View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

PaperCut NG/MF Zero-Day Exploited Against Internet-Facing Servers

🚨 ACTIVE EXPLOITATION

  • PaperCut NG/MF Zero-Day Exploited Against Internet-Facing Servers
    Attackers are exploiting a PaperCut NG/MF zero-day affecting all versions.
    • PaperCut NG and MF print management customers are affected, including offices, schools, and other organizations.
    • The vulnerability affects all NG/MF versions; emergency patches cover v25 and v26, while v24 fixes remain in progress.
    • Huntress identified a pre-authentication RCE chain allowing unauthenticated attackers to control trusted configuration and execute arbitrary Java code.
    • Observed indicators include suspicious pc-app.exe activity, altered or missing server.log files, and errors containing jdbc:no:x or cardID: VALUES CAST.
      πŸ“„ Source: huntress.com Β· πŸ“Ž Coverage: bleepingcomputer.com Β· πŸ‘ via SecurityWeek, The Hacker News

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • APT28-Linked HOOKEDGE Backdoor Targets European Government Organizations
    APT28-linked campaigns deployed the HOOKEDGE backdoor against European government and diplomatic organizations.
    • European government and diplomatic organizations in Romania, Spain, and TΓΌrkiye were targeted.
    • The previously undocumented HOOKEDGE is a lightweight Windows batch-script backdoor.
    • The malware abuses Microsoft Edge and webhook.site for command-and-control and data exfiltration.
    • Campaign activity ran from late September 2025 through early April 2026.
      πŸ“Ž Coverage: thehackernews.com Β· πŸ‘ via The Hacker News

πŸ”“ CVEs & KEV

  • CVE-2026-77016 β€” CVSS 9.6 β€” Workeera Remote Tech Job Board before 1.0.6 - Subscriber+ Arbitrary File Deletion ...

  • CVE-2026-40541 β€” CVSS 9.0 β€” An improper neutralization of input during web page generation ('Cross-site S...

  • CVE-2026-78333 β€” CVSS 8.8 β€” 12 Step Meeting List 3.17 - 3.19.16 - Unauthenticated Stored XSS via Geocode ...

  • CVE-2026-77018 β€” CVSS 8.8 β€” Workeera Remote Tech Job Board before 1.0.6 - Subscriber+ Arbitrary File Upload vi...

  • CVE-2026-77017 β€” CVSS 7.7 β€” Workeera Remote Tech Job Board before 1.0.6 - Subscriber+ Arbitrary File Read via ...

  • CVE-2026-19715 β€” CVSS 7.5 β€” WP OAuth Server before 6.3.1 - Unauthenticated OAuth Token and User Data Disclosur...

  • CVE-2026-19223 β€” CVSS 7.2 β€” Smush before 4.3.2 - Admin+ Network-Wide RCE via Hub Connector on MultisiteThe Smu...

  • CVE-2026-13415 β€” CVSS 7.2 β€” CMP - Coming Soon & Maintenance before 4.1.18 - Editor+ Privilege Escalation via c...

  • CVE-2026-19225 β€” CVSS 6.6 β€” Defender Security before 6.2.0 - Admin+ Network-Wide RCE via Hub Connector on Mult...

  • CVE-2026-9548 β€” CVSS 6.5 β€” An improper neutralization of input during web page generation ('Cross-site S...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check