24h | 7d | 30d

Overview

  • PaperCut
  • PaperCut MF/NG

28 Aug 2026
Published
31 Aug 2026
Updated

CVSS v4.0
HIGH (8.8)
EPSS
0.39%

Description

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

Statistics

  • 8 Posts
  • 2 Interactions

Last activity: 4 hours ago

Fediverse

Profile picture fallback

URGENT C-Suite Brief: CVE-2026-81578 active exploitation targets PaperCut NG/MF authentication flaws. Read our executive brief for rapid patch deployment, EDR monitoring, and access controls to safeguard your enterprise perimeter. thecybermind.co/4im9

  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback

A PaperCut zero-day (CVE-2026-81578, CVE-2026-82078) is exploited in the wild. Attackers run malicious SQL for RCE, and a Metasploit PoC is now public.

securityonline.info/papercut-z

  • 0
  • 0
  • 0
  • 16h ago

Bluesky

Profile picture fallback
We have published our @metasploit-r7.bsky.social exploit for the recent PaperCut MF and NG zero-day (CVE-2026-81578 + CVE-2026-82078) that is being actively exploited in-the-wild. github.com/rapid7/metas...
  • 0
  • 2
  • 0
  • 16h ago
Profile picture fallback
PaperCut disclosed two exploited vulnerabilities (CVE-2026-82078, CVE-2026-81578), enabling unauthenticated access to sensitive information and prompting immediate patching and isolation.
  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback
PaperCut NG and MF Flaws Exploited in the Wild, Prompting Emergency Security Patch #CVE202681578 #CVE202682078 #PaperCutMFvulnerability
  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback
~Cisa~ CISA added two actively exploited PaperCut NG/MF flaws to its KEV Catalog. - IOCs: CVE-2026-81578, CVE-2026-82078 - #CVE202681578 #CVE202682078 #ThreatIntel
  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback
~Cybergcca~ PaperCut flaws are exploited in the wild and added to CISA KEV; update affected products. - IOCs: CVE-2026-81578, CVE-2026-82078 - #CVE202681578 #CVE202682078 #PaperCut #ThreatIntel
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • PaperCut
  • PaperCut MF/NG

28 Aug 2026
Published
31 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.4)
EPSS
0.46%

Description

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.

Statistics

  • 8 Posts
  • 2 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

URGENT C-Suite Brief: CVE-2026-82078 active exploitation targets PaperCut NG/MF with unsafe reflection and arbitrary Java execution. Read our executive brief for rapid EDR tuning, least privilege controls, and asset integrity protection. thecybermind.co/4im9

  • 0
  • 0
  • 0
  • 3h ago
Profile picture fallback

A PaperCut zero-day (CVE-2026-81578, CVE-2026-82078) is exploited in the wild. Attackers run malicious SQL for RCE, and a Metasploit PoC is now public.

securityonline.info/papercut-z

  • 0
  • 0
  • 0
  • 16h ago

Bluesky

Profile picture fallback
We have published our @metasploit-r7.bsky.social exploit for the recent PaperCut MF and NG zero-day (CVE-2026-81578 + CVE-2026-82078) that is being actively exploited in-the-wild. github.com/rapid7/metas...
  • 0
  • 2
  • 0
  • 16h ago
Profile picture fallback
PaperCut disclosed two exploited vulnerabilities (CVE-2026-82078, CVE-2026-81578), enabling unauthenticated access to sensitive information and prompting immediate patching and isolation.
  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback
PaperCut NG and MF Flaws Exploited in the Wild, Prompting Emergency Security Patch #CVE202681578 #CVE202682078 #PaperCutMFvulnerability
  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback
~Cisa~ CISA added two actively exploited PaperCut NG/MF flaws to its KEV Catalog. - IOCs: CVE-2026-81578, CVE-2026-82078 - #CVE202681578 #CVE202682078 #ThreatIntel
  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback
~Cybergcca~ PaperCut flaws are exploited in the wild and added to CISA KEV; update affected products. - IOCs: CVE-2026-81578, CVE-2026-82078 - #CVE202681578 #CVE202682078 #PaperCut #ThreatIntel
  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback
~Checkpoint~ Attacks hit airports, healthcare and government while actively exploited flaws enable remote code execution. - IOCs: CVE-2026-82078, CVE-2026-18885, CVE-2026-75604 - #Ransomware #ThreatIntel #Vulnerabilities
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • langflow-ai
  • langflow

24 Mar 2026
Published
24 Mar 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
19.58%

KEV

Description

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.1, in the download_profile_picture function of the /profile_pictures/{folder_name}/{file_name} endpoint, the folder_name and file_name parameters are not strictly filtered, which allows the secret_key to be read across directories. Version 1.7.1 contains a patch.

Statistics

  • 2 Posts

Last activity: 12 hours ago

Fediverse

Profile picture fallback

🚨 In this week’s newsletter, we cover CVE-2026-33497, a high-severity path traversal vulnerability affecting Langflow that is seeing active exploitation.

We break down how attackers can steal the key used to sign login tokens with a single unauthenticated request and what defenders should do next.

