Jellyfin has released version 12.0, a significant update to its open-source media server. This version includes a wide range of platform improvements and essential security updates affecting both the server and the web client. The project strongly advises administrators to plan their upgrade carefully because it includes database migrations and compatibility-breaking changes for existing deployments. […]
The post Jellyfin 12.0 Released With Security Fixes for Unauthorized File Access and XSS Fla
Jellyfin has released version 12.0, a significant update to its open-source media server. This version includes a wide range of platform improvements and essential security updates affecting both the server and the web client. The project strongly advises administrators to plan their upgrade carefully because it includes database migrations and compatibility-breaking changes for existing deployments. […]
Dell has released security updates for the Secure Connect Gateway (SCG) Application and Appliance after discovering three critical vulnerabilities. These flaws can expose enterprise deployments to unauthenticated administrative access, remote command execution, and potential host-level compromise. Detailed in Dell Security Advisory DSA-2026-382, these issues affect SCG 5.0 appliance versions earlier than 5.36.00.16 and application versions […]
The post Dell Secure Connect Gateway Critical Flaws
Dell has released security updates for the Secure Connect Gateway (SCG) Application and Appliance after discovering three critical vulnerabilities. These flaws can expose enterprise deployments to unauthenticated administrative access, remote command execution, and potential host-level compromise. Detailed in Dell Security Advisory DSA-2026-382, these issues affect SCG 5.0 appliance versions earlier than 5.36.00.16 and application versions […]
This weekly CVE report covers 10 exploited vulnerabilities added to CISA KEV and 2,316 new CVEs from Aug 31 to Sep 6, 2026. Patch fast.
Related Posts:
Weekly CVE Report: 11 Exploited Flaws Added to KEV
Weekly Threat Intelligence Report: Late August 2026
Weekly Threat Intelligence Report: Mid-August 2026
The post Weekly CVE Report: Daily Cybersecurity Beats CISA KEV on Exploited Flaws appeared first on Daily CyberSecurity.
ConnectWise has announced a security issue affecting file transfer functionality in ScreenConnect Remote Access Support and Access sessions. This issue affects both cloud-hosted and on-premises ScreenConnect deployments. In response, the company has issued immediate mitigation guidance. At the same time, it is working on an official patch and securing a CVE identifier. The advisory, released […]
The post ConnectWise ScreenConnect Remote Access Flaw Impacts Guest File Transfer Sessions appeared f
ConnectWise has announced a security issue affecting file transfer functionality in ScreenConnect Remote Access Support and Access sessions. This issue affects both cloud-hosted and on-premises ScreenConnect deployments. In response, the company has issued immediate mitigation guidance. At the same time, it is working on an official patch and securing a CVE identifier. The advisory, released […]
This weekly roundup highlights a range of cybersecurity developments affecting artificial intelligence platforms, enterprise software, healthcare organizations, social media accounts, and internet-facing infrastructure.
From stolen Claude sessions and bypassed PaperCut security fixes to an attempted attack targeting hundreds of thousands of X users, recent incidents demonstrate how attackers continue to exploit both software vulnerabilities and active user sessions.
The latest developmen
This weekly roundup highlights a range of cybersecurity developments affecting artificial intelligence platforms, enterprise software, healthcare organizations, social media accounts, and internet-facing infrastructure.From stolen Claude sessions and bypassed PaperCut security fixes to an attempted attack targeting hundreds of thousands of X users, recent incidents demonstrate how attackers continue to exploit both software vulnerabilities and active user sessions.The latest developments also show that organizations face growing risks across AI services, on-premises systems, enterprise edge devices, and account recovery infrastructure. Security teams are being urged to respond quickly as attackers increasingly target exposed systems and authentication mechanisms.
