1. Top Action Item

Patch PaperCut NG and MF print servers now. Attackers are actively chaining two PaperCut flaws to gain unauthenticated remote control over PaperCut's trusted configuration and execute arbitrary Java code, and the vendor has released a fresh emergency fix with additional hardening. Anyone running PaperCut NG or MF should apply that emergency update immediately, then verify no unauthorized accounts, scripts, or configuration changes were left behind. Also confirm your ownCloud instance is patched against CVE-2023-49105, which CISA added to its Known Exploited Vulnerabilities catalog this week after it was used to steal data from a Philippine nuclear research body.


2. Exploited This Week

PaperCut NG / MF — actively exploited chained flaws (CVE: see source)

ownCloud — CVE-2023-49105

Cosmos EVM module — GHSA-7g4w-cg88-2cq2


3. Critical Patch Roundup

ServiceNow AI Platform — three CVSS 10.0 flaws (CVE: see source)

cPanel & WHM — CVE-2026-65643

WordPress plugins/themes: WPMU DEV Dashboard, Avada, TranslatePress, Pods, GiveWP — CVE-2026-76581 and related critical flaws

ZBT routers (Shenzhen Zhibotong) — CVE-2026-74232, CVE-2026-74233

Microsoft Edge (Chromium-based), Edge for iOS, and Copilot Chat — multiple CVEs


4. Home / SOHO Impact


5. Enterprise Impact


6. What To Patch First

  1. PaperCut NG/MF emergency update — actively exploited unauthenticated RCE chain (see source for CVE).
  2. ownCloud patched release — CVE-2023-49105 (CISA KEV; exploited against nuclear research body).
  3. ServiceNow AI Platform update — three CVSS 10.0 flaws (critical; hosted already fixed).
  4. cPanel & WHM patch — CVE-2026-65643 (critical; tenant-to-root server takeover).
  5. Cosmos EVM module upgrade — GHSA-7g4w-cg88-2cq2 (actively exploited; funds drained).
  6. WordPress: WPMU DEV Dashboard, Avada, TranslatePress, Pods, GiveWP updates — CVE-2026-76581 and related (CVSS 9.8; site takeover/RCE).
  7. Microsoft Edge / Chromium update — CVE-2026-72984, CVE-2026-78891, and others (widely deployed browser RCE fixes).
  8. Replace ZBT/white-label routers — CVE-2026-74232, CVE-2026-74233 (factory backdoors; no patch available).

Sources