Skip to content
September 16, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Agentic AI is Automating Live Intrusions in Latin America Agentic AI Cyber Attacks SHADOW-AETHER Threat Groups
  • Cybercriminals

Agentic AI is Automating Live Intrusions in Latin America

Do Son May 13, 2026 0
Read More Read more about Agentic AI is Automating Live Intrusions in Latin America
JDownloader Site Breach Installs Rootkits that Kill Your Antivirus Kali365 phishing platform EmEditor Supply Chain Attack, WALSHAM INVESTMENTS LIMITED EggStreme, fileless malware North Korea Cybercrime, Remote IT Job Fraud RedDelta APT
  • Malware

JDownloader Site Breach Installs Rootkits that Kill Your Antivirus

Do Son May 13, 2026 0
Read More Read more about JDownloader Site Breach Installs Rootkits that Kill Your Antivirus
GemStuffer: Attackers Weaponize RubyGems as a Covert Data Drop for UK Gov Scraping GemStuffer RubyGems Campaign RubyGems Data Exfiltration TanStack npm Compromise Supply Chain Attack DNS Hijacking APT28 (Fancy Bear) OpenVSX Supply Chain Attack Checkmarx Plugin Breach Stryker Cyberattack CISA Alert Trans-Regional Cyber Conflict Operation Epic Fury Cyber Operation MacroMaze APT28 Cyber Espionage Notepad++ Supply Chain Attack Lotus Blossom Group Defense Industrial Base Threats GTIG Report APT28 Operation Neusploit CVE-2026-21509 Bookworm Malware
  • Malware

GemStuffer: Attackers Weaponize RubyGems as a Covert Data Drop for UK Gov Scraping

Do Son May 13, 2026 0
Read More Read more about GemStuffer: Attackers Weaponize RubyGems as a Covert Data Drop for UK Gov Scraping
Pre-Auth RCE Exposed: Apache HTTP Server Vulnerability and Exploit Code Hit the Public Apache HTTP Server RCE CVE-2026-23918 PoC
  • Vulnerability

Pre-Auth RCE Exposed: Apache HTTP Server Vulnerability and Exploit Code Hit the Public

Do Son May 13, 2026 0
Read More Read more about Pre-Auth RCE Exposed: Apache HTTP Server Vulnerability and Exploit Code Hit the Public
Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days BitLocker Bypass PoC Windows Zero-Day Exploit 2026
  • Vulnerability Report

Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days

Do Son May 13, 2026 0
Read More Read more about Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days
Critical-Severity XSS Flaws Uncovered in Siemens SIMATIC S7 Web Servers Siemens SIMATIC S7 Vulnerability Industrial PLC XSS CVE-2024-44102 - Siemens TeleControl Server Basic
  • Vulnerability Report

Critical-Severity XSS Flaws Uncovered in Siemens SIMATIC S7 Web Servers

Do Son May 13, 2026 0
Read More Read more about Critical-Severity XSS Flaws Uncovered in Siemens SIMATIC S7 Web Servers
9.8 Severity Alert: Malicious Git Branches Can Hijack Your WebdriverIO Build Servers WebdriverIO Command Injection CVE-2026-25244
  • Vulnerability Report

9.8 Severity Alert: Malicious Git Branches Can Hijack Your WebdriverIO Build Servers

Do Son May 13, 2026 0
Read More Read more about 9.8 Severity Alert: Malicious Git Branches Can Hijack Your WebdriverIO Build Servers
Microsoft Patch Tuesday May 2026 Fixes 137 Flaws, Including Netlogon RCE and Critical SSO Bypass Microsoft Patch Tuesday May 2026 Netlogon RCE CVE-2026-41089 SharePoint Exploit Patch Tuesday Windows DWM Zero-Day CVE-2026-21519 CVE-2024-49039 Microsoft Patch Tuesday March 2025
  • Vulnerability Report

Microsoft Patch Tuesday May 2026 Fixes 137 Flaws, Including Netlogon RCE and Critical SSO Bypass

