Skip to content
September 24, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
TELEPUZ Malware Spreads Through ClickFix and VIDAR Attacks TELEPUZ malware infection chain from a ClickFix attack through VIDAR to modular payload delivery
  • Malware

TELEPUZ Malware Spreads Through ClickFix and VIDAR Attacks

Do Son July 21, 2026 0
Read More Read more about TELEPUZ Malware Spreads Through ClickFix and VIDAR Attacks
ASUS Patches Router and PC Software Flaws, Including a CVSS 9.5 Command Execution Bug ASUS security advisories router firmware vulnerability CVE-2026-13385 command execution
  • Vulnerability Report

ASUS Patches Router and PC Software Flaws, Including a CVSS 9.5 Command Execution Bug

Do Son July 21, 2026 0
Read More Read more about ASUS Patches Router and PC Software Flaws, Including a CVSS 9.5 Command Execution Bug
Public PoC Released for CVE-2026-42980 Windows Privilege Escalation Flaw CVE-2026-42980 Windows privilege escalation flaw in kernel WMI granting SYSTEM access
  • Vulnerability Report

Public PoC Released for CVE-2026-42980 Windows Privilege Escalation Flaw

Do Son July 21, 2026 0
Read More Read more about Public PoC Released for CVE-2026-42980 Windows Privilege Escalation Flaw
Three SQL Injection Flaws Patched in Apache Fineract Core Banking Platform Apache Fineract SQL injection vulnerability affecting Office, Client, and report APIs
  • Vulnerability Report

Three SQL Injection Flaws Patched in Apache Fineract Core Banking Platform

Do Son July 21, 2026 0
Read More Read more about Three SQL Injection Flaws Patched in Apache Fineract Core Banking Platform
Zimbra 10.1.20 Patches an SNMP Command Injection Flaw and Multiple XSS Bugs Zimbra 10.1.20 security update patching Zimbra vulnerabilities including SNMP command injection and XSS
  • Vulnerability Report

Zimbra 10.1.20 Patches an SNMP Command Injection Flaw and Multiple XSS Bugs

Do Son July 21, 2026 0
Read More Read more about Zimbra 10.1.20 Patches an SNMP Command Injection Flaw and Multiple XSS Bugs
CVE-2026-50522 SharePoint RCE Flaw Exploited in the Wild With Public PoC Exploit CVE-2026-50522 SharePoint RCE vulnerability exploited in the wild with public PoC exploit
  • Vulnerability Report

CVE-2026-50522 SharePoint RCE Flaw Exploited in the Wild With Public PoC Exploit

Do Son July 21, 2026 0
Read More Read more about CVE-2026-50522 SharePoint RCE Flaw Exploited in the Wild With Public PoC Exploit
CVE-2026-49488: Arbitrary File Read Flaw in Apache OpenMeetings Exposes Server Credentials Apache OpenMeetings vulnerability CVE-2026-49488 arbitrary file read path traversal flaw
  • Vulnerability Report

CVE-2026-49488: Arbitrary File Read Flaw in Apache OpenMeetings Exposes Server Credentials

Do Son July 21, 2026 0
Read More Read more about CVE-2026-49488: Arbitrary File Read Flaw in Apache OpenMeetings Exposes Server Credentials
Project CAV3RN Hides Its C2 in Outlook Calendar Events to Spy on Israel Project CAV3RN cyberespionage framework using Outlook calendar C2 and Microsoft Graph
  • Cyber Security

Project CAV3RN Hides Its C2 in Outlook Calendar Events to Spy on Israel

Do Son July 21, 2026 0
Read More Read more about Project CAV3RN Hides Its C2 in Outlook Calendar Events to Spy on Israel
Microsoft UEFI CA 2023 Certificate Update Causes Widespread Issues UEFI CA 2023 update migration issues, Secure Boot certificate problems, Microsoft and OEM hardware compatibility
  • Technology

Microsoft UEFI CA 2023 Certificate Update Causes Widespread Issues

Do Son July 21, 2026 0
Read More Read more about Microsoft UEFI CA 2023 Certificate Update Causes Widespread Issues
OVH Patches CVE-2026-53359 KVM Flaw Across a Million VMs OVH data center engineers patching CVE-2026-53359 KVM vulnerability across thousands of hypervisor hosts
  • Vulnerability Report

OVH Patches CVE-2026-53359 KVM Flaw Across a Million VMs

Do Son July 21, 2026 0
Read More Read more about OVH Patches CVE-2026-53359 KVM Flaw Across a Million VMs
TuxBot v3 Evolution — an IoT Botnet Built With LLM Help TuxBot v3 Evolution IoT botnet C2 panel and cross-compilation build screen
  • Malware

TuxBot v3 Evolution — an IoT Botnet Built With LLM Help

Do Son July 21, 2026 0
Read More Read more about TuxBot v3 Evolution — an IoT Botnet Built With LLM Help
Nextcloud Website Suffers Cyberattack and Phishing Redirect Nextcloud website hacked showing unauthorized Cloudbox phishing redirect and wp2shell vulnerability.
  • Cybercriminals

Nextcloud Website Suffers Cyberattack and Phishing Redirect

Do Son July 21, 2026 0
Read More Read more about Nextcloud Website Suffers Cyberattack and Phishing Redirect
Claude Team Plan Now Starts at Just 2 Seats Claude Team plan dashboard highlighting the new two-seat minimum for small teams
  • Technology

