Skip to content
September 16, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Hundreds of Millions Affected: New “nginx-poolslip” Zero-Day Weaponizes ASLR Bypass for Remote Code Execution nginx-poolslip zero-day Nginx 1.31.0 RCE
  • Vulnerability Report

Hundreds of Millions Affected: New “nginx-poolslip” Zero-Day Weaponizes ASLR Bypass for Remote Code Execution

Do Son May 21, 2026 0
Read More Read more about Hundreds of Millions Affected: New “nginx-poolslip” Zero-Day Weaponizes ASLR Bypass for Remote Code Execution
Signature Bypass Alert: Critical Coder Flaw (CVE-2026-46354) Exposes Git Keys and Developer Tokens Coder Token Theft Vulnerability CVE-2026-46354 Azure Identity
  • Vulnerability Report

Signature Bypass Alert: Critical Coder Flaw (CVE-2026-46354) Exposes Git Keys and Developer Tokens

Do Son May 21, 2026 0
Read More Read more about Signature Bypass Alert: Critical Coder Flaw (CVE-2026-46354) Exposes Git Keys and Developer Tokens
CVSS 10.0 Alert: Critical Cisco Secure Workload Exploit Grants Unauthenticated Site Admin Access Cisco Secure Workload Vulnerability CVE-2026-20223 CVSS 10
  • Vulnerability Report

CVSS 10.0 Alert: Critical Cisco Secure Workload Exploit Grants Unauthenticated Site Admin Access

Do Son May 21, 2026 0
Read More Read more about CVSS 10.0 Alert: Critical Cisco Secure Workload Exploit Grants Unauthenticated Site Admin Access
Unpatched CVSS 10 Alert: ChromaDB Python Server Grants Pre-Auth RCE via Malicious Hugging Face Models ChromaDB Pre-Auth RCE CVE-2026-45829
  • Vulnerability Report

Unpatched CVSS 10 Alert: ChromaDB Python Server Grants Pre-Auth RCE via Malicious Hugging Face Models

Do Son May 21, 2026 0
Read More Read more about Unpatched CVSS 10 Alert: ChromaDB Python Server Grants Pre-Auth RCE via Malicious Hugging Face Models
Double Critical Threat: Google Chrome Rushes Out Urgent Fixes for WebRTC and UI Sandbox Flaws Google Chrome Security Update CVE-2026-9111 Critical Patch
  • Vulnerability Report

Double Critical Threat: Google Chrome Rushes Out Urgent Fixes for WebRTC and UI Sandbox Flaws

Do Son May 21, 2026 0
Read More Read more about Double Critical Threat: Google Chrome Rushes Out Urgent Fixes for WebRTC and UI Sandbox Flaws
Exploited in the Wild: Critical Drupal SQL Injection (CVE-2026-9082) Grants Attacker Root Access CVE-2022-39261 Drupal SQL Injection Vulnerability CVE-2026-9082 PostgreSQL Flaw
  • Vulnerability Report

Exploited in the Wild: Critical Drupal SQL Injection (CVE-2026-9082) Grants Attacker Root Access

Do Son May 21, 2026 0
Read More Read more about Exploited in the Wild: Critical Drupal SQL Injection (CVE-2026-9082) Grants Attacker Root Access
Unpatched SGLang Vulnerabilities (CVE-2026-7301) Expose AI Inference Pipelines to RCE SGLang RCE Vulnerability CVE-2026-7301 Zero-Day SGLang RCE AI Infrastructure Vulnerability
  • Vulnerability Report

Unpatched SGLang Vulnerabilities (CVE-2026-7301) Expose AI Inference Pipelines to RCE

Do Son May 21, 2026 0
Read More Read more about Unpatched SGLang Vulnerabilities (CVE-2026-7301) Expose AI Inference Pipelines to RCE
Critical RCE Exploits Exposed: Apache OFBiz Patches Severe Authentication Bypass Flaws CVE-2022-25371 - CVE-2025-26865 Apache OFBiz RCE Vulnerability CVE-2026-45434 Authentication Bypass
  • Vulnerability Report

Critical RCE Exploits Exposed: Apache OFBiz Patches Severe Authentication Bypass Flaws