Do Son May 13, 2026 0
Read More Read more about Microsoft Patch Tuesday May 2026 Fixes 137 Flaws, Including Netlogon RCE and Critical SSO Bypass
CVSS 10 Alert: SandboxJS Critical Escape Vulnerability Enables Host Takeover SandboxJS Sandbox Escape CVE-2026-43898 RCE
  • Vulnerability Report

CVSS 10 Alert: SandboxJS Critical Escape Vulnerability Enables Host Takeover

Do Son May 13, 2026 0
Read More Read more about CVSS 10 Alert: SandboxJS Critical Escape Vulnerability Enables Host Takeover
PraisonAI CVE-2026-44338 Exploited in the Wild Hours After Patch Disclosure PraisonAI Authentication Bypass Exploited in the Wild CVE-2026-44338
  • Vulnerability Report

PraisonAI CVE-2026-44338 Exploited in the Wild Hours After Patch Disclosure

Do Son May 13, 2026 0
Read More Read more about PraisonAI CVE-2026-44338 Exploited in the Wild Hours After Patch Disclosure
9.8 Critical Alert: One-Byte Heap Corruption in Exim Exposes Global Mail Servers to Takeover Exim RCE Vulnerability CVE-2026-45185 GnuTLS
  • Vulnerability Report

9.8 Critical Alert: One-Byte Heap Corruption in Exim Exposes Global Mail Servers to Takeover

Do Son May 13, 2026 0
Read More Read more about 9.8 Critical Alert: One-Byte Heap Corruption in Exim Exposes Global Mail Servers to Takeover
Fortinet Critical Alert: 9.1 Severity Flaws in FortiSandbox and FortiAuthenticator Risk Remote Takeover CVE-2023-36553 Fortinet Critical Vulnerabilities FortiSandbox CVE-2026-26083
  • Vulnerability Report

Fortinet Critical Alert: 9.1 Severity Flaws in FortiSandbox and FortiAuthenticator Risk Remote Takeover

Do Son May 13, 2026 0
Read More Read more about Fortinet Critical Alert: 9.1 Severity Flaws in FortiSandbox and FortiAuthenticator Risk Remote Takeover
Multiple Memory Flaws in Dnsmasq Threaten Millions of Connected Devices dnsmasq Vulnerabilities DNS Cache Poisoning
  • Vulnerability Report

Multiple Memory Flaws in Dnsmasq Threaten Millions of Connected Devices

Do Son May 13, 2026 0
Read More Read more about Multiple Memory Flaws in Dnsmasq Threaten Millions of Connected Devices
Critical Casdoor Vulnerability CVE-2026-44213 Allows Arbitrary File Overwrites Casdoor Arbitrary File Write CVE-2026-44213 Path Traversal
  • Vulnerability Report

Critical Casdoor Vulnerability CVE-2026-44213 Allows Arbitrary File Overwrites

Do Son May 13, 2026 0
Read More Read more about Critical Casdoor Vulnerability CVE-2026-44213 Allows Arbitrary File Overwrites
Critical Siemens ROS# Flaw Enables Arbitrary File Access and Host Takeover ROS# Path Traversal CVE-2026-41551 Siemens SIMATIC Auth Bypass, CVE-2025-40771 CVE-2024-22039 & CVE-2024-49775 CVE-2024-56336
  • Vulnerability Report

Critical Siemens ROS# Flaw Enables Arbitrary File Access and Host Takeover

Do Son May 12, 2026 0
Read More Read more about Critical Siemens ROS# Flaw Enables Arbitrary File Access and Host Takeover
Google Confirms First AI-Generated Zero-Day Exploit Found in the Wild AI-Built Zero-Day Exploit Google Threat Intelligence Report 2026
  • Cybercriminals

Google Confirms First AI-Generated Zero-Day Exploit Found in the Wild

Do Son May 12, 2026 0
Read More Read more about Google Confirms First AI-Generated Zero-Day Exploit Found in the Wild
Critical cPanel Auth Bypass CVE-2026-41940 Exploited by Thousands cPanel Authentication Bypass CVE-2026-41940 Exploitation
  • Vulnerability Report

