Forwarded from TWCERTCC (Taiwan Computer Network Crisis Response and Coordination Center) Security Alert TWCERTCC-200-202609-00000009
【CVE-2026-82078】PaperCut NG/MF Unsafe Reflection Vulnerability (CVSS v3.1: 9.1)
【Exploited by Ransomware: Unknown】 PaperCut NG/MF has an unsafe reflection vulnerability that may allow an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode located on the application classpath under the security context of the PaperCut server process.
【CVE-2026-81578】PaperCut NG/MF Missing Authentication for Critical Function Vulnerability (CVSS v3.1: 9.8)
【Exploited by Ransomware: Unknown】 PaperCut NG/MF has a missing authentication for critical function vulnerability that allows an unauthenticated remote attacker to modify specific system configurations.
【CVE-2026-59822】BerriAI LiteLLM Improper Authentication Vulnerability (CVSS v3.1: 8.2)
【Exploited by Ransomware: Unknown】 The MCP Streamable HTTP endpoint of BerriAI LiteLLM has an improper authentication vulnerability that may allow an unauthenticated attacker to use an arbitrary Bearer token to create an authenticated MCP session.
【CVE-2026-48710】Kludex Starlette HTTP Request/Response Smuggling Vulnerability (CVSS v3.1: 6.5)
【Exploited by Ransomware: Unknown】 Kludex Starlette has an HTTP request/response smuggling vulnerability that may allow an attacker to inject a path into the Host field and place it before the actual path; when the system's authentication mechanism relies on the reconstructed
URL path, this may lead to issues such as authentication bypass.
【CVE-2026-49869】Kestra
OSS OS Command Injection Vulnerability (CVSS v3.1: 10.0)
【Exploited by Ransomware: Unknown】 Kestra
OSS has an
OS command injection vulnerability that may allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.
【CVE-2026-82329】JFrog Artifactory Improper Authentication Vulnerability (CVSS v3.1: 9.8)
【Exploited by Ransomware: Unknown】 JFrog Artifactory has an improper authentication vulnerability that, under default configurations, may allow an unauthenticated attacker with network access to gain administrative privileges.
【CVE-2026-9586】Sangoma Switchvox SQL Injection Vulnerability (CVSS v3.1: 9.8)
【Exploited by Ransomware: Unknown】 Sangoma Switchvox has a SQL injection vulnerability that allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database, including performing database operations and remote code execution, by sending a single crafted request.
【CVE-2026-83548】SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability (CVSS v3.1: 10.0)
【Exploited by Ransomware: Unknown】 SonicWall SMA1000 Appliances has a server-side request forgery vulnerability that may allow an unauthenticated remote attacker to access sensitive functions without authorization and perform unauthorized operations.
【CVE-2026-83549】SonicWall SMA1000 Appliances
OS Command Injection Vulnerability (CVSS v3.1: 7.8)
【Exploited by Ransomware: Unknown】 SonicWall SMA1000 Appliances has an
OS command injection vulnerability that may allow an authenticated remote attacker with administrative privileges to execute arbitrary
OS commands, potentially leading to remote code execution.
【CVE-2026-85046】Google Chromium V8 Type Confusion Vulnerability (CVSS v3.1: 8.8)
【Exploited by Ransomware: Unknown】 Google Chromium V8 has a type confusion vulnerability. A remote attacker can execute arbitrary code within the sandbox via a crafted
HTML web page. This vulnerability may affect multiple web browsers built on Chromium, including but not limited to Google Chrome, Microsoft Edge, and Opera.