The Cyber Express Weekly Roundup
Anthropic Warns of Claude Session Hijacking
Anthropic has warned that common infostealer malware is being used to steal active Claude sessions, potentially allowing attackers to bypass passwords and two-factor authentication. The campaign involves malware such as Vidar, LummaC2, RedLine, and Atomic Stealer, which is often distributed through pirated software and illicit downloads. Attackers may also consume victims’ paid AI usage. Read more…
PaperCut Releases Second Emergency Patch After First Fix Is Bypassed
PaperCut has released a second emergency patch for two actively exploited vulnerabilities affecting its NG and MF print management servers. Researchers discovered ways to bypass the initial security fix, potentially allowing attackers to chain the flaws and achieve pre-authentication remote code execution on exposed systems. Read more…
Boston Scientific Cyberattack Limited to Certain On-Premises Systems
Boston Scientific says its ongoing cybersecurity incident is limited to certain on-premises systems, with no impact identified on its cloud-based applications. The company has also reported no confirmed data breach or evidence of unauthorized activity since August 25, as its investigation into the incident continues. Read more…
DOJ Investigates Attempted Cyberattack on Hundreds of Thousands of X Users
The U.S. Department of Justice is investigating a large-scale cyberattack targeting hundreds of thousands of X accounts through the platform’s password-recovery system. Attorney General Todd Blanche said X detected and disrupted the campaign before the targeted accounts could be captured, preventing the attempted account takeover operation from succeeding. Read more…
Two Citrix NetScaler Flaws Put Enterprise Edge Devices at Risk
Two vulnerabilities in Citrix NetScaler ADC and Gateway have prompted an urgent patching warning from Australia’s cybersecurity agency. CVE-2026-19489, a memory overflow flaw, and CVE-2026-19490, an authentication bypass, can affect systems with specific configurations involving SIP ALG, SAML, or VPN gateway functionality. Read more…
Weekly Cybersecurity Takeaway
This week’s developments demonstrate that cybersecurity threats are increasingly targeting authentication systems, active user sessions, exposed enterprise infrastructure, and critical business applications. AI platforms, print management servers, healthcare environments, social media accounts, and network edge devices all remain potential targets for attackers.Organizations should prioritize rapid security patching, protection of active sessions, strong authentication controls, careful monitoring of exposed infrastructure, and timely investigation of suspicious activity. Security teams should also review systems that rely on password-recovery mechanisms and identify enterprise devices operating with vulnerable configurations.As businesses continue to rely on cloud services, AI platforms, remote access technologies, and internet-facing enterprise systems, attackers are finding new opportunities to exploit trusted sessions and security weaknesses. Organizations must maintain continuous monitoring and rapid response capabilities to reduce the impact of increasingly targeted cyberattacks.
Two Citrix NetScaler vulnerabilities affecting Citrix NetScaler Application Delivery Controller (ADC) and Citrix NetScaler Gateway products have prompted a patching warning for Australian organisations. The Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) has advised organisations using the products to assess their environments and apply available security updates as a priority.
Citrix has identified two vulnerabilities affecting NetScaler ADC and NetScaler Gatew
Two Citrix NetScaler vulnerabilities affecting Citrix NetScaler Application Delivery Controller (ADC) and Citrix NetScaler Gateway products have prompted a patching warning for Australian organisations. The Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) has advised organisations using the products to assess their environments and apply available security updates as a priority.
Citrix has identified two vulnerabilities affecting NetScaler ADC and NetScaler Gateway, which are critical edge devices used in enterprise networking to securely deliver applications, data and remote access to users.
Citrix NetScaler Vulnerabilities Affect ADC and Gateway
The first flaw, CVE-2026-19489, is a memory overflow vulnerability. According to the alert, exploitation of this vulnerability requires SIP ALG, or Session Initiation Protocol Application Layer Gateway, to be enabled on a Large Scale NAT (LSN) group configuration.
The second flaw, CVE-2026-19490, is an authentication bypass vulnerability. The vulnerability requires SAML actions to be enabled and/or the affected product to be configured as a VPN gateway.
