top of page

Security Bulletin

Public·5 members

Jake Geier
Jake Geier

CISA Adds PaperCut NG/MF Vulnerabilities to KEV Catalog as Active Exploitation Confirmed


What:

  • CISA added two PaperCut NG/MF vulnerabilities — CVE-2026-81578 (missing authentication, CWE-306) and CVE-2026-82078 (unsafe reflection, CWE-470) — to its Known Exploited Vulnerabilities catalog on August 31, 2026

  • CVE-2026-81578 lets an unauthenticated attacker modify system configuration settings

  • CVE-2026-82078 allows execution of arbitrary Java bytecode already on the application classpath, under the PaperCut server process's security context

  • The two can be chained: unauthenticated config change → reflection-based code execution, enabling remote compromise of vulnerable deployments


2 Views
Jake Geier
Jake Geier

UPDATE: Critical Microsoft SharePoint Server Zero-Days Under Active Exploitation



What:

  • CISA added critical zero-day vulnerabilities targeting Microsoft SharePoint Server to its Known Exploited Vulnerabilities catalog

  • CVE-2026-58644 is a deserialization flaw in SharePoint Server (Subscription Edition, 2019, and 2016) that allows remote, authenticated attackers to execute arbitrary code, gain persistence — historically through IIS machine key theft — and establish footholds in enterprise environments

  • CVE-2026-50522 is a critical SharePoint Server deserialization RCE vulnerability with a CVSS score of 9.8; public proof-of-concept exploit code became available shortly after Microsoft's July 2026 emergency patches, contributing to rapid and widespread exploitation

  • CISA added CVE-2026-58644 to the KEV catalog on July 16, 2026, with a remediation deadline of July 19, 2026 for federal agencies


19 Views
Jake Geier
Jake Geier

Russian APT Exploits OWA Zero-Day to Survive Password Resets — CVE-2026-42897


What:

  • Threat group Laundry Bear (aka TA488/Void Blizzard), previously tied to Zimbra zero-day exploitation, is now exploiting an XSS vulnerability in Microsoft Outlook Web Access tracked as CVE-2026-42897 (CVSS 8.1) thehackernews

  • Activity began July 22, 2026, targeting U.S. and European government entities plus telecom, financial, hospitality, and aerospace sectors thehackernews

  • It's a "half-click" exploit — simply viewing the email triggers the compromise, no clicks or attachments needed, using vague lures like supply chain analyses or tourism/gas market updates thehackernewsthehackernews

  • Deploys a new implant called OWAReaper, which runs entirely in the browser inside the OWA reading pane


7 Views
George SuttonGeorge Sutton
George Sutton

Patch Tuesday Special: June 2026

June 18th, 2026


Overview:

Microsoft’s June 9, 2026 Patch Tuesday addressed ~66–67 vulnerabilities (counts vary slightly by tracker methodology), including one publicly disclosed zero-day and ten critical vulnerabilities. While no vulnerabilities were confirmed as actively exploited at release, the presence of a publicly disclosed WebDAV flaw and several critical Remote Code Execution (RCE) vulnerabilities affecting core Windows services makes this a high-priority patch cycle.


Vulnerability Category Breakdown:

• Remote Code Execution (RCE): ~25 vulnerabilities (~37%)


38 Views
bottom of page