Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
2026-08-28T19:23:59Z•77a047f68902e3e95f70f612281067d8e801a89f39ccede72b041a535169bf80
CVE-2023-49105CVE-2026-65643CVE-2026-74232CVE-2026-74233CVE-2026-75604CVE-2026-76639CVE-2026-76640APT28CISA KEVChrome extensionsMicrosoft 365 session theftNext.jsPaperCutServiceNowUnitree G1 EDUZBT routersactive exploitationadversary-in-the-middlecPanelcryptocurrency theftdata exfiltrationmalwareownCloudphishingprivilege escalationprompt injectionremote code executionroot accessstate-sponsored activitysupply-chain compromiseunauthenticated RCEzero-day
What happened
The feed reports widespread active exploitation and disclosure of critical vulnerabilities across PaperCut, ownCloud, ServiceNow, cPanel, Next.js, ZBT routers, Unitree robots, and other products. It also covers state-sponsored campaigns, malware, supply-chain compromises, phishing and session theft, malicious browser extensions, AI-agent prompt injection, and GPU Rowhammer research. Several issues enable unauthenticated remote code execution or root access, including vulnerabilities listed in CISA’s KEV catalog; urgent patching and exposure reduction are warranted.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 77a047f68902e3e95f70f612281067d8e801a89f39ccede72b041a535169bf80
- Enrichment time
- 2026-08-28T19:23:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.