The conditions required for each vulnerability mean that organisations need to assess their specific Citrix configurations to determine whether affected systems are present in their environments.
Patches Released for Citrix NetScaler products
Citrix released patches for the affected products on August 19, 2026. ASD's ACSC is urging organisations to review the vendor's mitigation guidance, identify vulnerable versions of Citrix products and update affected systems to the latest versions.
The advisory places particular emphasis on timely patching because critical edge devices are frequently targeted by threat actors as an entry point into sensitive environments.
However, ASD's ACSC said it has no information indicating that a specific Australian industry or sector is currently being targeted in connection with these vulnerabilities.
Organisations Urged to Assess Vulnerable Versions
The mitigation guidance calls on organisations to assess their networks and environments for vulnerable versions of Citrix products and apply patches as soon as practicable.
Organisations should also review the mitigation advice provided by Citrix and confirm that affected systems have been updated.
Where NetScaler ADC and NetScaler Gateway products are managed by a third party, organisations are advised to contact the relevant managed service provider (MSP) or enterprise IT provider. They should confirm that the products have been patched and are being monitored for suspicious activity.
This step is particularly relevant for organisations that do not directly manage their Citrix infrastructure and may rely on external providers for patching and monitoring.
Monitoring Remains Important After Patching
Alongside addressing the Citrix NetScaler vulnerabilities, organisations are advised to monitor affected environments for suspicious activity. The alert recommends notifying ASD's ACSC if suspicious activity is detected.
The two vulnerabilities affect different configurations, with CVE-2026-19489 requiring SIP ALG to be enabled on an LSN group configuration, while CVE-2026-19490 requires SAML actions to be enabled and/or the product to be configured as a VPN gateway.
For Australian organisations using Citrix NetScaler products, the immediate steps outlined by ASD's ACSC are to identify vulnerable versions, apply the available patches, confirm third-party-managed systems have been addressed and maintain monitoring for suspicious activity.
Threat actors are actively exploiting a critical vulnerability in the Super Forms WordPress plugin, allowing them to upload PHP backdoors and gain remote code execution. This flaw, tracked as CVE-2026-14894, affects Super Forms versions 6.3.313 and earlier. Administrators are urged to upgrade to version 6.3.314 immediately. Super Forms WordPress Flaw Wordfence disclosed this unauthenticated arbitrary […]
The post Critical Super Forms WordPress Flaw Actively Exploited to Achieve Remote Code Execu
Threat actors are actively exploiting a critical vulnerability in the Super Forms WordPress plugin, allowing them to upload PHP backdoors and gain remote code execution. This flaw, tracked as CVE-2026-14894, affects Super Forms versions 6.3.313 and earlier. Administrators are urged to upgrade to version 6.3.314 immediately. Super Forms WordPress Flaw Wordfence disclosed this unauthenticated arbitrary […]
Plex has urged users to promptly update their Plex Media Server and Plex Desktop software following the release of fixes for several undisclosed security issues in older versions. The recommended versions are Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The company advises that all server owners and desktop users upgrade to the latest release […]
The post Plex Urges Users to Update Media Server as Multiple Security Flaws Are Discovered appeared first on GBHackers Security | #1 Globally Tru
Plex has urged users to promptly update their Plex Media Server and Plex Desktop software following the release of fixes for several undisclosed security issues in older versions. The recommended versions are Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The company advises that all server owners and desktop users upgrade to the latest release […]
TP-Link has released security updates for two vulnerabilities found in its Archer AX55 v4 wireless router. These vulnerabilities could allow attackers on the local network to crash a key networking service, potentially execute code, or steal administrator credentials from captured login traffic. The vulnerabilities, identified as CVE-2026-18167 and CVE-2026-18330, impact the router’s EasyMesh component and […]
The post TP-Link Archer AX55 Flaws Enable Remote Code Execution and Admin Password The
TP-Link has released security updates for two vulnerabilities found in its Archer AX55 v4 wireless router. These vulnerabilities could allow attackers on the local network to crash a key networking service, potentially execute code, or steal administrator credentials from captured login traffic. The vulnerabilities, identified as CVE-2026-18167 and CVE-2026-18330, impact the router’s EasyMesh component and […]
A critical vulnerability identified as CVE-2026-84115 affects Cleo Harmony versions through 5.8.1.10, with the weakness tied to the platform’s JWT Refresh Token Handler and the /api/connections endpoint.
