Skip to content
July 25, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Critical 9.8 RCE Threat to SGLang AI Infrastructure SGLang RCE Vulnerability CVE-2026-7301 Zero-Day SGLang RCE AI Infrastructure Vulnerability
  • Vulnerability Report

Critical 9.8 RCE Threat to SGLang AI Infrastructure

Do Son April 21, 2026 0
Read More Read more about Critical 9.8 RCE Threat to SGLang AI Infrastructure
MOVEit WAF Critical Alert: Multi-Level RCE and WAF Bypass Vulnerabilities Disclosed CVE-2024-4358 MOVEit WAF RCE Progress ADC Vulnerabilities
  • Vulnerability Report

MOVEit WAF Critical Alert: Multi-Level RCE and WAF Bypass Vulnerabilities Disclosed

Do Son April 21, 2026 0
Read More Read more about MOVEit WAF Critical Alert: Multi-Level RCE and WAF Bypass Vulnerabilities Disclosed
OVN Security Alert: Critical Heap Over-Read Flaws Risk Sensitive Data Leaks OVN Heap Over-read Network Memory Leak
  • Vulnerability Report

OVN Security Alert: Critical Heap Over-Read Flaws Risk Sensitive Data Leaks

Do Son April 21, 2026 0
Read More Read more about OVN Security Alert: Critical Heap Over-Read Flaws Risk Sensitive Data Leaks
Nexcorium Botnet Turns Unpatched DVRs into DDoS Foot Soldiers Nexcorium Botnet Mirai Variant
  • Malware

Nexcorium Botnet Turns Unpatched DVRs into DDoS Foot Soldiers

Do Son April 21, 2026 0
Read More Read more about Nexcorium Botnet Turns Unpatched DVRs into DDoS Foot Soldiers
Ubuntu 26.10 Set to Deliver Linux Kernel 7.2 and Rapid Innovation Ubuntu 26.10 Stonking Stingray Ubuntu Security Alert: Three Ways to Bypass User Namespace Restrictions
  • Linux

Ubuntu 26.10 Set to Deliver Linux Kernel 7.2 and Rapid Innovation

Do Son April 21, 2026 0
Read More Read more about Ubuntu 26.10 Set to Deliver Linux Kernel 7.2 and Rapid Innovation
The NTFS Resurrection: Linux Kernel 7.1 Delivers a Native Driver with 110% Faster Write Speeds CVE-2022-41850 Linux Kernel 7.1 NTFS driver
  • Linux

The NTFS Resurrection: Linux Kernel 7.1 Delivers a Native Driver with 110% Faster Write Speeds

Do Son April 21, 2026 0
Read More Read more about The NTFS Resurrection: Linux Kernel 7.1 Delivers a Native Driver with 110% Faster Write Speeds
SEO Poisoning & NativeAOT: Unmasking the “Kong RAT” Campaign Targeting IT Professionals Kong RAT SEO Poisoning
  • Malware

SEO Poisoning & NativeAOT: Unmasking the “Kong RAT” Campaign Targeting IT Professionals

Do Son April 21, 2026 0
Read More Read more about SEO Poisoning & NativeAOT: Unmasking the “Kong RAT” Campaign Targeting IT Professionals
Meta Unveils a New Premium Tier to Personalize Your WhatsApp Experience WhatsApp Plus subscription
  • Technology

Meta Unveils a New Premium Tier to Personalize Your WhatsApp Experience

Do Son April 21, 2026 0
Read More Read more about Meta Unveils a New Premium Tier to Personalize Your WhatsApp Experience
The 100-Billion-Dollar Power Play: Anthropic and Amazon Forge an 8.5GW AI Empire Motorola Smart Feed redirect Anthropic Amazon 5GW partnership Amazon Perplexity lawsuit AWS-LC Vulnerabilities Cryptographic Bypass AWS Middle East drone strikes Amazon layoffs 2026, Amazon AI restructuring Amazon Kindle DRM Policy, Publisher Control EPUB AWS Nova Forge AI Model Customization AWS Trainium3 EC2 Trn3 UltraServer Route 53 Accelerated Recovery AWS DNS Resilience AI Browser War, Amazon Comet Amazon layoffs, cost reduction AWS outage, DynamoDB DNS AWS outage, cloud dependency AWS VPN Client, Root Privilege Escalation WSA shutdown, Amazon Appstore Amazon Wondery, Podcast Restructuring Amazon Q2 2025 Generative AI AWS Client VPN, Privilege Escalation Amazon AI, Wearable AI
  • Technology

