Skip to content
October 8, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • VPS

VPS

Virtualizor Supply-Chain Attack: BGP Hijack Plants Backdoors Virtualizor supply-chain attack via BGP hijack delivering a malicious update that plants a root backdoor on VPS hosts
  • Cybercriminals

Virtualizor Supply-Chain Attack: BGP Hijack Plants Backdoors

Do Son September 1, 2026 0
The veteran VPS server management panel Virtualizor has confirmed a serious supply-chain attack. Between 28 and 30...
Read More Read more about Virtualizor Supply-Chain Attack: BGP Hijack Plants Backdoors
HostDzire Ransomware Attack Causes Complete Data Loss HostDzire ransomware attack on VMware infrastructure and encrypted VPS virtual disks
  • Malware

HostDzire Ransomware Attack Causes Complete Data Loss

Do Son August 6, 2026 0
Ransomware Intrusion Erases User Data When utilizing Virtual Private Server (VPS) infrastructure, performing routine data backups remains...
Read More Read more about HostDzire Ransomware Attack Causes Complete Data Loss
Cloud Attack: Extortionists Breach AWS, Expose 90,000 Variables cloud attack
  • Cyber Security

Cloud Attack: Extortionists Breach AWS, Expose 90,000 Variables

Do Son August 18, 2024 0
Palo Alto Networks has uncovered a large-scale ransomware campaign that has impacted over 100,000 domains. The perpetrators...
Read More Read more about Cloud Attack: Extortionists Breach AWS, Expose 90,000 Variables

Search

Translation

CVE ALERTS
πŸ“ˆ

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

πŸ›‘οΈ

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

πŸ™

GitHub Issues
Auto-create alert tickets without duplication.

πŸ“¬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

πŸ”€

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days β†’

🚨 Active Exploits in the Wild

  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-93836CVSS 7.2
    The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \'qty\'...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-21589CVSS 9.3
    This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2025-55182CVSS 10.0
    A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including...
    CISA KEV📅 Added to KEV: Dec 5, 2025📅 Updated: Oct 8, 2026
  • CVE-2024-50623CVSS 9.8
    In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload...
    CISA KEV📅 Added to KEV: Dec 13, 2024📅 Updated: Oct 8, 2026
  • CVE-2021-41277CVSS 10.0
    Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with...
    CISA KEV📅 Added to KEV: Nov 12, 2024📅 Updated: Oct 8, 2026
  • CVE-2026-107510CVSS 9.1
    An authenticated high privilege user can inject arguments in troubleshooting commands resulting in privilege escalation.
    📅 Updated: Oct 8, 2026
  • CVE-2025-43027CVSS 9.8
    A critical severity vulnerability has been identified in the ALPR Manager role of Security Center that could allow...
    📅 Updated: Oct 8, 2026
  • CVE-2025-67511CVSS 9.6
    Cybersecurity AI (CAI) is an open-source framework for building and deploying AI-powered offensive and defensive automation. Versions 0.5.9...
    📅 Updated: Oct 8, 2026
  • CVE-2025-13764CVSS 9.8
    The WP CarDealer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including,...
    📅 Updated: Oct 8, 2026
  • CVE-2026-105110CVSS 9.3
    OS Command Injection in the login.xgi CGI endpoint in Iskratel Innbox GPON ONT devices allows an unauthenticated remote...
    📅 Updated: Oct 8, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
Β© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.