PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes. [...]
A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. [...]
PaperCut released an emergency advisory on Thursday evening saying vulnerabilities in their print management software, PaperCut NG and MF, are under active exploitation.
Serial Number: AV26-861Date: August 28, 2026 As of August 27, 2026, WebPros is affected by vulnerabilities in the following products: cPanel & WebHost Manager (WHM) software Prior to 11.110.0.141 Prior to 11.134.0.53 Prior to 11.136.0.37 Prior to 11.138.0.2 Prior to WP2: 11.138.1.7 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available Security: CVE-2026-65643 Vulnerability in cPanel’s Domain Parking…
Serial Number: AV26-860Date: August 28, 2026 As of August 27, 2026, Grafana is affected by a vulnerability in the following product: Alloy Prior to or equal to 1.18.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Grafana: The open and composable observability platform | Grafana Labs CVE-2026-19516 CVE Record
Serial Number: AV26-859Date: August 28, 2026 As of August 27, 2026, Redis is affected by a vulnerability in the following product: Redis 8.0 All except 8.10.1 All except 8.2.9 All except 8.4.6 All except 8.6.6 All except 8.8.2 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Fix use-after-free in tlsProcessPendingData() pending-list iteration GitHub Releases
Serial number: AV26-858Date: August 28, 2026 As of August 27, 2026, PaperCut is affected by vulnerabilities in the following products: PaperCut MF Prior to v24 Emergency Patch Release 2 Prior to v25 Emergency Patch Release 2 Prior to v26 Emergency Patch Release 2 PaperCut NG Prior to v24 Emergency Patch Release 2 Prior to v25 Emergency Patch Release 2 Prior to v26 Emergency Patch Release 2 The Cyber Centre encourages users and administrators to review the provided web link and apply any…
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network.
Serial number: AV26-857Date: August 28, 2026 As of August 27, 2026, ServiceNow is affected by vulnerabilities in the following products: Xanadu Versions prior to Patch 11 Hot Fix 7a Yokohama Versions prior to Yokohama Patch 12 Hot Fix 3b Versions prior to Yokohama Patch 13 Hot Fix 4 Zurich Multiple versions Australia Multiple versions The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. August 2026 CVE…
PaperCut heeft kwetsbaarheden verholpen in PaperCut MF en PaperCut NG. Een ongeauthenticeerde kwaadwillende kan de kwetsbaarheden mogelijk achtereenvolgens misbruiken om een PaperCut-omgeving over te nemen en hierop willekeurige code uit te voeren. Hiertoe dient de kwaadwillende malafide netwerkverkeer naar de kwetsbare PaperCut-omgeving te sturen.
Rilasciati aggiornamenti di sicurezza per risolvere due vulnerabilità con gravità “alta” che interessano GitLab AI Gateway. Tali vulnerabilità, qualora sfruttate, potrebbero consentire a un utente autenticato malevolo di accedere a informazioni sensibili sui sistemi interessati.
Serial Number: AV26-856Date: August 28, 2026 As of August 25, 2026, National Instruments is affected by vulnerabilities in the following product: LabVIEW Prior to 23.0.0 Prior to 23.3.10 Prior to 24.3.7 Prior to 25.3.5 Prior to 26.3.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Memory Corruption Vulnerabilities in NI LabVIEW - NI Integer Conversion Vulnerability Resulting in an Out of Bounds Read…
Rilevate molteplici vulnerabilità, tra cui 6 con gravità “alta”, in varie librerie client per MongoDB. Tali vulnerabilità, qualora sfruttate, potrebbero consentire a un utente malintenzionato la modifica non autorizzata di dati o codice e la compromissione della disponibilità del servizio sui sistemi interessati.
Wibu-Systems heeft meerdere kwetsbaarheden verholpen in CodeMeter Runtime. De kwetsbaarheden bevinden zich in verschillende onderdelen van CodeMeter Runtime, met name in versies voor 8.41a en 9.10. Een lokale aanvaller kan misbruik maken van onjuiste verificatie van NTFS reparse points bij het aanmaken van tijdelijke bestanden door cmu.exe, wat kan leiden tot het verwijderen van willekeurige systeembestanden met System-privileges en daarmee lokale privilege-escalatie. Daarnaast bevat de…
ServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in code injection, SQL injection, and privilege escalation attacks. [...]
Overview On August 27, 2026, PaperCut Software published an urgent security advisory stating that it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. PaperCut has confirmed customer incidents and is treating the issue as a security emergency. At the time of writing, the vulnerability has not been assigned a CVE identifier, and PaperCut has not publicly disclosed a CVSS score, vulnerability class, authentication requirements, or the technical details…
Rilasciati aggiornamenti di sicurezza per risolvere una vulnerabilità con gravità “alta” presente in Grafana Alloy, agente open source per la raccolta ed elaborazione di dati di osservabilità e monitoraggio. Tale vulnerabilità, qualora sfruttata, potrebbe consentire a un utente malintenzionato di accedere ad informazioni sensibili sui sistemi interessati.
Aggiornamenti di sicurezza sanano una vulnerabilità con gravità "critica" presente in Synology Chat Server, componente del prodotto DiskStation Manager (DSM) di Synology. Tale vulnerabilità, qualora sfruttata, potrebbe consentire a un utente autenticato remoto di leggere o scrivere file arbitrari e compromettere la disponibilità del sistema.
Rilevate nuove vulnerabilità e disponibili PoC pubblici per le CVE-2026-54083 e CVE-2026-61800 presenti in Wazuh, piattaforma open-source con funzionalità Security Information and Event Management (SIEM) e Extended Detection and Response (XDR).
