Skip to content
July 25, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
The Great Gallic Exodus: Inside France’s Bold Mission to Ditch Microsoft for Linux French Digital Sovereignty Greg Kroah-Hartman AI code review CVE-2025-38352 Linux kernel exploit, Android 32-bit UAF vulnerability CVE-2022-36946 Linux Kernel 6.16, Hardware Support
  • Linux

The Great Gallic Exodus: Inside France’s Bold Mission to Ditch Microsoft for Linux

Do Son April 13, 2026 0
Read More Read more about The Great Gallic Exodus: Inside France’s Bold Mission to Ditch Microsoft for Linux
The Script Editor Shift: How ClickFix Evades macOS 26.4 Security to Deliver Atomic Stealer ClickFix macOS Script Editor Attack
  • Malware

The Script Editor Shift: How ClickFix Evades macOS 26.4 Security to Deliver Atomic Stealer

Do Son April 13, 2026 0
Read More Read more about The Script Editor Shift: How ClickFix Evades macOS 26.4 Security to Deliver Atomic Stealer
LucidRook: Sophisticated Spear-Phishing Campaign Targets Taiwan with Custom Malware Stack LucidRook Malware Taiwan Cyber Attack
  • Cybercriminals
  • Malware

LucidRook: Sophisticated Spear-Phishing Campaign Targets Taiwan with Custom Malware Stack

Do Son April 13, 2026 0
Read More Read more about LucidRook: Sophisticated Spear-Phishing Campaign Targets Taiwan with Custom Malware Stack
Supply Chain Alert: Critical 9.4 CVSS RCE Hits Sonatype Nexus Repository Manager Nexus Repository RCE Supply Chain Security Nexus Repository Manager - CVE-2024-5082 & CVE-2024-5083
  • Vulnerability

Supply Chain Alert: Critical 9.4 CVSS RCE Hits Sonatype Nexus Repository Manager

Do Son April 13, 2026 0
Read More Read more about Supply Chain Alert: Critical 9.4 CVSS RCE Hits Sonatype Nexus Repository Manager
Under 10 Hours: The marimo Terminal RCE Exploited in a Record-Breaking AI Sprint marimo Terminal RCE AI-Assisted Exploitation
  • Vulnerability Report

Under 10 Hours: The marimo Terminal RCE Exploited in a Record-Breaking AI Sprint

Do Son April 13, 2026 0
Read More Read more about Under 10 Hours: The marimo Terminal RCE Exploited in a Record-Breaking AI Sprint
Total CMS Takeover: Movable Type Patches Critical 9.8 CVSS Perl RCE Movable Type Vulnerability Perl RCE
  • Vulnerability Report

Total CMS Takeover: Movable Type Patches Critical 9.8 CVSS Perl RCE

Do Son April 13, 2026 0
Read More Read more about Total CMS Takeover: Movable Type Patches Critical 9.8 CVSS Perl RCE
The CVE Watchtower: Weekly Threat Intelligence Briefing (April 6 – April 12, 2026) Vulnerability Digest Active Exploitation
  • Weekly Recap

The CVE Watchtower: Weekly Threat Intelligence Briefing (April 6 – April 12, 2026)

Do Son April 13, 2026 0
Read More Read more about The CVE Watchtower: Weekly Threat Intelligence Briefing (April 6 – April 12, 2026)
The Stealthy Evolution of the DesckVB RAT Infection Chain DesckVB RAT Fileless Malware
  • Malware

The Stealthy Evolution of the DesckVB RAT Infection Chain

Do Son April 13, 2026 0
Read More Read more about The Stealthy Evolution of the DesckVB RAT Infection Chain
Encryption Bypasses and Kubernetes Token Leaks Hit Apache Tomcat CVE-2023-45648 Apache Tomcat Security Encryption Bypass
  • Vulnerability Report

Encryption Bypasses and Kubernetes Token Leaks Hit Apache Tomcat

Do Son April 13, 2026 0
Read More Read more about Encryption Bypasses and Kubernetes Token Leaks Hit Apache Tomcat
The Invisible Hijack: How FrostArmada Turned 18,000 Routers Into a Global Spy Network FrostArmada Campaign DNS Redirection
  • Cybercriminals

The Invisible Hijack: How FrostArmada Turned 18,000 Routers Into a Global Spy Network

Do Son April 13, 2026 0
Read More Read more about The Invisible Hijack: How FrostArmada Turned 18,000 Routers Into a Global Spy Network
CVE-2026-40175 (CVSS 10): Critical Axios Vulnerability and Exploit Code Disclosed Publicly Axios proxy vulnerabilities prototype pollution gadget Axios Vulnerability Cloud Hijacking Axios npm supply chain attack Axios Vulnerability Node.js DoS CVE-2025-58754 CVE-2025-27152 Axios Vulnerability, Form-Data Flaw
  • Vulnerability Report

CVE-2026-40175 (CVSS 10): Critical Axios Vulnerability and Exploit Code Disclosed Publicly

Do Son April 12, 2026 0
Read More Read more about CVE-2026-40175 (CVSS 10): Critical Axios Vulnerability and Exploit Code Disclosed Publicly
Best 7 Credential Leak Monitoring Services Ragic Enterprise Cloud Database - CVE-2024-9983 - CVE-2024-9984 - CVE-2024-9985
  • Technique

Best 7 Credential Leak Monitoring Services

Do Son April 12, 2026 0
Read More Read more about Best 7 Credential Leak Monitoring Services
Root Access at Risk: Critical Nix Sandbox Escape Overwrites Sensitive System Files Nix Sandbox Escape Root Escalation CVE-2024-45593
  • Vulnerability Report

Root Access at Risk: Critical Nix Sandbox Escape Overwrites Sensitive System Files

