Skip to content
September 15, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • Encoder & Hash Generator
    • IP / Subnet Calculator
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
FreeBSD Security Advisories Detail Critical Vulnerabilities Diagram of system vulnerabilities detailed in FreeBSD security advisories including CVE-2026-49420, CVE-2026-49429, and CVE-2026-49422
  • Vulnerability Report

FreeBSD Security Advisories Detail Critical Vulnerabilities

Do Son July 6, 2026 0
Read More Read more about FreeBSD Security Advisories Detail Critical Vulnerabilities
Kerberos Reflection Bypass CVE-2026-26128 Gets Public PoC Exploit Kerberos reflection CVE-2026-26128 SMB SYSTEM privilege escalation Windows Unicode SPN PoC exploit
  • Vulnerability Report

Kerberos Reflection Bypass CVE-2026-26128 Gets Public PoC Exploit

Do Son July 6, 2026 0
Read More Read more about Kerberos Reflection Bypass CVE-2026-26128 Gets Public PoC Exploit
ModSecurity Vulnerabilities Let Attackers Bypass WAF Rules ModSecurity vulnerabilities enabling WAF bypass via multipart parser and utf8toUnicode flaws (CVE-2026-52747, CVE-2026-52761)
  • Vulnerability Report

ModSecurity Vulnerabilities Let Attackers Bypass WAF Rules

Do Son July 6, 2026 0
Read More Read more about ModSecurity Vulnerabilities Let Attackers Bypass WAF Rules
FBI Warns of TeamPCP Supply Chain Attack TeamPCP supply chain attack and software supply chain compromise alert
  • Cybercriminals

FBI Warns of TeamPCP Supply Chain Attack

Do Son July 4, 2026 0
Read More Read more about FBI Warns of TeamPCP Supply Chain Attack
Critical Security Flaws Found in Langflow OSS Diagram illustrating Langflow OSS vulnerabilities and CVE-2026-10134 execution paths
  • Vulnerability Report

Critical Security Flaws Found in Langflow OSS

Do Son July 4, 2026 0
Read More Read more about Critical Security Flaws Found in Langflow OSS
DCMTK Vulnerabilities Expose Medical Imaging Systems to File Write and DoS DCMTK vulnerabilities enabling path traversal file write in the DICOM toolkit (CVE-2026-50003)
  • Vulnerability Report

DCMTK Vulnerabilities Expose Medical Imaging Systems to File Write and DoS

Do Son July 4, 2026 0
Read More Read more about DCMTK Vulnerabilities Expose Medical Imaging Systems to File Write and DoS
GitHub CD-ROM Repository: Physical Code Discs GitHub CD-ROM repository physical code disc campaign commemoration
  • Technology

GitHub CD-ROM Repository: Physical Code Discs

Do Son July 3, 2026 0
Read More Read more about GitHub CD-ROM Repository: Physical Code Discs
Claude Fable 5 Subscription: Credits Required for Access Claude Fable 5 subscription model and credit purchase prompt interface
  • Technology

Claude Fable 5 Subscription: Credits Required for Access

Do Son July 3, 2026 0
Read More Read more about Claude Fable 5 Subscription: Credits Required for Access
Chrome Prepares to Auto-Pin Extensions to Toolbar Google Chrome settings page showcasing the new auto-pin extensions option for toolbars
  • Technology

Chrome Prepares to Auto-Pin Extensions to Toolbar

Do Son July 3, 2026 0
Read More Read more about Chrome Prepares to Auto-Pin Extensions to Toolbar
Claude Fable 5 Auto-Downgrades Tasks It Deems Too Simple Logs Prove It Claude Fable 5 model classifier downgrade log showing TOO_DUMB_TO_NEED_FABLE flag
  • Technology

Claude Fable 5 Auto-Downgrades Tasks It Deems Too Simple Logs Prove It

Do Son July 3, 2026 0
Read More Read more about Claude Fable 5 Auto-Downgrades Tasks It Deems Too Simple Logs Prove It
Lazarus-Linked npm Malware Masquerades as Rollup Polyfills Lazarus npm malware masquerading as Rollup polyfill packages in a supply chain attack
  • Cybercriminals

Lazarus-Linked npm Malware Masquerades as Rollup Polyfills

Do Son July 3, 2026 0
Read More Read more about Lazarus-Linked npm Malware Masquerades as Rollup Polyfills
Silent Swap Crypto Clipper Hides in Google Notes Extension Diagram showing the Silent Swap crypto clipper and Google Notes extension infection chain
  • Malware

Silent Swap Crypto Clipper Hides in Google Notes Extension

Do Son July 3, 2026 0
Read More Read more about Silent Swap Crypto Clipper Hides in Google Notes Extension
kernel.org Outage: Config Error Wipes All Linux Kernel Files kernel.org outage HTTP 404 error caused by Linux Foundation mirror configuration failure
  • Technology

kernel.org Outage: Config Error Wipes All Linux Kernel Files

Do Son July 3, 2026 0
Read More Read more about kernel.org Outage: Config Error Wipes All Linux Kernel Files
EU Court Upholds €4.1 Billion Google Android Antitrust Fine EU Court upholds Google Android antitrust fine of 4.1 billion euros in landmark ruling
  • Technology

