Skip to content
September 15, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
ErrTraffic Malware Spreads ClickFix Lures via Hacked WordPress Sites Spirals ransomware double extortion attack chain from IIS web shell to network encryption
  • Malware

ErrTraffic Malware Spreads ClickFix Lures via Hacked WordPress Sites

Do Son June 22, 2026 0
Read More Read more about ErrTraffic Malware Spreads ClickFix Lures via Hacked WordPress Sites
Avo Flaw CVE-2026-55518 Enables Privilege Escalation in Rails Apps Avo authorization bypass CVE-2026-55518 enabling privilege escalation in a Ruby on Rails admin panel
  • Vulnerability Report

Avo Flaw CVE-2026-55518 Enables Privilege Escalation in Rails Apps

Do Son June 22, 2026 0
Read More Read more about Avo Flaw CVE-2026-55518 Enables Privilege Escalation in Rails Apps
Three Critical pgAdmin 4 Vulnerabilities Patched: XSS, Auth Bypass, and AI Assistant SQLi pgAdmin 4 vulnerabilities CVE-2026-12046 stored XSS and RCE in PostgreSQL admin tool
  • Vulnerability Report

Three Critical pgAdmin 4 Vulnerabilities Patched: XSS, Auth Bypass, and AI Assistant SQLi

Do Son June 22, 2026 0
Read More Read more about Three Critical pgAdmin 4 Vulnerabilities Patched: XSS, Auth Bypass, and AI Assistant SQLi
Public Exploit Released for FreeBSD kTLS Local Root Flaw CVE-2026-45257 FreeBSD kTLS vulnerability CVE-2026-45257 public PoC exploit enabling local privilege escalation to root
  • Vulnerability Report

Public Exploit Released for FreeBSD kTLS Local Root Flaw CVE-2026-45257

Do Son June 22, 2026 0
Read More Read more about Public Exploit Released for FreeBSD kTLS Local Root Flaw CVE-2026-45257
QNAP Patches 14 Vulnerabilities in QTS, QuTS hero, and QVP Devices QNAP NAS vulnerabilities in QTS and QuTS hero firmware including command injection flaws from QSA-26-10
  • Vulnerability Report

QNAP Patches 14 Vulnerabilities in QTS, QuTS hero, and QVP Devices

Do Son June 21, 2026 0
Read More Read more about QNAP Patches 14 Vulnerabilities in QTS, QuTS hero, and QVP Devices
NPM Package Tests AI Malware Scanner Evasion Spirals ransomware double extortion attack chain from IIS web shell to network encryption
  • Malware

NPM Package Tests AI Malware Scanner Evasion

Do Son June 21, 2026 0
Read More Read more about NPM Package Tests AI Malware Scanner Evasion
Critical ArcGIS Account Recovery Targeted in Active Attacks Illustration of ArcGIS Account Recovery attacks highlighted in the latest security bulletin
  • Cybercriminals

Critical ArcGIS Account Recovery Targeted in Active Attacks

Do Son June 20, 2026 0
Read More Read more about Critical ArcGIS Account Recovery Targeted in Active Attacks
Workplace Safety Checks Before Choosing a Laser Cleaning Machine Manufacturer dy
  • Technique

Workplace Safety Checks Before Choosing a Laser Cleaning Machine Manufacturer

Do Son June 20, 2026 0
Read More Read more about Workplace Safety Checks Before Choosing a Laser Cleaning Machine Manufacturer
Device Code Phishing: Microsoft 365 Attack That Steals No Passwords Head Mare TrueConf attack PhantomCore backdoor diagram
  • Cybercriminals

Device Code Phishing: Microsoft 365 Attack That Steals No Passwords

Do Son June 20, 2026 0
Read More Read more about Device Code Phishing: Microsoft 365 Attack That Steals No Passwords
GlassWASM Malware Hidden in Open VSX Extensions code
  • Malware

GlassWASM Malware Hidden in Open VSX Extensions

Do Son June 20, 2026 0
Read More Read more about GlassWASM Malware Hidden in Open VSX Extensions
How to Choose an HDD Transmitter for Deep and Complex Bores tech-pass
  • Technique

How to Choose an HDD Transmitter for Deep and Complex Bores

Do Son June 19, 2026 0
Read More Read more about How to Choose an HDD Transmitter for Deep and Complex Bores
Gcore Helps Ucom Safeguard Public Live Broadcast Infrastructure During Armenia’s Parliamentary Elections fi_5_e3ed09ff94_1_1781877042S8sPtX4e3f
  • Press Release

Gcore Helps Ucom Safeguard Public Live Broadcast Infrastructure During Armenia’s Parliamentary Elections

cybernewswire June 19, 2026 0
Read More Read more about Gcore Helps Ucom Safeguard Public Live Broadcast Infrastructure During Armenia’s Parliamentary Elections
eFAQ Publishes Investigation Into Alleged Scam Activity and Coordinated Reputation Attacks ChatGPT_Image_12__2026__14_15_31_1781266554PR1huQkj8c
  • Press Release

eFAQ Publishes Investigation Into Alleged Scam Activity and Coordinated Reputation Attacks

cybernewswire June 19, 2026 0
Read More Read more about eFAQ Publishes Investigation Into Alleged Scam Activity and Coordinated Reputation Attacks
UNC1151 ‘Ghostwriter’ Phishing Campaign Hijacks Gmail Accounts and 2FA Codes UNC1151 Gmail phishing fake Google login page stealing 2FA codes by Ghostwriter
  • Cybercriminals