MITRE documented the issue on September 1, 2026, while VulDB classified it as a serious privilege-management vulnerability with a CVSS score of 8.3.
CVE-2026-84115 Targets JWT Refresh Token Handler
According to the vulnerability analysis, CVE-2026-84115 involves an unknown function with
A critical vulnerability identified as CVE-2026-84115 affects Cleo Harmony versions through 5.8.1.10, with the weakness tied to the platform’s JWT Refresh Token Handler and the /api/connections endpoint. MITRE documented the issue on September 1, 2026, while VulDB classified it as a serious privilege-management vulnerability with a CVSS score of 8.3.
CVE-2026-84115 Targets JWT Refresh Token Handler
According to the vulnerability analysis, CVE-2026-84115 involves an unknown function within the JWT Refresh Token Handler component. The affected functionality processes requests sent to /api/connections, where manipulation of the Bearer argument in HTTP authorization headers can lead to improper privilege management.The weakness is classified as CWE-269, which refers to Improper Privilege Management. The flaw can allow an attacker to manipulate authentication-token arguments and potentially bypass intended access controls, gaining privileges beyond those assigned to the account.
Remote Exploitation Raises CVE-2026-84115 Risk
The vulnerability is remotely exploitable because the attack can be conducted through network-based HTTP requests without requiring local or physical access to the targeted system. The risk is heightened because a public exploit has reportedly been made available.An attacker exploiting CVE-2026-84115 could potentially obtain unauthorized administrative access, view sensitive information stored within Harmony, or interfere with integration workflows managed through the platform. Such activity could affect the confidentiality, integrity, and availability of systems that depend on Cleo Harmony for file transfer and API connectivity.The VulDB analysis links the exploitation method to authentication bypass through token manipulation. Attackers could potentially intercept legitimate traffic or create forged requests using malformed or replayed bearer tokens to circumvent JWT refresh-token controls. In environments where Cleo Harmony is connected to other systems, successful exploitation could also provide opportunities for further lateral movement.
CVE-2026-84115 Remediation Requires an Upgrade
Organizations using affected Cleo Harmony versions should upgrade to version 5.8.1.11 or later. The release contains the necessary correction for the privilege-management problem affecting the JWT Refresh Token Handler.Until patching is possible, organizations can strengthen input validation on API endpoints and monitor for unusual patterns involving bearer tokens. These measures may improve detection and reduce exposure, but they do not replace the recommended software upgrade, particularly given the reported public exploit.VulDB is listed as the responsible organization, with the vulnerability recorded under VDB-397558. Disclosure took place on September 1, 2026, and the entry has an accepted moderation status, with CPE marked as ready. CWE-269 is confirmed for the vulnerability.VulDB assigns CVE-2026-84115 a CVSS score of 8.3 and an EPSS score of 0.00284. The vulnerability record also identifies an exploit as available for download.
SonicWall disclosed this week that attackers are chaining two previously unknown vulnerabilities in its SMA1000 secure access appliances to run commands on unpatched devices, and urged customers to install an emergency hotfix.
The more severe flaw, CVE-2026-83548, is a pre-authentication server-side request forgery weakness in the appliance's Appliance Work Place interface, rated 10.0 on the CVSS scale. It lets a remote attacker with no credentials reach sensitive internal functionality. The se
SonicWall disclosed this week that attackers are chaining two previously unknown vulnerabilities in its SMA1000 secure access appliances to run commands on unpatched devices, and urged customers to install an emergency hotfix.