Critical cPanel Auth Bypass CVE-2026-41940 Exploited by Thousands

Do Son May 12, 2026 0
Read More Read more about Critical cPanel Auth Bypass CVE-2026-41940 Exploited by Thousands
TrickMo’s Stealthy Upgrade: Android Banking Malware is Pivoting to The Open Network TrickMo banking trojan TON network malware
  • Malware

TrickMo’s Stealthy Upgrade: Android Banking Malware is Pivoting to The Open Network

Do Son May 12, 2026 0
Read More Read more about TrickMo’s Stealthy Upgrade: Android Banking Malware is Pivoting to The Open Network
PamDOORa Backdoor Targets Linux PAM Stack to Steal Passwords and Wipe Logs PamDOORa Linux Backdoor PAM Stack Credential Harvesting
  • Malware

PamDOORa Backdoor Targets Linux PAM Stack to Steal Passwords and Wipe Logs

Do Son May 12, 2026 0
Read More Read more about PamDOORa Backdoor Targets Linux PAM Stack to Steal Passwords and Wipe Logs
Critical 9.8 Alert: Hard-Coded Credentials in Dell ECS and ObjectScale Leave Filesystems Exposed Dell ECS Security Update CVE-2026-40636 Hard-coded Credentials Dell Business Price Increase, RAM and SSD Shortage 2025 Dell Data Lakehouse, Critical Privilege Escalation Authentication Bypass Vulnerability CVE-2025-22398
  • Vulnerability Report

Critical 9.8 Alert: Hard-Coded Credentials in Dell ECS and ObjectScale Leave Filesystems Exposed

Do Son May 12, 2026 0
Read More Read more about Critical 9.8 Alert: Hard-Coded Credentials in Dell ECS and ObjectScale Leave Filesystems Exposed
APT37’s New “Python-in-a-Cat” Malware Uses Environment Variable Obfuscation APT37 Phishing Campaign Python Malware Obfuscation
  • Malware

APT37’s New “Python-in-a-Cat” Malware Uses Environment Variable Obfuscation

Do Son May 12, 2026 0
Read More Read more about APT37’s New “Python-in-a-Cat” Malware Uses Environment Variable Obfuscation
Critical 9.6 Severity: SAP May 2026 Patch Day Fixes Dangerous S/4HANA and Commerce Cloud Flaws SAP Security Patch May 2026 CVE-2026-34260 S/4HANA CVE-2024-22127 - CVE-2025-27434 SAP Solution Manager Code Injection, Critical SAP Patch
  • Vulnerability Report

Critical 9.6 Severity: SAP May 2026 Patch Day Fixes Dangerous S/4HANA and Commerce Cloud Flaws

Do Son May 12, 2026 0
Read More Read more about Critical 9.6 Severity: SAP May 2026 Patch Day Fixes Dangerous S/4HANA and Commerce Cloud Flaws
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-89026CVSS 9.8
    The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT...
    Admin intel📅 Updated: Sep 16, 2026
  • CVE-2026-58704
    In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This...
    Admin intelCISA KEV📅 Added to KEV: Sep 16, 2026📅 Updated: Sep 16, 2026
  • CVE-2026-87886
    Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin...
    Admin intel📅 Updated: Sep 16, 2026
  • CVE-2026-87827CVSS 10.0
    Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-78006CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-39364
    Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-27540CVSS 9.0
    Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-76461CVSS 9.8
    A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an...
    CISA KEV📅 Added to KEV: Sep 14, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-92398CVSS 9.1
    A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue...
  • CVE-2026-92397CVSS 9.1
    A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this...
  • CVE-2025-59953CVSS 9.8
    LMDeploy is a toolkit for compressing, deploying, and serving large language models....
  • CVE-2026-70416CVSS 10.0
    Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data...
  • CVE-2026-92395CVSS 9.1
    @fastify/proxy-addr is a Fastify plugin that determines a request's client address behind...
  • CVE-2026-91843CVSS 9.8
    A stack overflow during the unauthenticated login process may allow an attacker...
  • CVE-2026-90049CVSS 9.3
    In the Linux kernel, the following vulnerability has been resolved: net: skbuff:...
  • CVE-2026-90048CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix...
  • CVE-2026-90042CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: ceph: properly...
  • CVE-2026-90038CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent...
Powered by CVE WATCHTOWER

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.