PaperCut Zero-Day: Active Exploitation and Pre-Auth RCE
PaperCut NG and PaperCut MF are currently experiencing active exploitation of a zero-day vulnerability that allows unauthenticated remote code execution. Huntress has successfully reproduced the pre-authentication RCE attack chain and released guidance for immediate patching and exposure assessment to help organizations secure their systems against this threat.
CISA has added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, including a critical authentication flaw in ownCloud Server's WebDAV functionality with a CVSS score of 9.8, alongside flaws in the Linux Kernel and JFrog Artifactory. These additions to the KEV catalog indicate that threat actors are actively exploiting these vulnerabilities in the wild, making them priority targets for patching across affected organizations.
CISA has highlighted that the majority of actively exploited vulnerabilities represent security flaws that should have been eliminated years ago, pointing to persistent organizational culture issues and incomplete adoption of Secure by Design principles as root causes. The agency's assessment suggests that systemic gaps in security practices continue to leave organizations vulnerable to preventable attacks rather than zero-day exploits.
ServiceNow addressed four security vulnerabilities affecting its AI Platform, with three receiving a critical CVSS 10.0 rating that could allow unauthenticated attackers to execute code and SQL queries under certain conditions. The vendor deployed patches to its hosted instances and made updates available to partners and self-hosted customers, though organizations running self-hosted deployments will need to apply fixes independently. The disclosure underscores the importance of promptly patching critical flaws in widely-deployed enterprise platforms.
A critical Microsoft Entra ID vulnerability was exploited before remediation, while emerging threats from autonomous AI agents and cross-border cybercrime networks demonstrate how attackers are targeting both technical infrastructure and human trust across cloud services and digital platforms. Recent developments spanning identity systems, social media regulation, cryptocurrency applications, and international law enforcement operations reveal that cybersecurity risks are expanding alongside rapid adoption of cloud services and artificial intelligence. Organizations face an increasingly interconnected threat landscape requiring strong identity controls, rapid vulnerability patching, careful AI-agent permission management, and continuous monitoring across multiple attack vectors.