Skip to content
October 11, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Critical Apache MINA SSHD Vulnerabilities Patched in Update Diagram showing critical Apache MINA SSHD vulnerabilities and authentication bypass mechanisms
  • Vulnerability Report

Critical Apache MINA SSHD Vulnerabilities Patched in Update

Do Son October 1, 2026 0
Read More Read more about Critical Apache MINA SSHD Vulnerabilities Patched in Update
Critical Apache WSS4J Vulnerabilities Fixed in Update Diagram showing critical Apache WSS4J vulnerabilities and the CVE-2026-88920 attack flow
  • Vulnerability Report

Critical Apache WSS4J Vulnerabilities Fixed in Update

Do Son October 1, 2026 0
Read More Read more about Critical Apache WSS4J Vulnerabilities Fixed in Update
Critical Python SSL Vulnerabilities Fixed in CPython Diagram illustrating critical Python SSL vulnerabilities and attack mechanisms
  • Vulnerability Report

Critical Python SSL Vulnerabilities Fixed in CPython

Do Son October 1, 2026 0
Read More Read more about Critical Python SSL Vulnerabilities Fixed in CPython
CISA Warns of Unpatched CVSS 10 Flaw in Viidure Dashcam App Exposing Footage and Firmware Viidure dashcam app vulnerabilities CVE-2026-96587 hardcoded credentials and CVE-2026-94204 public cloud storage in CISA advisory
  • Vulnerability Report

CISA Warns of Unpatched CVSS 10 Flaw in Viidure Dashcam App Exposing Footage and Firmware

Do Son October 1, 2026 0
Read More Read more about CISA Warns of Unpatched CVSS 10 Flaw in Viidure Dashcam App Exposing Footage and Firmware
Citrix NetScaler CVE-2026-88772 Exploited in the Wild as PoC and Full Details Go Public CVE-2026-88772 Citrix NetScaler DTLS pre-auth memory overflow exploited in the wild with public proof-of-concept exploit code
  • Vulnerability Report

Citrix NetScaler CVE-2026-88772 Exploited in the Wild as PoC and Full Details Go Public

Do Son October 1, 2026 0
Read More Read more about Citrix NetScaler CVE-2026-88772 Exploited in the Wild as PoC and Full Details Go Public
Internet Society Launches Global Online Trust and Safety Hub as Part of Its Safer Internet Initiative 1200z720headers-07_17907968539qxNinU8e0
  • Press Release

Internet Society Launches Global Online Trust and Safety Hub as Part of Its Safer Internet Initiative

cybernewswire September 30, 2026 0
Read More Read more about Internet Society Launches Global Online Trust and Safety Hub as Part of Its Safer Internet Initiative
Microsoft Tracks Zimbra CVE-2026-73570 Attacks That Steal Mail and Auth Keys Zimbra CVE-2026-73570 command injection attack chain from crafted email to web shells and mailbox theft
  • Vulnerability Report

Microsoft Tracks Zimbra CVE-2026-73570 Attacks That Steal Mail and Auth Keys

Do Son September 30, 2026 0
Read More Read more about Microsoft Tracks Zimbra CVE-2026-73570 Attacks That Steal Mail and Auth Keys
Cisco SD-WAN Manager Authentication Bypass CVE-2026-76504 Exploited in the Wild Cisco SD-WAN Manager authentication bypass CVE-2026-76504 exploited in the wild
  • Vulnerability Report

Cisco SD-WAN Manager Authentication Bypass CVE-2026-76504 Exploited in the Wild

Do Son September 30, 2026 0
Read More Read more about Cisco SD-WAN Manager Authentication Bypass CVE-2026-76504 Exploited in the Wild
Russia’s Star Blizzard Scales Up Phishing With RedFlick to Deliver CosmicPulse Backdoor Star Blizzard RedFlick phishing campaign using scheduled tasks to install the CosmicPulse backdoor
  • Cybercriminals

