Crit
2026-08-27 18:01Z · last 4h · 32 findings
· glm-5.2:cloud
Threat Brief — 2026-08-27 — Splunk RCE hits KEV, PaperCut zero-day live, ICS batch lands
Executive summary: A CVSS 9.8 unauthenticated RCE in Splunk Enterprise (CVE-2026-20253KEV) is now in CISA's Known Exploited Vulnerabilities catalog — patch immediately if you run Splunk 10.x. PaperCut NG/MF is under active zero-day exploitation across all versions. CISA published a fresh batch of ICS advisories, one flagging a Fuel-Boss flaw with known ransomware involvement. Teletype.in went offline and emergency-migrated to a new domain.
Top items
- Splunk Enterprise unauthenticated RCE (CVE-2026-20253KEV, CVSS 9.8) — in CISA KEV. The PostgreSQL sidecar service endpoint in Splunk Enterprise 10.2 (<10.2.4) and 10.x (<10.0.7) lacks authentication (CWE-306), letting any network-reachable attacker achieve remote code execution. This vulnerability is already in CISA's Known Exploited Vulnerabilities catalog, meaning active exploitation is confirmed. (src: NVD / CISA KEV)
- PaperCut NG/MF zero-day actively exploited in the wild. PaperCut warns that hackers are exploiting a vulnerability across all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. No patch timeline has been confirmed yet — if print management servers are exposed, isolate them now. First reported 2026-08-27 by RSS:bleepingcomputer-main. (src: BleepingComputer)
- All-Line Equipment Company Fuel-Boss — remote command execution with known ransomware use. CISA's ICS advisory covers vulnerabilities allowing remote arbitrary command/code execution. CVE-2019-11043KEV·R is listed in CISA KEV with known ransomware activity, making this the highest-risk item in today's ICS batch. (src: CISA ICS Advisory)
- Xiiaozet LK100W — full device takeover. Vulnerabilities in versions prior to 2.1.240 (CVE-2026-78037 and CVE-2026-78038) allow an attacker to gain full control of the device. (src: CISA ICS Advisory)
- Ebyte NA111-M — full device compromise. Firmware 9013-2-17 is affected by multiple CVEs (CVE-2026-73125 and others) allowing complete device compromise. (src: CISA ICS Advisory)
- Applied Systems Engineering ASE2000 V2 Communications Test Set — file read/write, SSRF, MITM. Successful exploitation allows arbitrary local file read/write, outbound network requests, and connection interception for impersonation. (src: CISA ICS Advisory)
- Teletype.in offline — emergency domain migration. The publishing platform went offline and urgently migrated to teletype.media while the primary domain is being restored. No attribution yet; treat as an active availability incident. (src: SecurityLab RU)
Themes
- ICS/OT exposure week: CISA dropped seven ICS advisories today (Mitsubishi Electric, Rockwell Automation OTTO Fleet Manager, Xiiaozet, Ebyte, All-Line Fuel-Boss, ASE2000, plus a Mitsubishi update) — a reminder that OT asset inventories need continuous reconciliation against advisory feeds.
- Active exploitation dominates: Both Splunk and PaperCut are under real-world attack right now. The pattern this week is fewer theoretical bugs and more live weaponization of critical infrastructure software — prioritise patching anything internet-facing before anything else.