The more severe flaw, CVE-2026-83548, is a pre-authentication server-side request forgery weakness in the appliance's Appliance Work Place interface, rated 10.0 on the CVSS scale. It lets a remote attacker with no credentials reach sensitive internal functionality. The second, CVE-2026-83549, is an operating-system command injection bug in the Appliance Management Console rated 7.8; on its own it requires administrative authentication, but paired with the SSRF flaw it yields remote code execution.
The vendor said it found both issues internally and then observed them being used together in live attacks. SonicWall has not published indicators of compromise or described the attackers.
Affected products are the SMA1000 series 6210, 7210 and 8200v, in both hardware and virtual form. Fixed builds are 12.4.3-03526 and later, and 12.5.0-02952 and later. SonicWall firewalls running SSL-VPN and the separate SMA 100 line are not affected.
Remediation guidance goes beyond patching. SonicWall told customers to contact its support organization to review appliances for signs of intrusion and, where compromise is suspected, to re-image or redeploy the device, rotate all credentials and reset TOTP tokens — an acknowledgment that one-time-password seeds stored on a breached appliance survive a software update. The company said customers should move to the hotfix release as quickly as possible.
Shadowserver Foundation scanning has tracked more than 400 internet-exposed SMA1000 appliances, though an unknown share of those are already patched. The small install base belies the risk profile. These are remote-access gateways that sit at the network edge and hold credentials for the environments behind them.
The disclosure extends a difficult run for the product line. Attackers exploited a separate pair of SMA1000 zero-days in July 2026, tracked as CVE-2026-15409 and CVE-2026-15410, to deploy custom malware; CISA later confirmed ransomware operators were abusing that access.
Another zero-day surfaced in December 2025. Seventeen SonicWall vulnerabilities across the company's product families currently sit in CISA's Known Exploited Vulnerabilities catalog. Edge appliances from SonicWall, Ivanti, Citrix and Fortinet have collectively become the preferred initial-access route for ransomware affiliates and espionage crews, because they are internet-facing by design and rarely instrumented with endpoint detection.
Security researchers have reported active exploitation attempts targeting a critical vulnerability in Sangoma Switchvox, allowing unauthenticated attackers to execute code remotely via SQL injection. This vulnerability, tracked as CVE-2026-9586, affects internet-exposed Switchvox enterprise VoIP systems and was addressed in Switchvox version 8.4.0.2. Sangoma Switchvox RCE Flaw Zach Hanley, a researcher at Horizon3.ai, revealed that this […]
The post Sangoma Switchvox RCE Flaw Actively Exploited
Security researchers have reported active exploitation attempts targeting a critical vulnerability in Sangoma Switchvox, allowing unauthenticated attackers to execute code remotely via SQL injection. This vulnerability, tracked as CVE-2026-9586, affects internet-exposed Switchvox enterprise VoIP systems and was addressed in Switchvox version 8.4.0.2. Sangoma Switchvox RCE Flaw Zach Hanley, a researcher at Horizon3.ai, revealed that this […]
Three high-severity vulnerabilities in HP Easy Start for macOS could allow both local and network-positioned attackers to disrupt the printer software installation process and, under certain conditions, gain privileged access or modify files with root permissions. These vulnerabilities, tracked as CVE-2026-12554, CVE-2026-12555, and CVE-2026-12556, were discovered by researcher Nir Yehoshua from Cipher Security Labs during […]
The post Three HP Easy Start Flaws Let Attackers Gain Root Privileges
Three high-severity vulnerabilities in HP Easy Start for macOS could allow both local and network-positioned attackers to disrupt the printer software installation process and, under certain conditions, gain privileged access or modify files with root permissions. These vulnerabilities, tracked as CVE-2026-12554, CVE-2026-12555, and CVE-2026-12556, were discovered by researcher Nir Yehoshua from Cipher Security Labs during […]
FreeRDP released version 3.31.0, addressing 22 security flaws and multiple bugs in its open-source Remote Desktop Protocol implementation, and urges users and distributors to update promptly.