Russia’s Star Blizzard Scales Up Phishing With RedFlick to Deliver CosmicPulse Backdoor

Do Son September 30, 2026 0
Read More Read more about Russia’s Star Blizzard Scales Up Phishing With RedFlick to Deliver CosmicPulse Backdoor
OpenAI DevDay 2026: Elevating the AI Subscription Paradigm OpenAI DevDay 2026 presentation showcasing the new Pro 500 tier and GPT-6.1 Sol architecture
  • Technology

OpenAI DevDay 2026: Elevating the AI Subscription Paradigm

Do Son September 30, 2026 0
Read More Read more about OpenAI DevDay 2026: Elevating the AI Subscription Paradigm
Firefox Redesign Compact Mode Returns With AI Off Switch Firefox redesign compact mode on a modern browser interface, with a Firefox AI kill switch in the settings
  • Technology

Firefox Redesign Compact Mode Returns With AI Off Switch

Do Son September 30, 2026 0
Read More Read more about Firefox Redesign Compact Mode Returns With AI Off Switch
Critical Apache PLC4X Flaw Lets Attackers Hijack OPC UA Connections to PLCs Apache PLC4X vulnerability CVE-2026-102508 in the OPC UA driver allowing server impersonation and credential theft
  • Vulnerability Report

Critical Apache PLC4X Flaw Lets Attackers Hijack OPC UA Connections to PLCs

Do Son September 30, 2026 0
Read More Read more about Critical Apache PLC4X Flaw Lets Attackers Hijack OPC UA Connections to PLCs
OpenAI Dots AI Assistant Gets Its Own Cloud Computer OpenAI Dots AI assistant working around the clock on its own cloud computer as an always-on AI assistant inside Slack and Teams
  • Technology

OpenAI Dots AI Assistant Gets Its Own Cloud Computer

Do Son September 30, 2026 0
Read More Read more about OpenAI Dots AI Assistant Gets Its Own Cloud Computer
AI Coding Agents Leak 13,000 Internal Screenshots to Public GitHub Repos AI agent screenshot leak in PixelLeak research showing internal images pushed to public GitHub repos
  • Data Leak

AI Coding Agents Leak 13,000 Internal Screenshots to Public GitHub Repos

Do Son September 30, 2026 0
Read More Read more about AI Coding Agents Leak 13,000 Internal Screenshots to Public GitHub Repos
Nigeria-Based Fraudsters Hijack .edu Accounts to Run University Job Scams University job scams using edu account takeover to send fake job offers to college students
  • Cybercriminals

Nigeria-Based Fraudsters Hijack .edu Accounts to Run University Job Scams

Do Son September 30, 2026 0
Read More Read more about Nigeria-Based Fraudsters Hijack .edu Accounts to Run University Job Scams
Google Gemini Find Hub: The Evolution of AI Memory Tracking Google Gemini Find Hub dashboard showing semantic memory tracking for passports
  • Technology

Google Gemini Find Hub: The Evolution of AI Memory Tracking

Do Son September 30, 2026 0
Read More Read more about Google Gemini Find Hub: The Evolution of AI Memory Tracking
OpenAI DevDay 2026: The Shift Toward Enterprise Collaboration OpenAI enterprise collaboration workspace dashboard featuring ChatGPT Space and Dots
  • Technology

OpenAI DevDay 2026: The Shift Toward Enterprise Collaboration

Do Son September 30, 2026 0
Read More Read more about OpenAI DevDay 2026: The Shift Toward Enterprise Collaboration
America.gov AI Chatbot Launches With Gemini and Grok America.gov AI chatbot answering citizen questions as a single digital front door to US government services, the new US government chatbot
  • Technology