UNC1151 ‘Ghostwriter’ Phishing Campaign Hijacks Gmail Accounts and 2FA Codes

Do Son June 19, 2026 0
Read More Read more about UNC1151 ‘Ghostwriter’ Phishing Campaign Hijacks Gmail Accounts and 2FA Codes
Interlock and Rhysida Ransomware: IBM X-Force Maps a Shared Ecosystem malware
  • Malware

Interlock and Rhysida Ransomware: IBM X-Force Maps a Shared Ecosystem

Do Son June 19, 2026 0
Read More Read more about Interlock and Rhysida Ransomware: IBM X-Force Maps a Shared Ecosystem
1M WordPress Sites at Risk: Critical Unauthenticated Arbitrary File Deletion in Avada Builder (CVSS 9.1) Avada Builder vulnerability CVE-2026-8713 unauthenticated arbitrary file deletion in WordPress
  • Vulnerability Report

1M WordPress Sites at Risk: Critical Unauthenticated Arbitrary File Deletion in Avada Builder (CVSS 9.1)

Do Son June 19, 2026 0
Read More Read more about 1M WordPress Sites at Risk: Critical Unauthenticated Arbitrary File Deletion in Avada Builder (CVSS 9.1)
APT37 NarwhalRAT Malware: A Python Backdoor Threat APT37 NarwhalRAT malware diagram
  • Malware

APT37 NarwhalRAT Malware: A Python Backdoor Threat

Do Son June 19, 2026 0
Read More Read more about APT37 NarwhalRAT Malware: A Python Backdoor Threat
Google Calendar Adds 200 Custom Colors and a Full RGB Picker Google Calendar custom colors RGB picker event organization
  • Technology

Google Calendar Adds 200 Custom Colors and a Full RGB Picker

Do Son June 19, 2026 0
Read More Read more about Google Calendar Adds 200 Custom Colors and a Full RGB Picker
Claude Code Quota Reset Follows Morning Outage Claude Code quota reset notification displayed on a developer workstation screen
  • Technology

Claude Code Quota Reset Follows Morning Outage

Do Son June 19, 2026 0
Read More Read more about Claude Code Quota Reset Follows Morning Outage
Chrome Extension Vulnerabilities: Millions at Risk Illustration of Chrome extension vulnerabilities and hacker exploiting MaXSS and Spyder flaws
  • Vulnerability Report

Chrome Extension Vulnerabilities: Millions at Risk

Do Son June 19, 2026 0
Read More Read more about Chrome Extension Vulnerabilities: Millions at Risk
Apple Opens iOS to Third-Party App Stores in Brazil Under CADE Settlement iOS third-party app stores Brazil Apple CADE settlement
  • Technology

Apple Opens iOS to Third-Party App Stores in Brazil Under CADE Settlement

Do Son June 19, 2026 0
Read More Read more about Apple Opens iOS to Third-Party App Stores in Brazil Under CADE Settlement
F5 Patches Two Critical NGINX Flaws in HTTP/3 and HTTP/2 Modules (CVE-2026-42530, CVE-2026-42055) NGINX vulnerabilities CVE-2026-42530 HTTP/3 use-after-free and HTTP/2 buffer overflow
  • Vulnerability Report

F5 Patches Two Critical NGINX Flaws in HTTP/3 and HTTP/2 Modules (CVE-2026-42530, CVE-2026-42055)

Do Son June 19, 2026 0
Read More Read more about F5 Patches Two Critical NGINX Flaws in HTTP/3 and HTTP/2 Modules (CVE-2026-42530, CVE-2026-42055)
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-87827CVSS 10.0
    Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-78006CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-39364
    Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-27540CVSS 9.0
    Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-76461CVSS 9.8
    A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an...
    CISA KEV📅 Added to KEV: Sep 14, 2026
  • CVE-2026-51990
    A critical remote code execution vulnerability in Sogou Input Method, one of the most widely used Chinese-language input...
    Admin intel📅 Updated: Sep 12, 2026
  • CVE-2026-85706CVSS 10.0
    GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42016CVSS 8.1
    JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-91949CVSS 9.3
    FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that...
  • CVE-2026-63696CVSS 9.1
    Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of...
  • CVE-2026-63695CVSS 9.8
    Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation...
  • CVE-2026-39919CVSS 9.8
    Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG...
  • CVE-2026-91998CVSS 9.9
    Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint...
  • CVE-2026-91995CVSS 9.1
    pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint...
  • CVE-2026-90711CVSS 9.1
    proxy-addr is a Node.js module that determines a request's client address behind...
  • CVE-2026-91003CVSS 9.1
    A flaw has been found in D-Link DI-8300 16.07. The affected element...
  • CVE-2026-91001CVSS 9.9
    A security flaw has been discovered in D-Link DI-8400 16.07. This affects...
  • CVE-2026-90847CVSS 9.1
    A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element...
Powered by CVE WATCHTOWER

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.