The Daily Cyber
Archives
Search...
Log in
Subscribe
PaperCut Replaces Emergency Patches for Exploited Flaw Chain
September 11, 2026
PaperCut Replaces Emergency Patches for Exploited Flaw Chain PaperCut’s actively exploited CVE-2026-81578 and CVE-2026-82078 can chain authentication bypass...
Chrome V8 zero-day patched after in-the-wild exploitation
September 4, 2026
Chrome V8 zero-day patched after in-the-wild exploitation Google patched Chrome CVE-2026-85046, an actively exploited V8 type-confusion flaw that could be...
SonicWall SMA1000 Zero-Days Hit the Edge
September 3, 2026
SonicWall SMA1000 Zero-Days Hit the Edge SonicWall says two exploited SMA1000 zero-days, CVE-2026-83548 and CVE-2026-83549, can be chained against exposed...
Artifactory Admin Token Bypass
September 2, 2026
Artifactory Admin Token Bypass JFrog Artifactory CVE-2026-82329 is reportedly being exploited to mint admin tokens on self-hosted servers, putting trusted...
PaperCut Zero-Days Spill the Print Queue
September 1, 2026
PaperCut Zero-Days Spill the Print Queue PaperCut NG/MF flaws CVE-2026-81578 and CVE-2026-82078 are being chained for auth bypass, RCE and data theft. Patch...
PaperCut Emergency Patch Release 2
August 31, 2026
PaperCut Emergency Patch Release 2 PaperCut NG/MF flaws CVE-2026-81578 and CVE-2026-82078 can chain authentication bypass into RCE on vulnerable servers;...
Gitea diffpatch RCE exposes thousands of servers
August 28, 2026
Gitea diffpatch RCE exposes thousands of servers CVE-2026-60004 lets Gitea repo writers abuse diffpatch to plant Git hooks and run commands as the service...
CISA Pushes Urgent NetScaler Patching
August 27, 2026
CISA Pushes Urgent NetScaler Patching CISA added Citrix NetScaler ADC and Gateway CVE-2026-8452 to KEV after exploitation reports, with federal remediation...
Gitea Diffpatch RCE Hits KEV
August 26, 2026
Gitea Diffpatch RCE Hits KEV CISA added Gitea CVE-2026-60004 to KEV amid active exploitation; the diffpatch/Git hook RCE is fixed in 1.27.1, so exposed self-...
Oracle WebLogic CVE-2026-21962 hits CISA KEV
August 25, 2026
Oracle WebLogic CVE-2026-21962 hits CISA KEV CISA added Oracle WebLogic CVE-2026-21962 to KEV after active exploitation; unauthenticated HTTP access can...
Keycloak Password Reset Flaw Exposes Account Takeover Risk
August 24, 2026
Keycloak Password Reset Flaw Exposes Account Takeover Risk Keycloak CVE-2026-18963 is a critical password-reset flow flaw that could let unauthenticated...
Microsoft Entra ID RCE sealed server-side
August 21, 2026
Microsoft Entra ID RCE sealed server-side Microsoft mitigated CVE-2026-69836, a CVSS 10.0 Entra ID deserialization RCE, on the server side with no customer...
Zimbra SNMP RCE Exploited in the Wild
August 20, 2026
Zimbra SNMP RCE Exploited in the Wild Attackers are exploiting CVE-2026-73570 in Zimbra Collaboration where optional zimbra-snmp notifications can enable...
Windows IKE RCE Added to CISA KEV
August 19, 2026
Windows IKE RCE Added to CISA KEV CISA says CVE-2026-33824, a Windows IKE double-free RCE, is now exploited in the wild. Patch affected Windows systems and...
GitLab GraphQL Flaw Puts Public Projects at Risk
August 18, 2026
GitLab GraphQL Flaw Puts Public Projects at Risk GitLab patched CVE-2026-19478, a critical GraphQL directive issue that could let unauthenticated attackers...
GeoServer Zero-Day Probing Moves Fast
August 17, 2026
GeoServer Zero-Day Probing Moves Fast Attackers began probing an unpatched GeoServer zero-day SQL injection within hours of public disclosure. Identify...
Cisco Firewall VPN DoS Zero-Day
August 14, 2026
Cisco Firewall VPN DoS Zero-Day Cisco patched CVE-2026-20349, an actively exploited ASA/FTD Remote Access SSL VPN flaw that can reload exposed firewalls and...
SharePoint Token Bypass Gets Weaponized
August 13, 2026
SharePoint Token Bypass Gets Weaponized Attackers are reportedly using a public PoC for Microsoft SharePoint CVE-2026-55040, a JWT authentication bypass that...
ShieldBreak Defender Zero-Day Raises Patch Urgency
August 12, 2026
ShieldBreak Defender Zero-Day Raises Patch Urgency ShieldBreak is reported as a Microsoft Defender zero-day tied to RoguePlanet CVE-2026-50656 that can turn...
ClamAV ZIP Parser Bugs Put Scanners at Risk
August 11, 2026
ClamAV ZIP Parser Bugs Put Scanners at Risk Cisco warned that ClamAV CVE-2026-20337 and CVE-2026-20338 can let crafted ZIP archives crash scanning, causing...
Older archives