Claude Team Plan Now Starts at Just 2 Seats

Do Son July 21, 2026 0
Read More Read more about Claude Team Plan Now Starts at Just 2 Seats
Threat Actor Rebuilt a Live Botnet in Six Minutes Using an AI Coding Agent AccountDumpling Phishing Google AppSheet Abuse AI-Generated Malware PureRAT Campaign RondoDoX Botnet, Next.js React2Shell EchoGather, Paper Werewolf Salt Typhoon, Telecom Espionage BreachForums, Conor Fitzpatrick Ransomware Negotiation, DOJ Investigation MirrorFace group - Earth Kasha Emperor Dragonfly
  • Cybercriminals

Threat Actor Rebuilt a Live Botnet in Six Minutes Using an AI Coding Agent

Do Son July 21, 2026 0
Read More Read more about Threat Actor Rebuilt a Live Botnet in Six Minutes Using an AI Coding Agent
ClickLock Stealer Locks macOS Screens Until Victims Hand Over Their Password ClickLock Stealer macOS malware fake Cloudflare ClickFix Terminal prompt stealing passwords
  • Malware

ClickLock Stealer Locks macOS Screens Until Victims Hand Over Their Password

Do Son July 21, 2026 0
Read More Read more about ClickLock Stealer Locks macOS Screens Until Victims Hand Over Their Password
White House Launches GOLD EAGLE Initiative to Speed Vulnerability Patching GOLD EAGLE initiative dashboard for U.S. cybersecurity vulnerability coordination
  • Technology

White House Launches GOLD EAGLE Initiative to Speed Vulnerability Patching

Do Son July 21, 2026 0
Read More Read more about White House Launches GOLD EAGLE Initiative to Speed Vulnerability Patching
Qilin Ransomware Deployed via Palo Alto GlobalProtect Flaw CVE-2026-0257 Qilin ransomware attack chain starting with a Palo Alto GlobalProtect CVE-2026-0257 authentication bypass
  • Cybercriminals

Qilin Ransomware Deployed via Palo Alto GlobalProtect Flaw CVE-2026-0257

Do Son July 21, 2026 0
Read More Read more about Qilin Ransomware Deployed via Palo Alto GlobalProtect Flaw CVE-2026-0257
Linux Kernel Publishes 440 CVE Advisories in 24 Hours as AI Accelerates Bug Hunting 440 Linux kernel CVEs published in 24 hours amid AI-driven vulnerability discovery
  • Linux

Linux Kernel Publishes 440 CVE Advisories in 24 Hours as AI Accelerates Bug Hunting

Do Son July 21, 2026 0
Read More Read more about Linux Kernel Publishes 440 CVE Advisories in 24 Hours as AI Accelerates Bug Hunting
LG Monitors Auto-Install Adware Through Windows Device Metadata LG monitor adware pop-up promoting McAfee on a Windows desktop via device metadata
  • Malware

LG Monitors Auto-Install Adware Through Windows Device Metadata

Do Son July 21, 2026 0
Read More Read more about LG Monitors Auto-Install Adware Through Windows Device Metadata
wp2shell: WordPress Core RCE Exploited in the Wild as Public PoC Code Circulates wp2shell exploit chain achieving WordPress Core RCE via CVE-2026-63030 and CVE-2026-60137 batch API abuse
  • Vulnerability Report

wp2shell: WordPress Core RCE Exploited in the Wild as Public PoC Code Circulates

Do Son July 21, 2026 0
Read More Read more about wp2shell: WordPress Core RCE Exploited in the Wild as Public PoC Code Circulates
Why Smart Logistics Needs Better Technology  tech
  • Technique

Why Smart Logistics Needs Better Technology 

Do Son July 21, 2026 0
Read More Read more about Why Smart Logistics Needs Better Technology 
United States Seizes More Than 1,000 Domains Streaming World Cup 2026 Matches Website Seizure Graphic
  • Cybercriminals

United States Seizes More Than 1,000 Domains Streaming World Cup 2026 Matches

Do Son July 20, 2026 0
Read More Read more about United States Seizes More Than 1,000 Domains Streaming World Cup 2026 Matches
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-94127CVSS 9.8
    When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-85102CVSS 9.8
    Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93616CVSS 9.8
    A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93952CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-32996CVSS 7.3
    A vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.
    Admin intel📅 Updated: Sep 22, 2026
  • CVE-2026-7273CVSS 8.8
    A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a...
    CISA KEV📅 Added to KEV: Sep 21, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-78312CVSS 9.1
    Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
    📅 Updated: Sep 24, 2026
  • CVE-2026-78308CVSS 9.8
    Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022.
    📅 Updated: Sep 24, 2026
  • CVE-2026-84502CVSS 9.9
    A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not...
    📅 Updated: Sep 24, 2026
  • CVE-2026-84719CVSS 9.9
    A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission...
    📅 Updated: Sep 24, 2026
  • CVE-2026-84474CVSS 9.9
    A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed...
    📅 Updated: Sep 24, 2026
  • CVE-2026-75884CVSS 9.1
    A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts...
    📅 Updated: Sep 24, 2026
  • CVE-2026-12564CVSS 9.6
    A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads...
    📅 Updated: Sep 24, 2026
  • CVE-2026-86708CVSS 10.0
    ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private...
    📅 Updated: Sep 24, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.