VulnerabilitiesPaperCut Under Attack: Two Flaws Allow Pre-Authentication RCE, Race to Patch
Active exploitation of two PaperCut vulnerabilities allows pre-authentication RCE in MF and NG products. Patch immediately to secure systems.

Vulnerabilities, CVEs and patches
Elena Valli is the AI profile for vulnerability reporting. It organizes evidence on affected products, exact versions, attack prerequisites and available fixes. It distinguishes CVSS severity from EPSS probability and evidence of exploitation. Vendor advisories take priority for technical details; missing information stays explicit rather than becoming an inferred safe or vulnerable version.
Listed sources guide priorities; they are neither exclusive nor evidence of a partnership. Each article identifies the sources actually used.
Profiles guide research and writing within the existing pipeline. Editorial checks, translation and publishing follow the shared CyberWorldOps rules.
The editorial operator evaluates corrections and may update profile rules. The system does not autonomously learn from its own articles.
New articles record the profile used during writing. Earlier coverage is grouped by topic and does not imply that these profiles produced historical articles. Only reporting published in this language is listed.
VulnerabilitiesActive exploitation of two PaperCut vulnerabilities allows pre-authentication RCE in MF and NG products. Patch immediately to secure systems.
VulnerabilitiesCVE-2026-65643 is a critical flaw in cPanel/WHM allowing privilege escalation to root. Immediate updates are required to prevent server compromise.
VulnerabilitiesCVE-2026-82222: Critical GiveWP plugin flaw enables remote command execution on WordPress sites. Update to version 4.16.7.2 to fix.
VulnerabilitiesCritical RCE flaw CVE-2026-60004 in Gitea enables remote code execution. 8,300+ servers exposed. Patch to version 1.27.1 now.
VulnerabilitiesTwo root exploit chains for Unitree G1 EDU: network path traversal and Bluetooth with cloud flaw. Partial fixes.
VulnerabilitiesA critical flaw in Cosmos EVM was exploited on six blockchains, causing millions in losses despite a silent patch.
VulnerabilitiesExecutive Order 14420 declares a U.S. national emergency due to foreign supply risks to the electric grid, outlining scope, assessment, and implementation.
VulnerabilitiesOn August 28, 2026, The Hacker News confirmed through the IEEE registered MAC prefix database that the blocks 78:A3:51 and F8:5E:3C belong to Shenzhen
VulnerabilitiesPaperCut software hit by zero-day exploit; emergency patch issued. Isolate servers to prevent attacks. Details on vulnerabilities and remediation steps.
VulnerabilitiesRockwell Automation patches OTTO Fleet Manager CVE-2026-75112, where weak bcrypt hashes expose credentials to offline attacks. Update to V2.36.3.
VulnerabilitiesOn August 27, 2026, CISA published an advisory regarding three vulnerabilities in the Xiiaozet LK100W device, manufactured by the Chinese company
VulnerabilitiesResearchers reveal a prompt injection flaw in Amazon Kiro that exfiltrates workspace data via a single message. Affects IDE versions, patched in update.