Aggiornamenti di sicurezza Siemens sanano una vulnerabilità con gravità "alta" presente in Element Maps, libreria open source per la visualizzazione di mappe interattive. Tale vulnerabilità, qualora sfruttata, potrebbe consentire a un utente non autenticato remoto di iniettare codice arbitrario nella sessione del browser sul sistema target.
Rilasciati aggiornamenti di sicurezza che sanano 4 vulnerabilità ,di cui una con gravità "alta" e 3 con gravità "critica", presenti nella piattaforma ServiceNow. Tali vulnerabilità, qualora sfruttate, potrebbero consentire a un attaccante non autenticato di eseguire codice arbitrario, manipolare dati delle istanze e ottenere privilegi elevati sui sistemi interessati.
Aggiornamenti di sicurezza sanano numerose vulnerabilità, tra cui 5 con gravità "critica" e 12 con gravità “alta”, in prodotti WatchGuard. Tali vulnerabilità, qualora sfruttate, potrebbero consentire a un utente malintenzionato di eludere i meccanismi di autenticazione, eseguire codice arbitrario e/o compromettere la disponibilità del servizio sui sistemi interessati.
De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges et un déni de service à distance.
De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une atteinte à l'intégrité des données et un contournement de la politique de sécurité.
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et un déni de service.
De multiples vulnérabilités ont été découvertes dans Tenable Enclave Security. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
A critical vulnerability chain in the popular Avada theme for WordPress can be exploited by an unauthenticated attacker to execute arbitrary PHP code on the server. [...]
[VDE-2026-061] An information disclosure vulnerability in the web GUI of Murrelektronik Xelity switches causes MAC addresses from the device's MAC address table to be written into a server-side log that is exposed via the device's web interface to unauthenticated users. The leak is triggered when an authenticated administrator invokes the 'Copy learned MAC Addresses' function, which causes a syslog error that inserts the affected MAC addresses into the log output. Once the error has been…
[VDE-2026-083] Weidmueller security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by an unauthenticated remote code execution vulnerability. IE-SR-2TX-WL-4G routers are also affected by a SMS password authorization bypass vulnerability. Weidmueller has released new firmware versions of the affected products to fix the vulnerabilities.
Classification: Severe, Solution: Official Fix, Exploit Maturity: Proof-of-Concept, CVSSv3.1: 9.8, CVEs: CVE-2026-61979, CVE-2026-15981, Summary: The two vulnerabilities observed in exploitation attempts are tracked as CVE-2026-61979 and CVE-2026-15981 and can be chained together to bypass authentication. Because the miniOrange SAML SSO plugin accepts the signature algorithm from incoming SAML responses instead of enforcing the configured one, an attacker can leverage CVE-2026-61979 to select…
Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-77995, Summary: Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipulation of a cookie value allows actors to login as arbitrary accounts, including admins.
Executive Summary ShieldBreak (CVE-2026-69414) is a zero-day elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender, allowing a low-privilege local attacker to escalate to SYSTEM. A public PoC was released on August 12, 2026, and Microsoft assigned the CVE on August 14, and no patch is available yet. Qualys VMDR provides detection across Windows environments, and Qualys TruRisk Eliminate offers a mitigation that teams can apply now, with…
Serial Number: AV26-841Date: August 21, 2026 As of August 18, 2026, Malcolm is affected by vulnerabilities in the following product: Malcolm Prior to 26.06.1 (CVE-2026-55676) Prior to 26.07.0 (CVE-2026-63133, CVE-2026-63134, CVE-2026-63177) Prior to or equal to 26.07.1 (CVE-2026-19670, CVE-2026-19671) The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. CISA Malcolm | CISA ICS Advisories | CISA
The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical vulnerability in the MLflow open-source AI engineering platform. [...]
[VDE-2026-078] Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.
[vde-2025-056] This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.
De multiples vulnérabilités ont été découvertes dans Roundcube. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à la confidentialité des données et une falsification de requêtes côté serveur (SSRF).
[VDE-2025-007] The Year 2038 Problem affects systems using a 32-bit integer to represent time as the number of seconds since January 1, 1970. On January 19, 2038, at 03:14:07 UTC, the time value will exceed the maximum for a 32-bit integer, causing an overflow and resetting it to a negative number.
[PPSA-2026-003] The Linux kernel used in the IndustrialPI, 'linux-image-revpi-v8', prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.
OverviewOn July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066, an arbitrary file read in Active Storage applications that use the Vips image processor with untrusted uploads. The affected Active Storage ranges are < 7.2.3.2, >= 8.0, < 8.0.5.1, and >= 8.1, < 8.1.3.1. Vips is the default Active Storage variant processor for applications that load Rails 7.0 or later defaults. Rails 6 applications are affected only when they explicitly configure Vips.Our…
For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Minnesota IT Services has confirmed coordinated cyberattacks affecting more than 30 community water utilities across the state. The incidents briefly disrupted a treatment plant in Braham and affected industrial control systems. Officials reported that drinking water safety was not affected. While the attack was not officially attributed, federal…
[VDE-2026-065] A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory.
[VDE-2026-008] Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Phoenix Contact CHARX SEC-3000 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-41032.
[Advisory2026-06_VDE-2026-041] CODESYS PROFINET is an add‑on for the CODESYS Development System that provides a fully integrated PROFINET protocol stack along with diagnostic capabilities. When a PROFINET Controller is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems. The vulnerability in the CODESYS PROFINET Controller is caused by an out‑of‑bounds write during the processing of received invalid PROFINET communication data. Triggering…
[VDE-2026-076] The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
[VDE-2026-077] The affected products belong to the Controller or Servo Drive product family and contain a vulnerability in a security-critical activation mechanism for service access. The signature verification of a file used for SSH activation can be compromised, which could allow unauthorized access to the device.