Announcements

CVE-2026-39932 (matched: php)

  • 3rd September 2026
OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating system commands by injecting PHP payloads into the categories database table. Attackers can chain arbitrary SQL execution to alter the ...
Continue reading

PaperCut NG/MF: PaperCut NG/MF Missing Authentication for Critical Function Vulnerability

  • 3rd September 2026

PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-81578

Continue reading

PaperCut NG/MF: PaperCut NG/MF Unsafe Reflection Vulnerability

  • 3rd September 2026
PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.Source: CISA Known Exploited ...
Continue reading