U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog
CISA has added PaperCut NG/MF vulnerabilities to its Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. The flaws affect PaperCut's print management software deployed across schools, hospitals, and office environments globally, including a pre-authentication remote code execution vulnerability. Organizations running PaperCut should prioritize patching given CISA's formal recognition of ongoing exploitation.
Chaotic Eclipse has released HardBreacher, a proof-of-concept exploit for a privilege escalation vulnerability in Kaspersky Endpoint Security. The researcher, who operates under multiple aliases including INFINITE NIGHTMARE and MSNightmare, continues to add zero-day disclosures to an expanding portfolio of published exploits.
Threat actors are actively exploiting critical vulnerabilities in Langflow and Ruby on Rails to conduct credential-probing and command-and-control activities, with one flaw allowing arbitrary Python code execution with root privileges. The Langflow vulnerability (CVE-2026-0768, CVSS 9.8) stems from improper input validation, enabling remote code execution in a high-privilege context that attackers are leveraging in active campaigns.
CISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog. The post PaperCut Exploitation Escalates to Active Intrusions appeared first on SecurityWeek.
PaperCut has issued emergency patches to address chained vulnerabilities that threat actors exploited in attacks targeting the company's print management software. The attacks primarily focused on higher education customers during 2023, highlighting the risk posed by coordinated vulnerability exploitation in widely-deployed enterprise software.