FreeRDP is widely used by Linux systems, thin clients, remote-access tools, and enterprise applications to connect to Windows Remote Desktop Services.
Because it processes network data from remote servers and supports features such as graphics, smart cards, USB redirection, clipboard sharing, and aut
FreeRDP released version 3.31.0, addressing 22 security flaws and multiple bugs in its open-source Remote Desktop Protocol implementation, and urges users and distributors to update promptly.
FreeRDP is widely used by Linux systems, thin clients, remote-access tools, and enterprise applications to connect to Windows Remote Desktop Services.
Because it processes network data from remote servers and supports features such as graphics, smart cards, USB redirection, clipboard sharing, and authentication, memory-handling mistakes can create serious security exposure.
The 3.31.0 release includes fixes for 22 GitHub Security Advisories, covering issues reported through the project’s security process. The advisory identifiers include GHSA-c5gr-hmqp-pwj4, GHSA-h5w2-q35j-443h, GHSA-m85m-3qxv-63h5, and 19 others.
While the release notes do not provide public technical details for every flaw, the vendor’s “update ASAP” warning shows that maintainers consider the addressed issues significant.
FreeRDP Fixes 22 Security Flaws
Several changes in the release point to security-sensitive code paths. FreeRDP fixed bounds checking in the AVC444v2 YUV decoder, which processes remote desktop graphics data.
It also corrected parsing and length-validation problems in dynamic virtual channels, Remote Desktop Gateway tunnel responses, clipboard format lists, smart-card data, USB redirection, and device-redirection components.
The update further resolves use-after-free conditions involving the printer driver singleton and the reallocation of aligned memory. Use-after-free bugs occur when software continues to access memory after it has been released.
Depending on the affected code path and surrounding protections, such flaws can lead to application crashes, information disclosure, or possibly remote code execution. Authentication and cryptographic components also received attention.
The release improves NTLM and SSPI memory handling, adds checks before accessing signature buffers, fixes SPNEGO mechanism fallback behavior, and improves error handling when BIO or SSL object creation fails.
These changes are important because FreeRDP often handles authentication exchanges and encrypted connections to remote systems.
In addition to security fixes, version 3.31.0 brings performance improvements. The project said an optimized YUV decoder should deliver faster client-side graphics for AVC and H.264 remote desktop sessions. It also adds support for more hardware decoders and switches AV1 decoding to dav1d in supported configurations.
Administrators should identify systems that package or embed FreeRDP, including desktop clients, remote-access gateways, virtual desktop tools, and third-party products built on the library.
Organizations should install FreeRDP 3.31.0 through their supported distribution channel or build the updated release from the official source package. Teams should also verify the downloaded archive using the published SHA-256 checksum and signature where possible.
Prompt patching is especially important for systems that connect to untrusted or internet-exposed RDP servers. The official release includes source archives, ZIP packages, signatures, and checksums for version 3.31.0.
SonicWall has warned that attackers are actively exploiting two critical vulnerabilities affecting SMA1000 Series secure mobile access appliances.
The flaws could allow unauthenticated attackers to access sensitive functionality and enable administrators with authenticated access to execute arbitrary operating system commands.
The company published advisory SNWLID-2026-0016 on September 1, 2026, confirming that its Product Security Incident Response Team investigated a case indicating acti
The flaws could allow unauthenticated attackers to access sensitive functionality and enable administrators with authenticated access to execute arbitrary operating system commands.
The company published advisory SNWLID-2026-0016 on September 1, 2026, confirming that its Product Security Incident Response Team investigated a case indicating active exploitation.
SonicWall urged organizations to install the available platform hotfixes immediately and review exposed systems for signs of compromise.