The 100-Billion-Dollar Power Play: Anthropic and Amazon Forge an 8.5GW AI Empire

Do Son April 21, 2026 0
Read More Read more about The 100-Billion-Dollar Power Play: Anthropic and Amazon Forge an 8.5GW AI Empire
Beyond Gatekeeper: How Sapphire Sleet’s AppleScript Trap Hijacks macOS and Crypto Wallets Sapphire Sleet macOS TCC Bypass Malware
  • Malware

Beyond Gatekeeper: How Sapphire Sleet’s AppleScript Trap Hijacks macOS and Crypto Wallets

Do Son April 21, 2026 0
Read More Read more about Beyond Gatekeeper: How Sapphire Sleet’s AppleScript Trap Hijacks macOS and Crypto Wallets
The Negotiator Turned Traitor: Insider Betrayal in the BlackCat Ransomware Ring NATS-as-C2 Sysdig CVE-2026-33017 Langflow RCE Microsoft Phone Link Hijack CloudZ Pheno Plugin Insider Threat BlackCat (ALPHV) OFAC Sanctions DPRK IT Workers Transparent Tribe APT36 React2Shell, EtherRAT SideWinder Espionage, Netlify Phishing DDNS Abuse, C2 Infrastructure Hacking Health Club
  • Cybercriminals

The Negotiator Turned Traitor: Insider Betrayal in the BlackCat Ransomware Ring

Do Son April 21, 2026 0
Read More Read more about The Negotiator Turned Traitor: Insider Betrayal in the BlackCat Ransomware Ring
AI Hype Hijacked: How a Fake Claude Installer Blinds Windows Security Claude AI Phishing MSIX Malware
  • Malware

AI Hype Hijacked: How a Fake Claude Installer Blinds Windows Security

Do Son April 21, 2026 0
Read More Read more about AI Hype Hijacked: How a Fake Claude Installer Blinds Windows Security
The Price of Privacy: Atlassian to Train AI on Jira and Confluence Data Starting August 2026 CVE-2024-21687 & CVE-2024-21686 Atlassian AI data contribution
  • Data Leak

The Price of Privacy: Atlassian to Train AI on Jira and Confluence Data Starting August 2026

Do Son April 21, 2026 0
Read More Read more about The Price of Privacy: Atlassian to Train AI on Jira and Confluence Data Starting August 2026
The Ghost in the Browser: Is Claude Desktop Clandestinely Installing a Surveillance Bridge? Claude Cowork quota update Claude Desktop native messaging bridge Anthropic Opus 4.5 Claude Excel Integration
  • Data Leak

The Ghost in the Browser: Is Claude Desktop Clandestinely Installing a Surveillance Bridge?

Do Son April 21, 2026 0
Read More Read more about The Ghost in the Browser: Is Claude Desktop Clandestinely Installing a Surveillance Bridge?
Scotland Man Pleads Guilty in Massive $8 Million Crypto-Heist and Phishing Campaign Seedworm Espionage Campaign 2026 ChromElevator Stealer DLL Sideloading SIM Swapping Crypto Theft Lazarus Comebacker, Aerospace Espionage Delete PlugX Malware
  • Cybercriminals

Scotland Man Pleads Guilty in Massive $8 Million Crypto-Heist and Phishing Campaign

Do Son April 21, 2026 0
Read More Read more about Scotland Man Pleads Guilty in Massive $8 Million Crypto-Heist and Phishing Campaign
CISA Warns of Active Exploitation in Cisco, PaperCut, and Zimbra TP-Link, CISA CVE-2023-32315 CISA KEV Catalog Active Exploitation
  • Vulnerability Report

CISA Warns of Active Exploitation in Cisco, PaperCut, and Zimbra

Do Son April 21, 2026 0
Read More Read more about CISA Warns of Active Exploitation in Cisco, PaperCut, and Zimbra
Cybersecurity: How to Keep NoSQL Databases Safe tech
  • Technique

