PaperCut Releases Second Emergency Patch for Exploited Flaws. PaperCut NG and MF required two emergency patches within the same week after researchers discovered methods to bypass the initial fix for CVE-2026-82078 and CVE-2026-81578, which chain to allow unauthenticated RCE. Active exploitation has been confirmed, with attackers performing reconnaissance post-compromise using the legitimate pc-app.exe process. Learn more
Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL. ServiceNow patched four vulnerabilities in its AI Platform, three rated maximum severity, covering code injection, SQL injection, and improper access control. No active exploitation is confirmed yet, but past ServiceNow flaws have been rapidly weaponized and chained in real attacks.
Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server. CVE-2026-65643 allows any authenticated cPanel user to escalate to root across a shared server by abusing domain parking and addon domain logic. Shared hosting providers and managed WordPress environments carry elevated exposure here.
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE. Critical flaws in WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP (CVE-2026-82222) reach CVSS 10.0 in some cases, enabling unauthenticated authentication bypass, account takeover, and arbitrary code execution across hundreds of thousands of sites.
Over 8,300 Gitea Servers Vulnerable to Code Execution Attacks. CVE-2026-60004 allows authenticated RCE on unpatched Gitea instances, and with open registration enabled by default, the effective barrier is near zero. Cryptocurrency mining malware is already being deployed on compromised servers.
Key Takeaway
Prioritize patching PaperCut (apply the second patch, not just the first), ServiceNow, cPanel, and WordPress plugins this week, and audit Gitea instances for exposure to the internet.