The vulnerabilities affect SMA1000 6210, 7210, and 8200v appliances running version 12.4.3-03453 or earlier, as well as version 12.5.0-02835 or earlier. SonicWall stated that SSL-VPN services running on SonicWall firewalls and the SMA 100 Series product line are not affected.
SonicWall RCE Vulnerabilities Exploited
The most severe issue is tracked as CVE-2026-83548 and carries a CVSS score of 10.0. It is a pre-authentication server-side request forgery vulnerability in the SMA1000 Appliance Workplace interface.
According to SonicWall, the flaw stems from an unintended alternate access path that can serve as a forward proxy. A remote, unauthenticated attacker could exploit this path to access sensitive internal functionality and perform unauthorized operations.
The vulnerability is associated with CWE-918, covering server-side request forgery, and CWE-441, which describes an unintended proxy or confused-deputy condition.
SSRF vulnerabilities are especially dangerous in remote-access appliances because they can allow attackers to make requests from the device itself, potentially bypassing network restrictions designed to protect internal services.
The vulnerability has a CVSS score of 7.8 and stems from improper neutralization of special characters in operating system commands.
An authenticated attacker with administrator privileges could exploit the command injection issue to execute arbitrary commands on the appliance operating system.
While this vulnerability requires valid administrator access, it could be especially damaging when chained with another weakness that provides unauthorized access to appliance functions.
Remote-access infrastructure remains a high-value target because it often sits at the edge of enterprise networks and handles user authentication, VPN connectivity, and access to internal resources.
A compromised SMA appliance may provide attackers with a foothold for credential theft, lateral movement, and further network intrusion.
There is no workaround for either issue. Organizations should upgrade SMA1000 appliances to version 12.4.3-03526 or later, or to version 12.5.0-02952 or later, depending on the software branch they have deployed.
SonicWall also recommends contacting technical support to review appliances for indicators of compromise. If compromise indicators are found, organizations should re-image affected physical appliances or redeploy affected virtual appliances.
Administrators should then change all user and administrator passwords and reset TOTP tokens to invalidate potentially stolen authentication factors.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
FreeRDP version 3.31.0 has been released as a significant security and stability update, addressing 22 disclosed security vulnerabilities in the widely used open-source implementation of the Remote Desktop Protocol (RDP). Project maintainers have termed this release a “huge bug fix and security release” and strongly encourage distributors to update promptly due to the serious nature […]
The post FreeRDP 3.31.0 Fixes 22 Security Flaws Including Heap Overflow and Pre-Auth DoS Bugs appeared first o
FreeRDP version 3.31.0 has been released as a significant security and stability update, addressing 22 disclosed security vulnerabilities in the widely used open-source implementation of the Remote Desktop Protocol (RDP). Project maintainers have termed this release a “huge bug fix and security release” and strongly encourage distributors to update promptly due to the serious nature […]
SonicWall has issued an urgent security advisory regarding two vulnerabilities affecting its SMA 1000 Series secure access appliances. The company warns that there have been cases indicating active exploitation in the wild. The vulnerabilities are tracked as CVE-2026-83548 and CVE-2026-83549 and impact SonicWall SMA 1000 models 6210, 7210, and 8200v that are running vulnerable platform […]
The post Critical SonicWall SMA 1000 Vulnerabilities Actively Exploited in the Wild appeared first on GBHac
SonicWall has issued an urgent security advisory regarding two vulnerabilities affecting its SMA 1000 Series secure access appliances. The company warns that there have been cases indicating active exploitation in the wild. The vulnerabilities are tracked as CVE-2026-83548 and CVE-2026-83549 and impact SonicWall SMA 1000 models 6210, 7210, and 8200v that are running vulnerable platform […]
Google has released a new update for the Chrome Stable Channel on desktop platforms, addressing 26 security vulnerabilities. This includes two critical use-after-free flaws affecting WebGL and Shared Tab Groups. The update upgrades Chrome to version 152.0.7977.75 on Windows and macOS, while Linux users receive version 152.0.7977.76. Google stated that the update will be rolled […]
The post Google Patches 26 Chrome Vulnerabilities, Including Critical WebGL and Shared Tab Groups Flaws appeared fir
Google has released a new update for the Chrome Stable Channel on desktop platforms, addressing 26 security vulnerabilities. This includes two critical use-after-free flaws affecting WebGL and Shared Tab Groups. The update upgrades Chrome to version 152.0.7977.75 on Windows and macOS, while Linux users receive version 152.0.7977.76. Google stated that the update will be rolled […]
This weekly CVE report covers 2,488 new CVEs and 11 exploited vulnerabilities added to the CISA KEV catalog for Aug 24-30, 2026. See the priorities.
