Skip to content
July 25, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
The $17 Million Bounty: Google Smashes Records and Launches AI Frontier for 15th VRP Anniversary Google VRP 2025 Bug Bounty Records
  • Vulnerability Report

The $17 Million Bounty: Google Smashes Records and Launches AI Frontier for 15th VRP Anniversary

Do Son April 5, 2026 0
Read More Read more about The $17 Million Bounty: Google Smashes Records and Launches AI Frontier for 15th VRP Anniversary
Zero Authentication, Total Control: Critical CVSS 10 Flaw Uncovered in Dgraph Database Dgraph Vulnerability CVSS 10.0 Dgraph Admin Leak CVE-2026-40173
  • Vulnerability Report

Zero Authentication, Total Control: Critical CVSS 10 Flaw Uncovered in Dgraph Database

Do Son April 5, 2026 2
Read More Read more about Zero Authentication, Total Control: Critical CVSS 10 Flaw Uncovered in Dgraph Database
Hackers are Using “Legit” IT Tools to Hijack the 2026 Tax Season 2026 Tax Phishing RMM Abuse
  • Cybercriminals

Hackers are Using “Legit” IT Tools to Hijack the 2026 Tax Season

Do Son April 5, 2026 0
Read More Read more about Hackers are Using “Legit” IT Tools to Hijack the 2026 Tax Season
Under Active Attack: Critical 9.1 CVSS FortiClient EMS Flaw Exploited in the Wild Knowledge Deliver RCE vulnerability FortiClient EMS Vulnerability CVE-2026-35616 Cisco SD-WAN Vulnerability CVE-2026-20122 PCPcat, Next.js RCE Salesloft breach, Salesforce CRM WIREFIRE web shell
  • Vulnerability Report

Under Active Attack: Critical 9.1 CVSS FortiClient EMS Flaw Exploited in the Wild

Do Son April 4, 2026 0
Read More Read more about Under Active Attack: Critical 9.1 CVSS FortiClient EMS Flaw Exploited in the Wild
Apache Traffic Server Patches “Double-Header” DoS and Request Smuggling Flaws Apache Traffic Server Vulnerabilities CVE-2024-56195 and CVE-2024-56196
  • Vulnerability Report

Apache Traffic Server Patches “Double-Header” DoS and Request Smuggling Flaws

Do Son April 3, 2026 0
Read More Read more about Apache Traffic Server Patches “Double-Header” DoS and Request Smuggling Flaws
Password Hijack in the Modern Stack: Payload CMS Patches Critical 9.1 CVSS Reset Flaw Payload CMS Vulnerability CVE-2026-34751
  • Vulnerability Report

Password Hijack in the Modern Stack: Payload CMS Patches Critical 9.1 CVSS Reset Flaw

Do Son April 3, 2026 0
Read More Read more about Password Hijack in the Modern Stack: Payload CMS Patches Critical 9.1 CVSS Reset Flaw
CVE-2026-4370 (CVSS 10): Critical Juju Flaw Grants Attackers Total Infrastructure Control Juju Orchestration Cloud Credential Theft Juju Orchestration Vulnerability CVE-2026-4370
  • Vulnerability Report

CVE-2026-4370 (CVSS 10): Critical Juju Flaw Grants Attackers Total Infrastructure Control

Do Son April 3, 2026 0
Read More Read more about CVE-2026-4370 (CVSS 10): Critical Juju Flaw Grants Attackers Total Infrastructure Control
Breaking the Input: Sandbox Escape Hits libinput, Exposing Leading Linux Desktops libinput Sandbox Escape CVE-2026-35093
  • Vulnerability Report

Breaking the Input: Sandbox Escape Hits libinput, Exposing Leading Linux Desktops

Do Son April 3, 2026 0
Read More Read more about Breaking the Input: Sandbox Escape Hits libinput, Exposing Leading Linux Desktops
The MuPDF Vulnerability Turning “Safe” PDFs into System Hijackers MuPDF RCE Integer Overflow
  • Vulnerability Report