Do Son May 21, 2026 0
Read More Read more about Critical RCE Exploits Exposed: Apache OFBiz Patches Severe Authentication Bypass Flaws
Public Exploit Exposes Root Privilege Escalation Flaw in VMware Fusion VMware Fusion TOCTOU Exploit CVE-2026-41702 PoC
  • Vulnerability

Public Exploit Exposes Root Privilege Escalation Flaw in VMware Fusion

Do Son May 21, 2026 0
Read More Read more about Public Exploit Exposes Root Privilege Escalation Flaw in VMware Fusion
Secret Blizzard Transforms Kazuar into a Modular P2P Botnet Ecosystem Kazuar P2P Botnet Secret Blizzard Malware Evolution
  • Malware

Secret Blizzard Transforms Kazuar into a Modular P2P Botnet Ecosystem

Do Son May 20, 2026 0
Read More Read more about Secret Blizzard Transforms Kazuar into a Modular P2P Botnet Ecosystem
Inside UNC6671’s “BlackFile” Cloud Extortion Campaigns UNC6671 BlackFile Cloud Attacks AiTM MFA Bypass Okta Microsoft
  • Cybercriminals

Inside UNC6671’s “BlackFile” Cloud Extortion Campaigns

Do Son May 20, 2026 0
Read More Read more about Inside UNC6671’s “BlackFile” Cloud Extortion Campaigns
Google Drops Antigravity 2.0 to Orchestrate Teams of Autonomous Coding Agents Gemini CLI deprecation notice as Google moves developers to the Antigravity CLI terminal tool Google Antigravity 2.0 release
  • Technology

Google Drops Antigravity 2.0 to Orchestrate Teams of Autonomous Coding Agents

Do Son May 20, 2026 0
Read More Read more about Google Drops Antigravity 2.0 to Orchestrate Teams of Autonomous Coding Agents
Zero-Trust Voice: Discord Finalizes Mandatory “DAVE” Encryption for All Audio and Video Streams DAVE protocol Discord DAVE protocol encryption
  • Technology

Zero-Trust Voice: Discord Finalizes Mandatory “DAVE” Encryption for All Audio and Video Streams

Do Son May 20, 2026 0
Read More Read more about Zero-Trust Voice: Discord Finalizes Mandatory “DAVE” Encryption for All Audio and Video Streams
Velvet Chollima Leaves Backend Keys Inside Critical GitLab Dead-Drop Malware Velvet Chollima GitLab Malware Tralert FX EV Certificate
  • Malware

Velvet Chollima Leaves Backend Keys Inside Critical GitLab Dead-Drop Malware

Do Son May 20, 2026 0
Read More Read more about Velvet Chollima Leaves Backend Keys Inside Critical GitLab Dead-Drop Malware
Kernel Chaos: Linus Torvalds Blasts “Drive-By” AI Bug Reports Paralyzing Linux Maintainers Linus Torvalds AI bug reports Linux Kernel 7.0 Linux EFI Zboot - CVE-2022-42719 Linux KVM Intel AMX kernel panic, KVM guest host crash 2025
  • Linux

Kernel Chaos: Linus Torvalds Blasts “Drive-By” AI Bug Reports Paralyzing Linux Maintainers

Do Son May 20, 2026 0
Read More Read more about Kernel Chaos: Linus Torvalds Blasts “Drive-By” AI Bug Reports Paralyzing Linux Maintainers
Kimsuky Core Upgrades Weaponize Rust Backdoors and VSCode Remote Tunneling Kimsuky HelloDoor Backdoor VSCode Tunneling Espionage
  • Malware

Kimsuky Core Upgrades Weaponize Rust Backdoors and VSCode Remote Tunneling

Do Son May 20, 2026 0
Read More Read more about Kimsuky Core Upgrades Weaponize Rust Backdoors and VSCode Remote Tunneling
Google Cloud Abruptly Shuts Down Railway, Sparking Catastrophic Infrastructure Outage Railway infrastructure outage GCP suspension 2026
  • Technology

Google Cloud Abruptly Shuts Down Railway, Sparking Catastrophic Infrastructure Outage

Do Son May 20, 2026 0
Read More Read more about Google Cloud Abruptly Shuts Down Railway, Sparking Catastrophic Infrastructure Outage
Inside the Breach: How TeamPCP Poisoned a VS Code Extension to Exfiltrate 3,800 GitHub Repositories GitHub source code breach TeamPCP 2026
  • Data Leak