Related Posts:
Weekly Threat Intelligence Report: Late August 2026
Weekly Threat Intelligence Report: Mid-August 2026
Weekly CVE Report: 6 Actively Exploited Flaws and 1,877 New CVEs
The post Weekly CVE Report: 11 Exploited Flaws Added to KEV appeared first on Daily CyberSecurity.
PaperCut released a second emergency patch last Friday, for two vulnerabilities in its NG and MF print management servers that attackers are already exploiting, after security researchers demonstrated that the vendor's first fix could be bypassed.
The two flaws work as a chain. CVE-2026-81578, rated 8.8 on the CVSS scale, is an improper access control weakness in the PaperCut web management interface that lets unauthenticated remote requests reach administrative functions before the server fini
PaperCut released a second emergency patch last Friday, for two vulnerabilities in its NG and MF print management servers that attackers are already exploiting, after security researchers demonstrated that the vendor's first fix could be bypassed.
The two flaws work as a chain. CVE-2026-81578, rated 8.8 on the CVSS scale, is an improper access control weakness in the PaperCut web management interface that lets unauthenticated remote requests reach administrative functions before the server finishes validating access.
CVE-2026-82078, rated 9.4, is an unsafe dynamic class-loading flaw in the product's database utilities. The application loads database driver classes without checking them against an allowlist, so an attacker who can alter configuration parameters can get arbitrary Java bytecode running inside the application server process. Together they produce pre-authentication remote code execution on an internet-facing server.
PaperCut software runs print queues for universities, school districts, hospitals, local government and large enterprises, and the platform has a history of drawing ransomware attention. Three earlier PaperCut NG/MF vulnerabilities already sit in the U.S. Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog, two of them weaponized in ransomware campaigns.
Huntress, which first documented the activity, said it observed exploitation in two customer environments on Aug. 26 and Aug. 27. In one case the whole intrusion ran under two minutes. Attackers dropped hex-encoded Java class files that the firm described as a bridge between PaperCut and the underlying operating system, then issued basic reconnaissance commands - enumerating the current user, operating system version and running processes - rather than deploying ransomware or other payloads. That pattern typically indicates access brokering or target triage ahead of a later stage.
The reason for a second patch was straightforward; the first one did not hold. Researchers at watchTowr found multiple ways around the original fix and turned up an additional authentication bypass in the process, while Huntress independently reproduced the full attack chain and found its own workarounds. Both firms worked with PaperCut's engineers on Emergency Patch Release 2.
PaperCut said it was aware of confirmed customer incidents and was treating the matter with the highest priority. Release 2 covers PaperCut NG and MF versions 24, 25 and 26 on Windows, Linux and macOS. Customers running version 23 or earlier are told to upgrade rather than wait for a backported patch - a significant caveat, since Huntress reported that roughly 47% of the approximately 2,500 installations it tracks are on those older builds.
The pair had not been added to CISA's KEV catalog as of the vendor's Aug. 28 update.
Whether CISA adds the two CVEs to KEV, whether the reconnaissance-only activity converts into ransomware deployment, and whether Release 2 survives the scrutiny that broke its predecessor, remains to be seen. But administrators should pull PaperCut servers off the public internet regardless of patch status, and check application logs for unexpected process execution and stray .class files.