America.gov AI Chatbot Launches With Gemini and Grok

Do Son September 30, 2026 0
Read More Read more about America.gov AI Chatbot Launches With Gemini and Grok
SVG Phishing Attacks Return in August as Symantec Logs 222,000 Detections SVG phishing attacks using SVG smuggling to hide fake login pages inside image attachments
  • Cybercriminals

SVG Phishing Attacks Return in August as Symantec Logs 222,000 Detections

Do Son September 30, 2026 0
Read More Read more about SVG Phishing Attacks Return in August as Symantec Logs 222,000 Detections
Microsoft Links JADEPUFFER Azure Attack to Agentic Ransomware Actor Storm-3168 JADEPUFFER Azure attack by agentic ransomware actor Storm-3168 using compromised service principals
  • Cybercriminals

Microsoft Links JADEPUFFER Azure Attack to Agentic Ransomware Actor Storm-3168

Do Son September 30, 2026 0
Read More Read more about Microsoft Links JADEPUFFER Azure Attack to Agentic Ransomware Actor Storm-3168
TeamViewer Fixes Five High-Severity Flaws in Full Client and Host TeamViewer vulnerabilities CVE-2026-92370, CVE-2026-19743 and CVE-2026-92368 in TeamViewer Full Client and Host
  • Vulnerability Report

TeamViewer Fixes Five High-Severity Flaws in Full Client and Host

Do Son September 30, 2026 0
Read More Read more about TeamViewer Fixes Five High-Severity Flaws in Full Client and Host
Electron Fixes Five High-Severity Sandbox and Isolation Vulnerabilities Electron vulnerabilities CVE-2026-102676, CVE-2026-102673 and CVE-2026-102674 weakening sandbox and isolation in desktop apps
  • Vulnerability Report

Electron Fixes Five High-Severity Sandbox and Isolation Vulnerabilities

Do Son September 30, 2026 0
Read More Read more about Electron Fixes Five High-Severity Sandbox and Isolation Vulnerabilities
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
πŸ“ˆ

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

πŸ›‘οΈ

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

πŸ™

GitHub Issues
Auto-create alert tickets without duplication.

πŸ“¬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

πŸ”€

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days β†’

🚨 Active Exploits in the Wild

  • CVE-2026-102255CVSS 10.0
    A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access...
    Admin intel📅 Updated: Oct 9, 2026
  • CVE-2026-105133CVSS 6.9
    A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file...
    Admin intel📅 Updated: Oct 9, 2026
  • CVE-2023-22894CVSS 4.9
    Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2016-3081CVSS 8.1
    Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled,...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2015-3306CVSS 10.0
    The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2015-5477CVSS 7.5
    named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2021-3199CVSS 9.8
    Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-108707CVSS 9.3
    Wukong_HRM through commit 186115e contains an authentication bypass vulnerability in ParamAspect that allows unauthenticated attackers to call every...
    📅 Updated: Oct 11, 2026
  • CVE-2026-78533CVSS 9.8
    Unauthenticated PHP Object Injection in Qwery
    📅 Updated: Oct 10, 2026
  • CVE-2026-78535CVSS 9.8
    Unauthenticated PHP Object Injection in Photolia
    📅 Updated: Oct 10, 2026
  • CVE-2026-81797CVSS 9.8
    Unauthenticated PHP Object Injection in Buzz Stone | Magazine & Viral Blog WordPress Theme
    📅 Updated: Oct 10, 2026
  • CVE-2026-66567CVSS 9.8
    Unauthenticated PHP Object Injection in Anesta
    📅 Updated: Oct 10, 2026
  • CVE-2026-66568CVSS 9.8
    Unauthenticated PHP Object Injection in Original
    📅 Updated: Oct 10, 2026
  • CVE-2026-66569CVSS 9.8
    Unauthenticated PHP Object Injection in Kicker
    📅 Updated: Oct 10, 2026
  • CVE-2026-78529CVSS 9.8
    Unauthenticated PHP Object Injection in Alliance
    📅 Updated: Oct 10, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
Β© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.