Read the full analysis and protect your systems 👉 crowdsec.net/vulntracking-repo

  • 0
  • 0
  • 0
  • 12h ago

Bluesky

Profile picture fallback
🚨 In this week’s newsletter, we cover CVE-2026-33497, a high-severity path traversal vulnerability affecting Langflow that is seeing active exploitation. Read the full analysis and protect your systems 👉 www.crowdsec.net/vulntracking...
  • 0
  • 0
  • 0
  • 12h ago

Overview

  • Gitea
  • Gitea

26 Aug 2026
Published
26 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
84.55%

Description

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

Statistics

  • 2 Posts

Last activity: 9 hours ago

Fediverse

Profile picture fallback

Discover how a critical Gitea RCE vulnerability, combined with open registration, leaves thousands of servers exposed to ongoing cyberattacks.

meterpreter.org/gitea-rce-vuln

  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback
  • 0
  • 0
  • 0
  • 9h ago

Overview

  • WebPros
  • cPanel

29 Apr 2026
Published
11 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
98.53%

Description

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 16 hours ago

Fediverse

Profile picture fallback

Critical root vulnerability in cPanel and WHM! Attackers can gain full control of a server without any login credentials. CVE-2026-41940 is a critical cPanel/WHM flaw (CVSS 9.8) let attackers get root access with NO login. ~1.5M servers exposed. Exploited in the wild for months before the patch.

What you need to do now 👇

roothosts.com/critical-vulnera

#roothosts #cPanel #WHM #CyberSecurity #CVE202641940 #InfoSec

  • 1
  • 1
  • 0
  • 16h ago

Overview

  • jfrog
  • artifactory

28 Aug 2026
Published
31 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.38%

KEV

Description

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 10 hours ago

Bluesky

Profile picture fallback
JFrog Security Advisories: CVE-2026-82329 - Potential authentication bypass leading to administrative access in Artifactory
  • 1
  • 0
  • 0
  • 10h ago

Overview

  • z-galaxy
  • zbus_polkit
  • zbus_polkit

31 Aug 2026
Published
31 Aug 2026
Updated

CVSS v4.0
HIGH (7.3)
EPSS
Pending

KEV

Description

Subject::new_for_owner() in the zbus_polkit crate encodes the uid entry of a unix-process polkit subject as an unsigned 32-bit integer (D-Bus type u), whereas the org.freedesktop.PolicyKit1.Authority interface specifies a signed 32-bit integer (D-Bus type i). Because of this type mismatch, polkit silently discards the caller-supplied UID and instead determines the subject's owner itself by looking up the PID in /proc, a lookup that is inherently subject to a time-of-check/time-of-use race. Consequently, an application that passes a UID obtained from a trustworthy source — for example SO_PEERCRED Unix socket peer credentials — in order to defend against PID reuse receives no protection, and the supplied UID has no effect on the authorization decision. A local unprivileged attacker who can cause an authorized process to terminate and then win the race to have their own process assigned the same PID can be authorized under the identity of the terminated process, bypassing the polkit authorization check and performing actions the attacker is not entitled to. This issue affects zbus_polkit before 5.1.0.

Statistics

  • 1 Post
  • 6 Interactions

Last activity: 10 hours ago

Fediverse

Overview

  • Linux
  • Linux

24 Jun 2026
Published
05 Aug 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.12%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: io_uring/poll: fix signed comparison in io_poll_get_ownership() io_poll_get_ownership() uses a signed comparison to check whether poll_refs has reached the threshold for the slowpath: if (unlikely(atomic_read(&req->poll_refs) >= IO_POLL_REF_BIAS)) atomic_read() returns int (signed). When IO_POLL_CANCEL_FLAG (BIT(31)) is set in poll_refs, the value becomes negative in signed arithmetic, so the >= 128 comparison always evaluates to false and the slowpath is never taken. Fix this by casting the atomic_read() result to unsigned int before the comparison, so that the cancel flag is treated as a large positive value and correctly triggers the slowpath.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 12 hours ago

Fediverse

Profile picture fallback

A public proof-of-concept for the CVE-2026-52933 privilege escalation flaw is available. This Linux kernel io_uring exploit carries a CVSS 7.8 score.

securityonline.info/cve-2026-5

  • 0
  • 2
  • 0
  • 12h ago

Overview

  • Pending

21 Nov 2023
Published
28 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
43.20%

Description

An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 10 hours ago

Fediverse

Profile picture fallback

URGENT C-Suite Brief: CVE-2023-49105 active exploitation targets ownCloud authentication flaws. Read our executive brief for rapid mitigation steps, identity governance controls, and asset integrity protocols to protect your enterprise perimeter. thecybermind.co/v5jn

  • 0
  • 1
  • 0
  • 10h ago

Overview

  • itsourcecode
  • Online Medicine Delivery System

31 Aug 2026
Published
31 Aug 2026
Updated

CVSS v4.0
MEDIUM (6.9)
EPSS
0.26%

KEV

Description

A vulnerability was detected in itsourcecode Online Medicine Delivery System 1.0. This affects the function loadResultList of the file /index.php?q=product of the component Product Search Interface. Performing a manipulation of the argument Search results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.

Statistics

  • 1 Post

Last activity: 14 hours ago

Fediverse

Profile picture fallback

CVE-2026-82613 - High severity SQLi in ItsSourceCode Online Medicine Delivery System 1.0. Public exploit available. CVSS 7.3. Mitigate immediately. #CVE #infosec #cybersecurity

valtersit.com/cve/CVE-2026-826

  • 0
  • 0
  • 0
  • 14h ago
Showing 1 to 10 of 25 CVEs