Skip to main content

Overview

PaperCut has issued an urgent security advisory following two critical severity vulnerabilities found within PaperCut NG/MF. Successful exploitation of these vulnerabilities could lead to execution of arbitrary bytecode or modification to system configurations by a remote attacker. These vulnerabilities can be chained together to create a sophisticated attack on the system.

  • CVE-2026-82078 – Unsafe Reflection Vulnerability – CVSSv4.0 Score: 9.4
  • CVE-2026-81578 – Missing Authentication for Critical Function – CVSSv4.0 Score: 8.8

Affected Versions:

  • All versions of PaperCut MF / NG before Emergency Patch Release 3 (released on the 1st of September).

 

Gitea has released a security advisory for their latest critical severity vulnerability within the ‘diffpatch’ API. Successful exploitation of CVE-2026-60004 enables a remote attacker with write access to send a malicious patch to the diffpatch API endpoint, then plant an executable that runs shell commands as the Gitea service account.

  • CVE-2026-60004 – Code Injection Vulnerability – CVSSv3.1 Score: 9.8

Affected Versions:

  • All versions of Gitea from 1.17 until Gitea 1.27.1.

 

Plesk for Linux has discovered a local privilege escalation vulnerability. Exploitation of CVE-2026-67394 enables a customer with shell access to elevate their privileges to the root account on the hosting server. Plesk for Windows is unaffected by the vulnerability.

  • CVE-2026-67394 – OS Command Injection – CVSSv4.0 Score: 9.0

Affected Versions (for both Community and Enterprise Editions):

  • Plesk for Linux 18.0.34 until 18.0.79.9
  • Plesk for Linux 18.0.80 until 18.0.80.5

 

Recommended Action

Organisations are encouraged to review the appropriate security advisory pages and apply the updates:

PaperCut NG/MF: PaperCut Urgent Security Advisory

Gitea: Gitea Security Advisory

Plesk: Plesk Vulnerability Report

Topics

  • Advisory
  • Vulnerability
  • Exploit
  • Patches and Updates