This day 02:04 06:05 10:07 14:06 18:07 22:06
⚠ exploit status: CVE-2026-81578 · KEV CVE-2026-82078 · KEV
High  2026-09-01 14:06Z · last 4h · 12 findings · glm-5.2:cloud

Threat Brief — 2026-09-01 — PaperCut hits KEV, Exchange exposure persists

Executive summary: Two PaperCut NG/MF zero-days now appear in CISA's Known Exploited Vulnerabilities catalog, confirming active in-the-wild exploitation and raising the urgency for any exposed print-management servers. Nearly 22,000 unpatched Microsoft Exchange servers remain internet-exposed to a high-severity mailbox-hijack authentication bypass. Iranian actor Nimbus Manticore has expanded its recruiter-lure toolkit with cross-platform RATs targeting Linux and macOS, broadening the traditional Windows-only footprint of these campaigns.


Top items


Themes

KeV momentum on print and document infrastructure. The PaperCut KEV listings, following earlier exploitation reports, place print-management servers squarely in the active-attacker category alongside the Exchange exposure. Both product families are common in enterprise environments but often run with less patching discipline than core IT systems, making them pivot points for initial access.

Cross-platform expansion of established actors. Nimbus Manticore's move to Linux and macOS RATs reflects a broader industry trend where threat groups historically focused on Windows are building or acquiring multi-platform tooling, reducing the protective value of OS monocultures in targeted environments.

Social engineering as the reliable initial-access workhorse. The clipboard-hijacking CAPTCHA technique, the recruiter-lure coding tests, and the tech-support vishing campaigns all rely on human interaction rather than software exploitation—reinforcing that "asking" remains the most common and repeatable way into an organisation.


Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db