Skip to content
September 24, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Apache Syncope Patches SQL Injection and Privilege Escalation Flaws Apache Syncope vulnerabilities including a privilege escalation flaw fixed in CVE-2026-57308 and CVE-2026-62183
  • Vulnerability Report

Apache Syncope Patches SQL Injection and Privilege Escalation Flaws

Do Son July 23, 2026 0
Read More Read more about Apache Syncope Patches SQL Injection and Privilege Escalation Flaws
CVE-2026-57239: Public PoC Exploits Foxit PDF Reader Vulnerability for SYSTEM Privileges Foxit PDF Reader vulnerability CVE-2026-57239 exploited for SYSTEM privileges via local privilege escalation
  • Vulnerability Report

CVE-2026-57239: Public PoC Exploits Foxit PDF Reader Vulnerability for SYSTEM Privileges

Do Son July 23, 2026 0
Read More Read more about CVE-2026-57239: Public PoC Exploits Foxit PDF Reader Vulnerability for SYSTEM Privileges
Next.js Patches Three CVSS 8.3 Flaws in Rewrites, Server Actions, and Middleware Next.js vulnerabilities diagram showing Server-Side Request Forgery through rewrites and Server Actions in CVE-2026-64645 and CVE-2026-64649
  • Vulnerability Report

Next.js Patches Three CVSS 8.3 Flaws in Rewrites, Server Actions, and Middleware

Do Son July 23, 2026 0
Read More Read more about Next.js Patches Three CVSS 8.3 Flaws in Rewrites, Server Actions, and Middleware
Unpatched SGLang Flaw CVE-2026-14890 Allows Unauthenticated Remote Code Execution SGLang vulnerability CVE-2026-14890 enabling unauthenticated remote code execution via pickle deserialization
  • Vulnerability Report

Unpatched SGLang Flaw CVE-2026-14890 Allows Unauthenticated Remote Code Execution

Do Son July 23, 2026 0
Read More Read more about Unpatched SGLang Flaw CVE-2026-14890 Allows Unauthenticated Remote Code Execution
Canonical Launches the Enterprise Store for Air-Gapped Networks Canonical Enterprise Store architecture diagram showing software distribution in air-gapped enterprise environments
  • Linux

Canonical Launches the Enterprise Store for Air-Gapped Networks

Do Son July 23, 2026 0
Read More Read more about Canonical Launches the Enterprise Store for Air-Gapped Networks
New 10-Inch Raspberry Pi Touch Display 2 Costs $80 Raspberry Pi Touch Display 2 in the 10-inch size showing its 1200x1920 portrait panel connected to a Raspberry Pi 5
  • Technology

New 10-Inch Raspberry Pi Touch Display 2 Costs $80

Do Son July 23, 2026 0
Read More Read more about New 10-Inch Raspberry Pi Touch Display 2 Costs $80
Dolphin X Stealer Sold on a Cybercrime Forum Uses an AI Profiler to Rank Victims Trojanized streaming site causing Packagist themes iOS spyware infections
  • Cybercriminals

Dolphin X Stealer Sold on a Cybercrime Forum Uses an AI Profiler to Rank Victims

Do Son July 23, 2026 0
Read More Read more about Dolphin X Stealer Sold on a Cybercrime Forum Uses an AI Profiler to Rank Victims
Google’s Nuvem Subsea Cable Links US and Portugal Nuvem subsea cable route linking Myrtle Beach South Carolina to Sines Portugal via Bermuda and the Azores with 384 Tbps capacity
  • Technology

Google’s Nuvem Subsea Cable Links US and Portugal

Do Son July 23, 2026 0
Read More Read more about Google’s Nuvem Subsea Cable Links US and Portugal
Apple Patches Hide My Email Vulnerability at Last Hide My Email vulnerability in Apple iCloud+ exposing real email addresses behind randomly generated forwarding aliases
  • Vulnerability Report

Apple Patches Hide My Email Vulnerability at Last

Do Son July 23, 2026 0
Read More Read more about Apple Patches Hide My Email Vulnerability at Last
GitHub Overhauls Bug Bounty Program with New VIP Tier GitHub bug bounty program restructuring flowchart, VIP security researcher reward tiers
  • Technology

GitHub Overhauls Bug Bounty Program with New VIP Tier

Do Son July 23, 2026 0
Read More Read more about GitHub Overhauls Bug Bounty Program with New VIP Tier
GST Phishing Campaign Distributes Remcos RAT Malware DPRK IT Workers, APT38 Crypto Forfeiture
  • Malware

GST Phishing Campaign Distributes Remcos RAT Malware

Do Son July 23, 2026 0
Read More Read more about GST Phishing Campaign Distributes Remcos RAT Malware
Google Enhances iOS to Android Migration Tool Upgraded Google iOS to Android migration tool interface displaying eSIM data transfer options
  • Android

Google Enhances iOS to Android Migration Tool

Do Son July 23, 2026 0
Read More Read more about Google Enhances iOS to Android Migration Tool
HelloNet Campaign Abuses ViPNet Update System to Hit Russian Firms HelloNet campaign malware delivered through the ViPNet update system on a Russian workstation
  • Cybercriminals

HelloNet Campaign Abuses ViPNet Update System to Hit Russian Firms

Do Son July 23, 2026 0
Read More Read more about HelloNet Campaign Abuses ViPNet Update System to Hit Russian Firms
DoNot APT Targets Bangladesh Military With a Fake Officer Biography CRussian Market, "Fly" (Flyded) hange Healthcare Cyberattack - CVE-2024-50603 Exploit
  • Cybercriminals

