Skip to content
September 24, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
CVE-2026-58443: Gitea Flaw (CVSS 9.6) Details and PoC Exploit Code Publicly Disclosed Gitea vulnerability CVE-2026-58443 public-only token writing to private repository
  • Vulnerability Report

CVE-2026-58443: Gitea Flaw (CVSS 9.6) Details and PoC Exploit Code Publicly Disclosed

Do Son July 20, 2026 0
Read More Read more about CVE-2026-58443: Gitea Flaw (CVSS 9.6) Details and PoC Exploit Code Publicly Disclosed
OAuth Client ID Spoofing Lets Attackers Enumerate Entra ID Accounts Without a Trace OAuth client ID spoofing enabling stealthy account enumeration against Microsoft Entra ID sign-in logs
  • Cybercriminals

OAuth Client ID Spoofing Lets Attackers Enumerate Entra ID Accounts Without a Trace

Do Son July 20, 2026 0
Read More Read more about OAuth Client ID Spoofing Lets Attackers Enumerate Entra ID Accounts Without a Trace
Critical Apache Doris Flaw (CVE-2026-58319) Exposes Admin APIs to Unauthenticated Attackers Apache Doris vulnerability CVE-2026-58319 improper authentication in Frontend HTTP API
  • Vulnerability Report

Critical Apache Doris Flaw (CVE-2026-58319) Exposes Admin APIs to Unauthenticated Attackers

Do Son July 20, 2026 0
Read More Read more about Critical Apache Doris Flaw (CVE-2026-58319) Exposes Admin APIs to Unauthenticated Attackers
CVE-2026-56451: CVSS 10 Siemens Opcenter X Flaw Grants Full Unauthorized Access Siemens Opcenter X authentication bypass vulnerability CVE-2026-56451 JWT forgery
  • Vulnerability Report

CVE-2026-56451: CVSS 10 Siemens Opcenter X Flaw Grants Full Unauthorized Access

Do Son July 20, 2026 0
Read More Read more about CVE-2026-56451: CVSS 10 Siemens Opcenter X Flaw Grants Full Unauthorized Access
HOLLOWGRAPH Malware Hides Command-and-Control in Microsoft 365 Calendars HOLLOWGRAPH malware using Microsoft Graph API abuse to hide command-and-control inside a Microsoft 365 calendar event dated 2050
  • Malware

HOLLOWGRAPH Malware Hides Command-and-Control in Microsoft 365 Calendars

Do Son July 20, 2026 0
Read More Read more about HOLLOWGRAPH Malware Hides Command-and-Control in Microsoft 365 Calendars
CrashStealer: New macOS Infostealer Poses as Apple Crash Reporter to Steal Wallets and Passwords CrashStealer macOS infostealer posing as Apple crash reporter to steal browser and crypto wallet data
  • Malware

CrashStealer: New macOS Infostealer Poses as Apple Crash Reporter to Steal Wallets and Passwords

Do Son July 20, 2026 0
Read More Read more about CrashStealer: New macOS Infostealer Poses as Apple Crash Reporter to Steal Wallets and Passwords
Operation ShadowRecruit Uses Fake Government Job Ads to Plant SheetAgent RAT on Indian Systems Salt Typhoon Teleco Hack, Cisco Academy Link CVE-2025-0282 PoC exploit
  • Cybercriminals

Operation ShadowRecruit Uses Fake Government Job Ads to Plant SheetAgent RAT on Indian Systems

Do Son July 20, 2026 0
Read More Read more about Operation ShadowRecruit Uses Fake Government Job Ads to Plant SheetAgent RAT on Indian Systems
LabubaRAT Poses as NVIDIA Software to Hand Operators Full Control of Windows Hosts Exploited VMware
  • Malware

LabubaRAT Poses as NVIDIA Software to Hand Operators Full Control of Windows Hosts

Do Son July 20, 2026 0
Read More Read more about LabubaRAT Poses as NVIDIA Software to Hand Operators Full Control of Windows Hosts
Codex Cuts Its Context Window to 272K and Forbids rm -rf $HOME After Home-Directory Deletions Codex context window change: OpenAI lowers the limit to 272K and forbids rm -rf $HOME in the system prompt after deletions
  • Technology

Codex Cuts Its Context Window to 272K and Forbids rm -rf $HOME After Home-Directory Deletions

Do Son July 20, 2026 0
Read More Read more about Codex Cuts Its Context Window to 272K and Forbids rm -rf $HOME After Home-Directory Deletions
Microsoft Ships KB5121767 Out-of-Band Update to Fix a Dell USB-C Compatibility Fault KB5121767 out-of-band update: Microsoft fix for the Dell USB-C driver compatibility fault on affected Precision and XPS laptops
  • Windows

Microsoft Ships KB5121767 Out-of-Band Update to Fix a Dell USB-C Compatibility Fault

Do Son July 20, 2026 0
Read More Read more about Microsoft Ships KB5121767 Out-of-Band Update to Fix a Dell USB-C Compatibility Fault
The Mac Pro That Never Shipped: Apple Secretly Built a New Intel Model and Killed Its “Extreme” Chips Mac Pro discontinuation: Apple's cheese-grater tower retired as the Mac Studio and Apple Silicon take over professional workflows
  • Technology

The Mac Pro That Never Shipped: Apple Secretly Built a New Intel Model and Killed Its “Extreme” Chips

