← Back
VulnerabilitySecurityWeek·5 hours ago

PaperCut Releases Emergency Patch for Exploited Zero-Day

PaperCut has released an emergency patch to address a zero-day vulnerability currently being exploited in the wild, affecting both NG and MF product versions. The company is urging users to prioritize installation of the patch and implement available mitigations while a CVE identifier is still pending assignment.

Read full article at SecurityWeek

Related Articles

VulnerabilityThe Register·2 hours ago

CISA: Most exploited vulnerabilities should have been eradicated decades ago

CISA has highlighted that the majority of actively exploited vulnerabilities represent security flaws that should have been eliminated years ago, pointing to persistent organizational culture issues and incomplete adoption of Secure by Design principles as root causes. The agency's assessment suggests that systemic gaps in security practices continue to leave organizations vulnerable to preventable attacks rather than zero-day exploits.

VulnerabilityThe Hacker News·2 hours ago

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

ServiceNow addressed four security vulnerabilities affecting its AI Platform, with three receiving a critical CVSS 10.0 rating that could allow unauthenticated attackers to execute code and SQL queries under certain conditions. The vendor deployed patches to its hosted instances and made updates available to partners and self-hosted customers, though organizations running self-hosted deployments will need to apply fixes independently. The disclosure underscores the importance of promptly patching critical flaws in widely-deployed enterprise platforms.

VulnerabilityRapid7 Blog·4 hours ago

PaperCut NG/MF Critical Zero-Day Exploited in the Wild

A critical zero-day vulnerability chain affecting PaperCut NG and MF print management platforms is being actively exploited in the wild, combining an authentication bypass (CVE-2026-81578) with unsafe dynamic class loading (CVE-2026-82078) to achieve remote code execution. Organizations with internet-accessible PaperCut Application Servers should immediately apply emergency patches released on August 28, 2026, or restrict web access to trusted IP addresses, as all versions are potentially impacted and this represents the second major PaperCut vulnerability exploited by threat actors in recent years.

VulnerabilityThe Hacker News·4 hours ago

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

A critical vulnerability in cPanel and WebHost Manager (WHM) affecting domain parking and addon domain functionality could allow a hosting customer to execute code with root privileges on a shared server. The flaw, tracked as CVE-2026-65643, impacts all supported versions of the platform and has prompted cPanel to release patches. This represents a significant privilege escalation risk in multi-tenant hosting environments where multiple customers share the same server infrastructure.