EU Court Upholds €4.1 Billion Google Android Antitrust Fine

Do Son July 3, 2026 0
Read More Read more about EU Court Upholds €4.1 Billion Google Android Antitrust Fine
Glitch SPY Android RAT Spreads Through a Fake Polish Rental App Glitch SPY Android RAT distributed through a fake Polish rental app abusing Accessibility Service
  • Malware

Glitch SPY Android RAT Spreads Through a Fake Polish Rental App

Do Son July 3, 2026 0
Read More Read more about Glitch SPY Android RAT Spreads Through a Fake Polish Rental App
ToddyCat APT Umbrij Tool Steals Cloud Email Tokens Diagram of ToddyCat APT Umbrij tool performing OAuth token theft from Chrome
  • Cybercriminals

ToddyCat APT Umbrij Tool Steals Cloud Email Tokens

Do Son July 3, 2026 0
Read More Read more about ToddyCat APT Umbrij Tool Steals Cloud Email Tokens
Active ColdFusion Arbitrary Code Execution Flaw Scores CVSS 10 Diagram showing ColdFusion arbitrary code execution path traversal vulnerability.
  • Vulnerability Report

Active ColdFusion Arbitrary Code Execution Flaw Scores CVSS 10

Do Son July 3, 2026 0
Read More Read more about Active ColdFusion Arbitrary Code Execution Flaw Scores CVSS 10
Public PoC Code Exposes CVSS 9.8 Control Web Panel SQL Injection CVE-2026-57517 Diagram of the Control Web Panel SQLi exploit mechanism for CVE-2026-57517.
  • Vulnerability Report

Public PoC Code Exposes CVSS 9.8 Control Web Panel SQL Injection CVE-2026-57517

Do Son July 3, 2026 0
Read More Read more about Public PoC Code Exposes CVSS 9.8 Control Web Panel SQL Injection CVE-2026-57517
UltraVNC Repeater Vulnerabilities Allow Remote Code Execution UltraVNC repeater vulnerabilities enabling arbitrary code execution and hardcoded-password admin access (CVE-2026-7839, CVE-2026-7840)
  • Vulnerability Report

UltraVNC Repeater Vulnerabilities Allow Remote Code Execution

Do Son July 3, 2026 0
Read More Read more about UltraVNC Repeater Vulnerabilities Allow Remote Code Execution
WatchGuard Firebox Vulnerabilities Include Critical Unauthenticated RCE Flaw WatchGuard Firebox vulnerabilities CVE-2026-13368 use-after-free remote code execution advisory
  • Vulnerability Report

WatchGuard Firebox Vulnerabilities Include Critical Unauthenticated RCE Flaw

Do Son July 3, 2026 0
Read More Read more about WatchGuard Firebox Vulnerabilities Include Critical Unauthenticated RCE Flaw
Apache ActiveMQ Vulnerabilities Allow Denial of Service and Takeover Apache ActiveMQ vulnerabilities causing denial of service and temporary destination takeover (CVE-2026-54475)
  • Vulnerability Report

Apache ActiveMQ Vulnerabilities Allow Denial of Service and Takeover

Do Son July 3, 2026 0
Read More Read more about Apache ActiveMQ Vulnerabilities Allow Denial of Service and Takeover
Icinga 2 Vulnerabilities Allow Unauthenticated Node Takeover Icinga 2 vulnerabilities enabling unauthenticated node takeover and process crash, fixed in v2.16.2
  • Vulnerability Report

Icinga 2 Vulnerabilities Allow Unauthenticated Node Takeover

Do Son July 3, 2026 0
Read More Read more about Icinga 2 Vulnerabilities Allow Unauthenticated Node Takeover
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-87827CVSS 10.0
    Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-78006CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-39364
    Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-27540CVSS 9.0
    Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-76461CVSS 9.8
    A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an...
    CISA KEV📅 Added to KEV: Sep 14, 2026
  • CVE-2026-51990
    A critical remote code execution vulnerability in Sogou Input Method, one of the most widely used Chinese-language input...
    Admin intel📅 Updated: Sep 12, 2026
  • CVE-2026-85706CVSS 10.0
    GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42016CVSS 8.1
    JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-90847CVSS 9.1
    A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element...
  • CVE-2026-12944CVSS 9.6
    IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary...
  • CVE-2026-67399CVSS 9.3
    Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before...
  • CVE-2026-65414CVSS 9.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue...
  • CVE-2026-16338CVSS 9.9
    IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow...
  • CVE-2026-59178CVSS 9.8
    ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management...
  • CVE-2026-90945CVSS 9.8
    Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing...
  • CVE-2026-90942CVSS 9.6
    Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private...
  • CVE-2026-76461CVSS 9.8
    A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco...
  • CVE-2026-76443CVSS 9.8
    As part of Cisco's ongoing commitment to proactive security and product quality,...
Powered by CVE WATCHTOWER

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.