Announcements

CVE-2026-39932 (matched: php)

  • 31st August 2026
OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating system commands by injecting PHP payloads into the categories database table. Attackers can chain arbitrary SQL execution to alter the ...
Continue reading

CVE-2026-15369 (matched: wordpress)

  • 31st August 2026
The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role value from the unauthenticated WooCommerce Store API /wc/store/v1/checkout request in the ...
Continue reading

PaperCut NG/MF: PaperCut NG/MF Missing Authentication for Critical Function Vulnerability

  • 31st August 2026

PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-81578

Continue reading

PaperCut NG/MF: PaperCut NG/MF Unsafe Reflection Vulnerability

  • 31st August 2026
PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.Source: CISA Known Exploited ...
Continue reading