The MuPDF Vulnerability Turning “Safe” PDFs into System Hijackers

Do Son April 3, 2026 0
Read More Read more about The MuPDF Vulnerability Turning “Safe” PDFs into System Hijackers
The Hidden Costs of Managing Too Many Security Tools bc257a04-d077-46b7-a6bc-3011efc3ac3f
  • Technique

The Hidden Costs of Managing Too Many Security Tools

Do Son April 3, 2026 0
Read More Read more about The Hidden Costs of Managing Too Many Security Tools
The EU’s AWS “Master Key”: How a Compromised Trivy Update Leaked 340GB of Data Apple Google EU alliance DMA European Commission Breach Trivy Supply Chain Attack Europa.eu Breach EU Cloud Infrastructure EU Cyber Sanctions State-Sponsored Hacking EU 2040 Emissions Target, Europe Climate Leadership AWS Azure DMA Cloud Gatekeeper DSA violation, illegal content Apple DMA Delay, iPhone Mirroring EU EU Age Verification, Google Play Integrity Corning Antitrust, EU Competition Apple EU Digital Markets Act App Store commission European Union cyberattacks - InvestAI EU Targets Musk’s X Digital Markets Act, EU fines
  • Data Leak

The EU’s AWS “Master Key”: How a Compromised Trivy Update Leaked 340GB of Data

Do Son April 3, 2026 0
Read More Read more about The EU’s AWS “Master Key”: How a Compromised Trivy Update Leaked 340GB of Data
The WordPress Killer? Cloudflare Unveils EmDash, the AI-Native CMS Built for the Serverless Epoch Cloudflare EmDash CMS
  • Technology

The WordPress Killer? Cloudflare Unveils EmDash, the AI-Native CMS Built for the Serverless Epoch

Do Son April 3, 2026 0
Read More Read more about The WordPress Killer? Cloudflare Unveils EmDash, the AI-Native CMS Built for the Serverless Epoch
OpenSSH 10.3 Patches Command Execution and “scp” Privilege Escalation OpenSSH 10.3 Patch SSH Command Injection CVE-2023-38408 OpenSSH Vulnerability CVE-2026-3497
  • Vulnerability Report

OpenSSH 10.3 Patches Command Execution and “scp” Privilege Escalation

Do Son April 3, 2026 0
Read More Read more about OpenSSH 10.3 Patches Command Execution and “scp” Privilege Escalation
The Resurrection of the Beam: Google Challenges AirDrop with Android 17’s “Tap to Share” Android 17 Tap to Share Gemini Scam Detection Galaxy S26 AI Security
  • Android

The Resurrection of the Beam: Google Challenges AirDrop with Android 17’s “Tap to Share”

Do Son April 3, 2026 0
Read More Read more about The Resurrection of the Beam: Google Challenges AirDrop with Android 17’s “Tap to Share”
Inside the Rapid Evolution of the BlankGrabber Stealer BlankGrabber Stealer Python Malware Analysis
  • Malware

Inside the Rapid Evolution of the BlankGrabber Stealer

Do Son April 3, 2026 0
Read More Read more about Inside the Rapid Evolution of the BlankGrabber Stealer
The Apache 2.0 Revolution: Google’s Gemma 4 Shatters the Open-Source Intelligence Ceiling Google Gemma 4 release
  • Technology

The Apache 2.0 Revolution: Google’s Gemma 4 Shatters the Open-Source Intelligence Ceiling

Do Son April 3, 2026 0
Read More Read more about The Apache 2.0 Revolution: Google’s Gemma 4 Shatters the Open-Source Intelligence Ceiling
The Lobster Craze: How OpenClaw is Triggering a High-Stakes AI Agent Arms Race in China Apple OpenClaw competitor Apple AI agent, Siri agentic capabilities, Apple computer-use agent OpenClaw Lobster
  • Technology

The Lobster Craze: How OpenClaw is Triggering a High-Stakes AI Agent Arms Race in China

Do Son April 3, 2026 0
Read More Read more about The Lobster Craze: How OpenClaw is Triggering a High-Stakes AI Agent Arms Race in China
Microsoft’s Declaration of Independence: The New MAI Models Challenging OpenAI and Google Microsoft MAI models
  • Technology

