← Back
VulnerabilitySecurity Affairs·3 hours ago

U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog

CISA has added PaperCut NG/MF vulnerabilities to its Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. The flaws affect PaperCut's print management software deployed across schools, hospitals, and office environments globally, including a pre-authentication remote code execution vulnerability. Organizations running PaperCut should prioritize patching given CISA's formal recognition of ongoing exploitation.

Read full article at Security Affairs

Related Articles

VulnerabilitySecurity Affairs·2 hours ago

Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher

Chaotic Eclipse has released HardBreacher, a proof-of-concept exploit for a privilege escalation vulnerability in Kaspersky Endpoint Security. The researcher, who operates under multiple aliases including INFINITE NIGHTMARE and MSNightmare, continues to add zero-day disclosures to an expanding portfolio of published exploits.

VulnerabilityThe Hacker News·4 hours ago

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

Threat actors are actively exploiting critical vulnerabilities in Langflow and Ruby on Rails to conduct credential-probing and command-and-control activities, with one flaw allowing arbitrary Python code execution with root privileges. The Langflow vulnerability (CVE-2026-0768, CVSS 9.8) stems from improper input validation, enabling remote code execution in a high-privilege context that attackers are leveraging in active campaigns.

VulnerabilitySecurityWeek·6 hours ago

PaperCut Exploitation Escalates to Active Intrusions

CISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog. The post PaperCut Exploitation Escalates to Active Intrusions appeared first on SecurityWeek.

VulnerabilityCybersecurity Dive·20 hours ago

PaperCut issues emergency patches as threat actors target chained vulnerabilities

PaperCut has issued emergency patches to address chained vulnerabilities that threat actors exploited in attacks targeting the company's print management software. The attacks primarily focused on higher education customers during 2023, highlighting the risk posed by coordinated vulnerability exploitation in widely-deployed enterprise software.