 9.2 CVSS: NGINX JavaScript Module Flaw (CVE-2026-8711) Triggers Heap Buffer Overflows NGINX JavaScript Module Vulnerability CVE-2026-8711 NGINX 1.30.1 Security Update CVE-2026-42945 RCE NGINX Vulnerability CVE-2026-1642 NGINX Github - CVE-2025-23419
  • Vulnerability Report

Critical 9.2 CVSS: NGINX JavaScript Module Flaw (CVE-2026-8711) Triggers Heap Buffer Overflows

Do Son May 20, 2026 0
Read More Read more about Critical 9.2 CVSS: NGINX JavaScript Module Flaw (CVE-2026-8711) Triggers Heap Buffer Overflows
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-0770CVSS 9.8
    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2021-27137CVSS 8.1
    An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2026-6875CVSS 9.5
    ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability...
    Admin intel📅 Updated: Jul 18, 2026
  • CVE-2026-39808CVSS 9.8
    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox...
    CISA KEV📅 Added to KEV: Jul 16, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-15704CVSS 9.8
    In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled...
  • CVE-2026-62825CVSS 10.0
    Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate...
  • CVE-2026-58275CVSS 10.0
    Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges...
  • CVE-2026-56191CVSS 10.0
    Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform...
  • CVE-2026-56165CVSS 9.8
    Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute...
  • CVE-2026-56160CVSS 9.1
    Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker...
  • CVE-2026-54120CVSS 9.9
    Improper input validation in Microsoft Surface allows an authorized attacker to execute...
  • CVE-2026-50517CVSS 9.9
    Deserialization of untrusted data in M365 Copilot allows an authorized attacker to...
  • CVE-2026-63359CVSS 9.8
    The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an...
  • CVE-2026-6516CVSS 10.0
    Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.