Do Son July 20, 2026 0
Read More Read more about The Mac Pro That Never Shipped: Apple Secretly Built a New Intel Model and Killed Its “Extreme” Chips
Mid-July 2026: Weekly Threat Intelligence Report actively exploited vulnerabilities
  • Weekly Recap

Mid-July 2026: Weekly Threat Intelligence Report

Do Son July 20, 2026 0
Read More Read more about Mid-July 2026: Weekly Threat Intelligence Report
CVE-2026-52824: Default Docker Secret in Kimai Enables Account Takeover of Super Admin Accounts Kimai vulnerability CVE-2026-52824 account takeover via default Docker APP_SECRET
  • Vulnerability Report

CVE-2026-52824: Default Docker Secret in Kimai Enables Account Takeover of Super Admin Accounts

Do Son July 20, 2026 0
Read More Read more about CVE-2026-52824: Default Docker Secret in Kimai Enables Account Takeover of Super Admin Accounts
Why Network Teams Are Pulling Routing Intelligence Back In-House why
  • Technique

Why Network Teams Are Pulling Routing Intelligence Back In-House

Do Son July 20, 2026 0
Read More Read more about Why Network Teams Are Pulling Routing Intelligence Back In-House
OpenSSL HollowByte Vulnerability Causes Memory Exhaustion Diagram explaining the OpenSSL HollowByte vulnerability and OpenSSL DoS attack mechanism
  • Vulnerability Report

OpenSSL HollowByte Vulnerability Causes Memory Exhaustion

Do Son July 20, 2026 0
Read More Read more about OpenSSL HollowByte Vulnerability Causes Memory Exhaustion
SonicWall SMA Zero-Day Chain Roots VPN Appliances and Plants Hidden Malware SonicWall SMA zero-day exploit chain compromising SMA VPN appliances to deploy malware
  • Cybercriminals

SonicWall SMA Zero-Day Chain Roots VPN Appliances and Plants Hidden Malware

Do Son July 19, 2026 0
Read More Read more about SonicWall SMA Zero-Day Chain Roots VPN Appliances and Plants Hidden Malware
US Justice Department Approves TikTok for Government Devices DOJ lifts TikTok ban for federal workers and allows government downloads
  • Technology

US Justice Department Approves TikTok for Government Devices

Do Son July 18, 2026 0
Read More Read more about US Justice Department Approves TikTok for Government Devices
Hugging Face Discloses Production Breach Driven by an Autonomous AI Agent Hugging Face breach driven by an autonomous AI agent attack exposing internal datasets and credentials
  • Data Leak

Hugging Face Discloses Production Breach Driven by an Autonomous AI Agent

Do Son July 18, 2026 0
Read More Read more about Hugging Face Discloses Production Breach Driven by an Autonomous AI Agent
Meta and Anthropic Negotiate Computing Power Lease Meta AI computing power lease and Anthropic data center negotiations
  • Technology

Meta and Anthropic Negotiate Computing Power Lease

Do Son July 18, 2026 0
Read More Read more about Meta and Anthropic Negotiate Computing Power Lease
Claude Fable 5 Subscription Changes Announced Claude Fable 5 subscription updates and AI computational limitations
  • Technology

Claude Fable 5 Subscription Changes Announced

Do Son July 18, 2026 0
Read More Read more about Claude Fable 5 Subscription Changes Announced
Active Exploitation and Public PoC Disclosed for CVE-2026-6875 ServiceNow Sandbox Escape Remote Code Execution Diagram of CVE-2026-6875 ServiceNow sandbox escape RCE and pre-auth code execution
  • Vulnerability Report

Active Exploitation and Public PoC Disclosed for CVE-2026-6875 ServiceNow Sandbox Escape Remote Code Execution

Do Son July 18, 2026 0
Read More Read more about Active Exploitation and Public PoC Disclosed for CVE-2026-6875 ServiceNow Sandbox Escape Remote Code Execution
Cloudflare Blocks Critical WordPress wp2shell Vulnerability Cloudflare firewall blocking the critical WordPress wp2shell vulnerability and RCE attacks
  • Vulnerability Report

Cloudflare Blocks Critical WordPress wp2shell Vulnerability

Do Son July 18, 2026 0
Read More Read more about Cloudflare Blocks Critical WordPress wp2shell Vulnerability
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-94127CVSS 9.8
    When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-85102CVSS 9.8
    Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93616CVSS 9.8
    A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93952CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-32996CVSS 7.3
    A vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.
    Admin intel📅 Updated: Sep 22, 2026
  • CVE-2026-7273CVSS 8.8
    A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a...
    CISA KEV📅 Added to KEV: Sep 21, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-19072CVSS 9.9
    Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for...
    📅 Updated: Sep 24, 2026
  • CVE-2026-94097CVSS 10.0
    A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of...
    📅 Updated: Sep 24, 2026
  • CVE-2026-94003CVSS 10.0
    A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /cgi-bin/mbox-config...
    📅 Updated: Sep 24, 2026
  • CVE-2026-12227CVSS 9.8
    The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up...
    📅 Updated: Sep 24, 2026
  • CVE-2026-78312CVSS 9.1
    Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
    📅 Updated: Sep 24, 2026
  • CVE-2026-78308CVSS 9.8
    Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022.
    📅 Updated: Sep 24, 2026
  • CVE-2026-84502CVSS 9.9
    A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not...
    📅 Updated: Sep 24, 2026
  • CVE-2026-84719CVSS 9.9
    A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission...
    📅 Updated: Sep 24, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.