DoNot APT Targets Bangladesh Military With a Fake Officer Biography

Do Son July 23, 2026 0
Read More Read more about DoNot APT Targets Bangladesh Military With a Fake Officer Biography
GitHub Actions Abuse Powers a Distributed cPanel and WHM Attack Campaign WhatsApp Worm, Brazilian Banking Trojan LAPSUS$ Alliance, Scattered Spider Ransomware, Cybercrime RedCurl APT group Russian Cyberespionage, ApolloShadow Malware
  • Cybercriminals

GitHub Actions Abuse Powers a Distributed cPanel and WHM Attack Campaign

Do Son July 23, 2026 0
Read More Read more about GitHub Actions Abuse Powers a Distributed cPanel and WHM Attack Campaign
ISC Patches 9 BIND 9 Vulnerabilities, Including a DNSSEC Cache Poisoning Flaw BIND vulnerability advisory chart listing nine DNSSEC flaws including CVE-2026-13321 cache poisoning fixed in BIND 9.20.26 and 9.21.24
  • Vulnerability Report

ISC Patches 9 BIND 9 Vulnerabilities, Including a DNSSEC Cache Poisoning Flaw

Do Son July 23, 2026 0
Read More Read more about ISC Patches 9 BIND 9 Vulnerabilities, Including a DNSSEC Cache Poisoning Flaw
600K Sites at Risk: Ninja Forms Stored XSS Flaw CVE-2026-65048 Hits CVSS 9.3 Ninja Forms vulnerability dashboard showing CVE-2026-65048 unauthenticated stored XSS with a CVSS 9.3 score across 600K WordPress sites
  • Vulnerability Report

600K Sites at Risk: Ninja Forms Stored XSS Flaw CVE-2026-65048 Hits CVSS 9.3

Do Son July 23, 2026 0
Read More Read more about 600K Sites at Risk: Ninja Forms Stored XSS Flaw CVE-2026-65048 Hits CVSS 9.3
RefluXFS CVE-2026-64600: XFS Root Privilege Escalation Hits 16.4M Systems RefluXFS CVE-2026-64600 XFS privilege escalation to root diagram showing a reflink direct-I/O race overwriting a protected file across 16.4 million Linux systems
  • Vulnerability Report

RefluXFS CVE-2026-64600: XFS Root Privilege Escalation Hits 16.4M Systems

Do Son July 22, 2026 0
Read More Read more about RefluXFS CVE-2026-64600: XFS Root Privilege Escalation Hits 16.4M Systems
Check Point SmartConsole Auth Bypass CVE-2026-16232 Exploited in the Wild Check Point SmartConsole authentication bypass CVE-2026-16232 exploited in the wild against internet-exposed Management servers
  • Vulnerability Report

Check Point SmartConsole Auth Bypass CVE-2026-16232 Exploited in the Wild

Do Son July 22, 2026 0
Read More Read more about Check Point SmartConsole Auth Bypass CVE-2026-16232 Exploited in the Wild
Exim Directory Traversal Flaw Enables Privilege Escalation, Fixed in 4.99.5 Exim vulnerability diagram showing a directory traversal that escapes the spool area and leads to local privilege escalation
  • Vulnerability Report

Exim Directory Traversal Flaw Enables Privilege Escalation, Fixed in 4.99.5

Do Son July 22, 2026 0
Read More Read more about Exim Directory Traversal Flaw Enables Privilege Escalation, Fixed in 4.99.5
Public PoC Exploit Exposes CVE-2026-44421 FreeRDP Heap Buffer Overflow to Remote Code Execution FreeRDP heap buffer overflow vulnerability CVE-2026-44421 CVE-2026-44422 CVE-2026-40033 diagram
  • Vulnerability Report

Public PoC Exploit Exposes CVE-2026-44421 FreeRDP Heap Buffer Overflow to Remote Code Execution

Do Son July 22, 2026 0
Read More Read more about Public PoC Exploit Exposes CVE-2026-44421 FreeRDP Heap Buffer Overflow to Remote Code Execution
Spirals Ransomware Encrypts a South Asian IT Network in Under 24 Hours Spirals ransomware double extortion attack chain from IIS web shell to network encryption
  • Malware

Spirals Ransomware Encrypts a South Asian IT Network in Under 24 Hours

Do Son July 22, 2026 0
Read More Read more about Spirals Ransomware Encrypts a South Asian IT Network in Under 24 Hours
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-94127CVSS 9.8
    When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-85102CVSS 9.8
    Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93616CVSS 9.8
    A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93952CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-32996CVSS 7.3
    A vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.
    Admin intel📅 Updated: Sep 22, 2026
  • CVE-2026-7273CVSS 8.8
    A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a...
    CISA KEV📅 Added to KEV: Sep 21, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-78312CVSS 9.1
    Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
    📅 Updated: Sep 24, 2026
  • CVE-2026-78308CVSS 9.8
    Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022.
    📅 Updated: Sep 24, 2026
  • CVE-2026-84502CVSS 9.9
    A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not...
    📅 Updated: Sep 24, 2026
  • CVE-2026-84719CVSS 9.9
    A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission...
    📅 Updated: Sep 24, 2026
  • CVE-2026-84474CVSS 9.9
    A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed...
    📅 Updated: Sep 24, 2026
  • CVE-2026-75884CVSS 9.1
    A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts...
    📅 Updated: Sep 24, 2026
  • CVE-2026-12564CVSS 9.6
    A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads...
    📅 Updated: Sep 24, 2026
  • CVE-2026-86708CVSS 10.0
    ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private...
    📅 Updated: Sep 24, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.