Announcements

CVE-2026-39932 (matched: php)

  • 1st September 2026
OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating system commands by injecting PHP payloads into the categories database table. Attackers can chain arbitrary SQL execution to alter the ...
Continue reading

CVE-2026-75865 (matched: wordpress)

  • 1st September 2026
The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the saas_upload_logo() function combined with an authorization bypass on the WPLP connector REST endpoints in all versions up to, and including, ...
Continue reading

PaperCut NG/MF: PaperCut NG/MF Missing Authentication for Critical Function Vulnerability

  • 1st September 2026

PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-81578

Continue reading

PaperCut NG/MF: PaperCut NG/MF Unsafe Reflection Vulnerability

  • 1st September 2026
PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.Source: CISA Known Exploited ...
Continue reading