Announcements

PaperCut NG/MF: PaperCut NG/MF Unsafe Reflection Vulnerability

  • 3rd September 2026
PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.Source: CISA Known Exploited ...
Continue reading

SonicWall SMA1000 Appliances: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

  • 3rd September 2026

SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-83548

Continue reading

Sangoma Switchvox: Sangoma Switchvox SQL Injection Vulnerability

  • 3rd September 2026
Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.Source: CISA Known Exploited Vulnerabilities Catalog — ...
Continue reading

JFrog Artifactory: JFrog Artifactory Improper Authentication Vulnerability

  • 3rd September 2026

JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-82329

Continue reading