View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

PaperCut NG/MF flaws added to KEV after active exploitation

๐Ÿšจ ACTIVE EXPLOITATION

  • PaperCut NG/MF flaws added to KEV after active exploitation CVE-2026-81578 CVE-2026-82078
    Attackers are exploiting two PaperCut NG/MF vulnerabilities added to CISA's KEV catalog.
    • PaperCut NG and MF print-management servers used by enterprises, schools, and other organizations are affected.
    • CVE-2026-81578 is an 8.8 authentication bypass in the web management interface.
    • CVE-2026-82078 is a 9.4 unsafe dynamic class-loading flaw in database connection utilities.
    • Attackers can chain the flaws to alter configurations and execute arbitrary Java bytecode as the PaperCut server process.
    • PaperCut versions 24, 25, and 26 received emergency patches; all versions are potentially impacted, with pc-app.exe activity and anomalous server.log entries reported as indicators.
      ๐Ÿ“Ž Coverage: rapid7.com ยท ๐Ÿ‘ via SecurityWeek

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

๐Ÿ”“ CVEs & KEV

  • CVE-2026-19806 โ€” CVSS 8.8 โ€” Support Genix through 1.4.52 - Authenticated (Subscriber+) Authentication Bypass t...

  • CVE-2026-19952 โ€” CVSS 7.5 โ€” Frontend Admin by DynamiApps through 3.29.12 - Unauthenticated Arbitrary File Dele...

  • CVE-2026-19573 โ€” CVSS 7.2 โ€” Affiliate Super Assistent through 1.10.2 - Unauthenticated Stored Cross-Site Scrip...

  • CVE-2026-75921 โ€” CVSS 7.2 โ€” Master Addons for Elementor through 3.1.9 - Incorrect Authorization to Authenticat...

  • CVE-2026-77189 โ€” CVSS 6.5 โ€” Charitable through 1.8.12.1 - Authenticated (Contributor+) SQL Injection via 'orde...

  • CVE-2026-18752 โ€” CVSS 6.5 โ€” Persistent Login through 3.1.0 - Authenticated (Subscriber+) SQL Injection via 'wp...

  • CVE-2026-18488 โ€” CVSS 6.4 โ€” Blocksy Companion through 2.1.51 - Authenticated (Author+) Stored Cross-Site Scrip...

  • CVE-2026-75980 โ€” CVSS 6.4 โ€” BetterDocs through 4.8.1 - Authenticated (Contributor+) Stored Cross-Site Scriptin...

  • CVE-2026-12747 โ€” CVSS 6.4 โ€” Frontend Admin by DynamiApps through 3.29.11 - Authenticated (Contributor+) Stored...

  • CVE-2026-13203 โ€” CVSS 6.4 โ€” Live Composer through 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scri...

  • CVE-2026-16787 โ€” CVSS 6.4 โ€” Live Composer through 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scri...

  • CVE-2026-75965 โ€” CVSS 6.4 โ€” User Profile Builder through 4.0.0 - Authenticated (Contributor+) Stored Cross-Sit...

  • CVE-2026-75964 โ€” CVSS 6.1 โ€” User Profile Builder through 4.0.0 - Unauthenticated Stored Cross-Site Scripting v...

๐Ÿ“‹ ADVISORIES

  • ๐Ÿ“„ Source for Fake Crypto AML Sites Trick Users Into Approving Wallet-Draining Transactions โ€” malwarebytes.com

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check