Do Son April 10, 2026 0
Read More Read more about Root Access at Risk: Critical Nix Sandbox Escape Overwrites Sensitive System Files
Critical Privilege Escalation in Checkmk: Root Access at Risk Checkmk Privilege Escalation
  • Vulnerability Report

Critical Privilege Escalation in Checkmk: Root Access at Risk

Do Son April 10, 2026 0
Read More Read more about Critical Privilege Escalation in Checkmk: Root Access at Risk
The “Seal of Approval” Trap: How Hackers are Hijacking GitHub and Jira Notifications phishing-3390518_1280
  • Cybercriminals

The “Seal of Approval” Trap: How Hackers are Hijacking GitHub and Jira Notifications

Do Son April 10, 2026 0
Read More Read more about The “Seal of Approval” Trap: How Hackers are Hijacking GitHub and Jira Notifications
New AI-Driven Phishing Campaign Subverts Microsoft’s Device Code Flow EvilToken Device Code Phishing
  • Cybercriminals

New AI-Driven Phishing Campaign Subverts Microsoft’s Device Code Flow

Do Son April 10, 2026 0
Read More Read more about New AI-Driven Phishing Campaign Subverts Microsoft’s Device Code Flow
New ClickFix Campaign Unveiled: Modular NodeJS Malware Targets Windows Users Node.js Infostealer ClickFix Campaign
  • Malware

New ClickFix Campaign Unveiled: Modular NodeJS Malware Targets Windows Users

Do Son April 10, 2026 0
Read More Read more about New ClickFix Campaign Unveiled: Modular NodeJS Malware Targets Windows Users
North Korea’s “Portfolio Model” Shatters Modern Attribution Attribution Resistance DPRK Cyber Portfolio
  • Cyber Security

North Korea’s “Portfolio Model” Shatters Modern Attribution

Do Son April 10, 2026 0
Read More Read more about North Korea’s “Portfolio Model” Shatters Modern Attribution
HPE Aruba Patches High-Severity Credential Theft Flaw CVE-2024-26305 _ CVE-2025-23058 Aruba 5G Core Open Redirect
  • Vulnerability Report

HPE Aruba Patches High-Severity Credential Theft Flaw

Do Son April 10, 2026 0
Read More Read more about HPE Aruba Patches High-Severity Credential Theft Flaw
North Korean Hackers Pivot to AI: New npm Malware Targets Cursor, Claude, and Gemini Tokens AI Tool Targeting Contagious Interview
  • Malware

North Korean Hackers Pivot to AI: New npm Malware Targets Cursor, Claude, and Gemini Tokens

Do Son April 10, 2026 0
Read More Read more about North Korean Hackers Pivot to AI: New npm Malware Targets Cursor, Claude, and Gemini Tokens
TP-Link Archer AX53 Hit by Multiple High-Severity Vulnerabilities Archer MR600 command injection WireGuard client configuration Tapo smart device vulnerability unencrypted Bluetooth transmission TP-Link router vulnerability CVE-2026-5509 patch Archer AX53 Vulnerability TP-Link Router Security Tapo C520WS Vulnerability TP-Link Security Patch TP-Link Archer NX Router Vulnerability TP-Link Archer Vulnerability CVE-2025-15568 TP-Link Archer BE230 Vulnerability Command Injection TP-Link Omada Vulnerability CVE-2025-9520 TP-Link Archer MR600 Vulnerability CVE-2025-14756 CVE-2026-0629 TP-Link Omada RCE, CVE-2025-6542 TP-Link, Smart plug vulnerability TP-Link Archer C50, Hardcoded DES Key TP-Link NVR, Command Injection TP-Link Routers cybersecurity
  • Vulnerability Report

TP-Link Archer AX53 Hit by Multiple High-Severity Vulnerabilities

Do Son April 10, 2026 0
Read More Read more about TP-Link Archer AX53 Hit by Multiple High-Severity Vulnerabilities
LinkedIn Job Seekers Targeted by Sophisticated “PXA Stealer” Campaign PXA Stealer LinkedIn Job Phishing
  • Cybercriminals

LinkedIn Job Seekers Targeted by Sophisticated “PXA Stealer” Campaign

Do Son April 10, 2026 0
Read More Read more about LinkedIn Job Seekers Targeted by Sophisticated “PXA Stealer” Campaign
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-16723CVSS 9.0
    A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson\'s stock...
    Admin intel📅 Updated: Jul 25, 2026
  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-0770CVSS 9.8
    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2021-27137CVSS 8.1
    An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2026-6875CVSS 9.5
    ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability...
    Admin intel📅 Updated: Jul 18, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-66012CVSS 10.0
    SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp...
  • CVE-2026-61884CVSS 9.8
    The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation...
  • CVE-2026-62379CVSS 9.8
    ## Summary A pre-authentication remote code execution vulnerability affects OpenAM. The remote...
  • CVE-2026-62263
    ### Summary The GHSA-6c99-87fr-6q7r fix wrapped WebAuthn authenticator deserialization in an `ObjectInputFilter`...
  • CVE-2026-62835CVSS 9.3
    Improper authorization in Azure Portal allows an unauthorized attacker to disclose information...
  • CVE-2026-48021CVSS 9.1
    In epa4all, prior to version 2026-05-20, an attacker who can intercept the...
  • CVE-2026-59940CVSS 9.8
    ## Summary A type confusion issue in `seroval.fromJSON()` allowed attacker-controlled JSON input...
  • CVE-2026-58630CVSS 10.0
    Improper access control in Azure App Service allows an unauthorized attacker to...
  • CVE-2026-57106CVSS 10.0
    Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to...
  • CVE-2026-56163CVSS 10.0
    Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.