PaperCut released a follow-up emergency update for PaperCut NG and MF after researchers found ways around its initial patch for actively exploited vulnerabilities. The company disclosed CVE-2026-82078, a critical unsafe dynamic class-loading bug, and CVE-2026-81578, a high-severity authentication bypass, which can be chained to let unauthenticated attackers execute code on vulnerable servers.
bleepingcomputer.com
· 2026-08-28
Security researchers disclosed CVE-2026-82222, a maximum-severity vulnerability in the GiveWP donation plugin affecting versions through 4.16.7.1. By chaining an unauthenticated registration bypass, an insecure PHP unserialize function, and a gadget chain in bundled libraries, attackers can create an account, plant a malicious object in the plugin's session data, and trigger arbitrary command execution on the server by simply loading a front-end page.
bleepingcomputer.com
· 2026-08-28
NIST has responded to a surge in vulnerability disclosures by reclassifying about 30,000 CVEs published before March 2026 as 'Not Scheduled,' effectively deprioritizing their enrichment. The move comes as Action1's 2026 report shows disclosed vulnerabilities in enterprise software jumped 92% in 2025, with critical and high-severity flaws each up 103% and remote-code-execution bugs up 128%.
bleepingcomputer.com
· 2026-08-28
Shadowserver reports over 8,300 internet-facing Gitea instances remain unpatched against CVE-2026-60004, a critical code injection bug already being exploited in the wild. The flaw lets an attacker with repository write access run arbitrary shell commands as the Gitea service account, and since Gitea allows open self-registration by default, unauthenticated users can create an account and repository to gain that access. Gitea patched the issue in version 1.27.1 on July 27, and CISA has added it to its known exploited vulnerabilities list, giving federal agencies just three days to remediate.
bleepingcomputer.com
· 2026-08-28
ServiceNow issued fixes for three critical vulnerabilities in its AI Platform that could let unauthenticated attackers run arbitrary code, escalate privileges, or manipulate data via SQL injection, all without user interaction. The company also patched a separate high-severity sandbox escape bug that could allow low-privileged users to achieve remote code execution. ServiceNow says it has no evidence of active exploitation but is urging customers to apply the updates immediately.
bleepingcomputer.com
· 2026-08-28
At Black Hat USA 2026, security researchers and reporters focused heavily on the risks posed by agentic AI systems and mounting concerns over the future of the CVE vulnerability-tracking program. Discussions centered on how AI is reshaping vulnerability disclosure and security research practices industry-wide.
darkreading.com
· 2026-08-27
CISA has added CVE-2026-8452, a memory overflow bug in Citrix NetScaler ADC and Gateway appliances, to its Known Exploited Vulnerabilities catalog, requiring federal civilian agencies to patch by August 29. Originally described by Citrix as only enabling denial-of-service, researchers at watchTowr later demonstrated it can be exploited for root-level remote code execution, and reports indicate attackers are already deploying web shells on unpatched systems.
bleepingcomputer.com
· 2026-08-27
Wordfence researchers found a critical vulnerability chain, tracked as CVE-2026-18431 with a 9.8 severity score, in the Avada theme and its companion Fusion Builder plugin for WordPress. By chaining six separate weaknesses in a specific sequence, an attacker with no login credentials could execute arbitrary PHP code on a vulnerable server, fully compromising the site.
bleepingcomputer.com
· 2026-08-26
Threat intelligence firm Defused reports that hackers are actively probing SharePoint servers by combining two vulnerabilities: an authentication bypass in JWT token validation (CVE-2026-55040) and a Business Connectivity Services flaw (CVE-2026-63520) that enables remote code execution. Proof-of-concept code for both bugs was published publicly in August by researchers at Rapid7 and VulnCheck, and Defused says it has already observed the bypass being exploited alongside admin enumeration on honeypots, though no successful code execution has been confirmed yet.
bleepingcomputer.com
· 2026-08-26
CISA has added a critical Gitea vulnerability to its Known Exploited Vulnerabilities catalog after confirming attackers are exploiting it in the wild. The flaw, found in the diffpatch API endpoint, lets someone with repository write access run shell commands as the Gitea service account, and since many installations allow open self-registration, even unauthenticated attackers can gain that access simply by signing up and creating a repository. Gitea patched the issue in version 1.27.1 released July 27.
bleepingcomputer.com
· 2026-08-26
OWASP GenAI Security Project leaders Kyriakos Lambros and Steve Wilson published an analysis comparing expert rankings of LLM security threats against 6,639 real-world incidents pulled from CVE, GitHub advisories, OSV and the AIAAIC database. Prompt injection tops the OWASP expert list for three straight years but ranks only 12th in the incident data, and statistical testing found no reliable agreement between the two rankings.
venturebeat.com
· 2026-08-25
Shadowserver identified 274 Zimbra Collaboration Suite instances already breached through exploitation of CVE-2026-73570, a command injection flaw in the SNMP monitoring component that allows unauthenticated remote code execution. Synacor patched the bug in ZCS 10.1.20 on July 20, but Shadowserver still counts over 8,200 unpatched instances exposed online, though not all are necessarily exploitable due to non-default configuration requirements.
bleepingcomputer.com
· 2026-08-25