Cybersecurity: How to Keep NoSQL Databases Safe

Do Son April 21, 2026 0
Read More Read more about Cybersecurity: How to Keep NoSQL Databases Safe
Progress Kemp LoadMaster Alert: Multiple RCE and WAF Bypass Flaws Patched Kemp LoadMaster flaws command injection remote execution Kemp LoadMaster Vulnerability WAF Bypass Technique Progress WhatsUp Gold Vulnerabilities
  • Vulnerability Report

Progress Kemp LoadMaster Alert: Multiple RCE and WAF Bypass Flaws Patched

Do Son April 21, 2026 0
Read More Read more about Progress Kemp LoadMaster Alert: Multiple RCE and WAF Bypass Flaws Patched
RondoDox Botnet Hijacks Everything from IoT to Fortnite RondoDox Botnet Nanomite Anti-Debugging
  • Malware

RondoDox Botnet Hijacks Everything from IoT to Fortnite

Do Son April 21, 2026 0
Read More Read more about RondoDox Botnet Hijacks Everything from IoT to Fortnite
ASUSTOR Issues Critical Patch: Command Injection Vulnerability Threatens ADM Users ASUSTOR ADM Vulnerability CVE-2026-6644
  • Vulnerability Report

ASUSTOR Issues Critical Patch: Command Injection Vulnerability Threatens ADM Users

Do Son April 21, 2026 0
Read More Read more about ASUSTOR Issues Critical Patch: Command Injection Vulnerability Threatens ADM Users
ZionSiphon: The “Defanged” Malware Aiming for the Water Supply Energy Meter RCE CVE-2025-41709 ICS Exposure, Power Grid Security CVE-2025-1393 & CVE-2024-23943
  • Malware

ZionSiphon: The “Defanged” Malware Aiming for the Water Supply

Do Son April 21, 2026 0
Read More Read more about ZionSiphon: The “Defanged” Malware Aiming for the Water Supply
Detection as Code: The Quiet Discipline Reshaping How Large Enterprises Run Their SOCs WD Discovery Vulnerability CVE-2025-30248 binary-parser Vulnerability CVE-2026-1245 H3C RCE Vulnerability CVE-2025-60262 Telenium RCE, CVE-2025-10659 Fuel station security, ICS vulnerabilities FreePBX vulnerability CVE-2024-9478 & CVE-2024-9479 SysTrack Vulnerability, Privilege Escalation
  • Technique

Detection as Code: The Quiet Discipline Reshaping How Large Enterprises Run Their SOCs

Nikolay Milyaev April 20, 2026 0
Read More Read more about Detection as Code: The Quiet Discipline Reshaping How Large Enterprises Run Their SOCs
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-16723CVSS 9.0
    A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson\'s stock...
    Admin intel📅 Updated: Jul 25, 2026
  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-0770CVSS 9.8
    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2021-27137CVSS 8.1
    An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2026-6875CVSS 9.5
    ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability...
    Admin intel📅 Updated: Jul 18, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-61884CVSS 9.8
    The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation...
  • CVE-2026-62379CVSS 9.8
    ## Summary A pre-authentication remote code execution vulnerability affects OpenAM. The remote...
  • CVE-2026-62263
    ### Summary The GHSA-6c99-87fr-6q7r fix wrapped WebAuthn authenticator deserialization in an `ObjectInputFilter`...
  • CVE-2026-62835CVSS 9.3
    Improper authorization in Azure Portal allows an unauthorized attacker to disclose information...
  • CVE-2026-48021CVSS 9.1
    In epa4all, prior to version 2026-05-20, an attacker who can intercept the...
  • CVE-2026-59940CVSS 9.8
    ## Summary A type confusion issue in `seroval.fromJSON()` allowed attacker-controlled JSON input...
  • CVE-2026-58630CVSS 10.0
    Improper access control in Azure App Service allows an unauthorized attacker to...
  • CVE-2026-57106CVSS 10.0
    Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to...
  • CVE-2026-56163CVSS 10.0
    Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an...
  • CVE-2026-15704CVSS 9.8
    In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.