← Back
VulnerabilityCISA Advisories·5 hours ago

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two PaperCut NG/MF vulnerabilities (CVE-2026-81578 and CVE-2026-82078) to its Known Exploited Vulnerabilities Catalog based on active exploitation evidence. Federal agencies are required under BOD 26-04 to prioritize rapid remediation of these high-risk vulnerabilities on publicly exposed assets, while CISA encourages all organizations to adopt similar risk-based vulnerability management practices. Organizations aware of other exploited vulnerabilities can nominate them for catalog inclusion through CISA's KEV Nomination Form if they have a CVE ID, exploitation evidence, and mitigation guidance available.

Read full article at CISA Advisories

Related Articles

VulnerabilityCybersecurity Dive·1 hour ago

PaperCut issues emergency patches as threat actors target chained vulnerabilities

PaperCut has issued emergency patches to address chained vulnerabilities that threat actors exploited in attacks targeting the company's print management software. The attacks primarily focused on higher education customers during 2023, highlighting the risk posed by coordinated vulnerability exploitation in widely-deployed enterprise software.

VulnerabilityHelp Net Security·2 hours ago

Attackers plant remote access tools on compromised PaperCut servers

Threat actors exploiting PaperCut zero-day vulnerabilities are installing legitimate remote access tools on compromised internet-facing Application Servers to maintain persistent access. PaperCut Software disclosed the ongoing campaign and advised customers running NG and MF print management solutions to immediately restrict web access to trusted IP addresses only. The covert deployment of these tools demonstrates attackers' intent to establish long-term footholds on affected infrastructure.

VulnerabilitySecurityWeek·3 hours ago

ServiceNow Patches 3 Critical Code Injection Vulnerabilities

ServiceNow has released patches addressing three critical code injection vulnerabilities that could allow attackers to execute arbitrary code on affected systems. Exploitation of these flaws could enable unauthorized access to sensitive data or allow attackers to modify information within ServiceNow instances.