Microsoft’s Declaration of Independence: The New MAI Models Challenging OpenAI and Google

Do Son April 3, 2026 0
Read More Read more about Microsoft’s Declaration of Independence: The New MAI Models Challenging OpenAI and Google
Apple Severs All Payment Processing in Russia Following Government Mandates Apple Russia payment suspension iOS 26.3 Proximity Pairing, Apple DMA compliance 2026 Tap to Pay, Apple Pay Wireless charging Always-On Display, iOS 26 iOS 26, EU App APIs Rare Earths, Apple Supply Chain
  • Technology

Apple Severs All Payment Processing in Russia Following Government Mandates

Do Son April 3, 2026 0
Read More Read more about Apple Severs All Payment Processing in Russia Following Government Mandates
Critical 9.8 CVSS RCE Vulnerabilities Exposed in Progress ShareFile Progress ShareFile RCE Storage Zones Controller
  • Vulnerability Report

Critical 9.8 CVSS RCE Vulnerabilities Exposed in Progress ShareFile

Do Son April 3, 2026 0
Read More Read more about Critical 9.8 CVSS RCE Vulnerabilities Exposed in Progress ShareFile
Targeting the Cloud: IRGC Claims Strike on Oracle’s Dubai Data Sanctuary IRGC Oracle Cloud Dubai strike Oracle global layoffs 2026 Oracle Fusion Middleware Vulnerability CVE-2026-21992 Oracle Edge Cloud Vulnerability CVE-2026-21994 Oracle Critical RCE, EBS Marketing Flaws CVE-2024-21182 PoC Exploit Oracle EBS Auth Bypass, CVE-2025-61884
  • Technology

Targeting the Cloud: IRGC Claims Strike on Oracle’s Dubai Data Sanctuary

Do Son April 3, 2026 0
Read More Read more about Targeting the Cloud: IRGC Claims Strike on Oracle’s Dubai Data Sanctuary
The Human Variable: How a Masterful Phishing Ruse Hijacked Axios and 100 Million Users Axios proxy vulnerabilities prototype pollution gadget Axios Vulnerability Cloud Hijacking Axios npm supply chain attack Axios Vulnerability Node.js DoS CVE-2025-58754 CVE-2025-27152 Axios Vulnerability, Form-Data Flaw
  • Cybercriminals

The Human Variable: How a Masterful Phishing Ruse Hijacked Axios and 100 Million Users

Do Son April 3, 2026 0
Read More Read more about The Human Variable: How a Masterful Phishing Ruse Hijacked Axios and 100 Million Users
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-16723CVSS 9.0
    A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson\'s stock...
    Admin intel📅 Updated: Jul 25, 2026
  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-0770CVSS 9.8
    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2021-27137CVSS 8.1
    An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2026-6875CVSS 9.5
    ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability...
    Admin intel📅 Updated: Jul 18, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-66012CVSS 10.0
    SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp...
  • CVE-2026-61884CVSS 9.8
    The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation...
  • CVE-2026-62379CVSS 9.8
    ## Summary A pre-authentication remote code execution vulnerability affects OpenAM. The remote...
  • CVE-2026-62263
    ### Summary The GHSA-6c99-87fr-6q7r fix wrapped WebAuthn authenticator deserialization in an `ObjectInputFilter`...
  • CVE-2026-62835CVSS 9.3
    Improper authorization in Azure Portal allows an unauthorized attacker to disclose information...
  • CVE-2026-48021CVSS 9.1
    In epa4all, prior to version 2026-05-20, an attacker who can intercept the...
  • CVE-2026-59940CVSS 9.8
    ## Summary A type confusion issue in `seroval.fromJSON()` allowed attacker-controlled JSON input...
  • CVE-2026-58630CVSS 10.0
    Improper access control in Azure App Service allows an unauthorized attacker to...
  • CVE-2026-57106CVSS 10.0
    Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to...
  • CVE-2026-56163CVSS 10.0
    Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.