Inside the Breach: How TeamPCP Poisoned a VS Code Extension to Exfiltrate 3,800 GitHub Repositories

Do Son May 20, 2026 0
Read More Read more about Inside the Breach: How TeamPCP Poisoned a VS Code Extension to Exfiltrate 3,800 GitHub Repositories
Multi-Stage PyInstaller Loader Weaponizes AMSI Patching to Deploy XWorm RAT NATS-as-C2 Sysdig CVE-2026-33017 Langflow RCE Microsoft Phone Link Hijack CloudZ Pheno Plugin Insider Threat BlackCat (ALPHV) OFAC Sanctions DPRK IT Workers Transparent Tribe APT36 React2Shell, EtherRAT SideWinder Espionage, Netlify Phishing DDNS Abuse, C2 Infrastructure Hacking Health Club
  • Malware

Multi-Stage PyInstaller Loader Weaponizes AMSI Patching to Deploy XWorm RAT

Do Son May 20, 2026 0
Read More Read more about Multi-Stage PyInstaller Loader Weaponizes AMSI Patching to Deploy XWorm RAT
The Missed Token: Grafana Labs Suffers Source Code Theft via Shai-Hulud npm Worm Campaign CVE-2023-1550 Grafana Labs Cyberattack Mini Shai-Hulud npm Worm
  • Data Leak

The Missed Token: Grafana Labs Suffers Source Code Theft via Shai-Hulud npm Worm Campaign

Do Son May 20, 2026 0
Read More Read more about The Missed Token: Grafana Labs Suffers Source Code Theft via Shai-Hulud npm Worm Campaign
Critical 9.2 CVSS: NGINX JavaScript Module Flaw (CVE-2026-8711) Triggers Heap Buffer Overflows NGINX JavaScript Module Vulnerability CVE-2026-8711 NGINX 1.30.1 Security Update CVE-2026-42945 RCE NGINX Vulnerability CVE-2026-1642 NGINX Github - CVE-2025-23419
  • Vulnerability Report

Critical 9.2 CVSS: NGINX JavaScript Module Flaw (CVE-2026-8711) Triggers Heap Buffer Overflows

Do Son May 20, 2026 0
Read More Read more about Critical 9.2 CVSS: NGINX JavaScript Module Flaw (CVE-2026-8711) Triggers Heap Buffer Overflows
Beyond the Phone: Google Unveils Wear OS 7 with “Wear Widgets” and Wrist-Bound AI Agents Wear OS 7 update Google IO 2026
  • Technology

Beyond the Phone: Google Unveils Wear OS 7 with “Wear Widgets” and Wrist-Bound AI Agents

Do Son May 20, 2026 0
Read More Read more about Beyond the Phone: Google Unveils Wear OS 7 with “Wear Widgets” and Wrist-Bound AI Agents
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-89026CVSS 9.8
    The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT...
    Admin intel📅 Updated: Sep 16, 2026
  • CVE-2026-58704
    In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This...
    Admin intel📅 Updated: Sep 16, 2026
  • CVE-2026-87886
    Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin...
    Admin intel📅 Updated: Sep 16, 2026
  • CVE-2026-87827CVSS 10.0
    Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-78006CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-39364
    Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-27540CVSS 9.0
    Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-76461CVSS 9.8
    A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an...
    CISA KEV📅 Added to KEV: Sep 14, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-86106CVSS 9.6
    An unauthenticated actor with network access to the private HA interconnect may...
  • CVE-2026-73453CVSS 10.0
    An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary...
  • CVE-2026-27565CVSS 9.8
    An unauthenticated remote attacker can upload a malicious IODD file that places...
  • CVE-2026-27546CVSS 9.8
    An unauthenticated remote attacker can exploit an authentication bypass in the _account_log...
  • CVE-2026-73447CVSS 9.1
    A privileged attacker can exploit certain operation to execute arbitrary commands with...
  • CVE-2026-12793CVSS 9.8
    The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable...
  • CVE-2026-14349CVSS 9.8
    The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is...
  • CVE-2026-73807CVSS 9.8
    The mySCADA myPRO Manager command API does not properly enforce authentication for...
  • CVE-2026-81855CVSS 9.1
    A hardcoded cryptographic client authentication key vulnerability exists in the robot testing...
  • CVE-2026-78225CVSS 9.0
    A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller...
Powered by CVE WATCHTOWER

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.