RedLegg RedLegg is a veteran-owned, global cybersecurity company.

Security Bulletin: PaperCut NG and PaperCut MF Vulnerabilities — Two vulnerabilities affecting PaperCut NG and MF are ac...
09/01/2026

Security Bulletin: PaperCut NG and PaperCut MF Vulnerabilities — Two vulnerabilities affecting PaperCut NG and MF are actively exploited in the wild, with PaperCut confirming customer incidents.

CVE-2026-82078 (CVSS 9.4) is an unsafe dynamic class loading vulnerability that may allow arbitrary Java bytecode ex*****on under the security context of the PaperCut server process.

CVE-2026-81578 (CVSS 8.8) is an improper access control vulnerability that may allow unauthenticated attackers to trigger administrative backend actions and modify certain system configurations.

PaperCut has released Emergency Patch Release 2, which supersedes the original emergency patch and adds additional hardening. Organizations should install Release 2 across all PaperCut NG and MF Application Servers, including Site Servers and secondary or print servers, even if the original emergency patch was already applied.

Teams should also review http://server.log, IDS, EDR, and network telemetry for indicators of exploitation or suspicious activity involving http://pc-app.exe.


https://hubs.li/Q04w8z160

PaperCut NG and MF vulnerabilities (CVE-2026-82078, CVE-2026-81578) may enable code ex*****on and unauthorized configuration changes. Actively exploited—install Emergency Patch Release 2.

Security Bulletin: Multiple Critical Vulnerabilities in ServiceNow AI Platform — Three vulnerabilities affecting the Ser...
08/28/2026

Security Bulletin: Multiple Critical Vulnerabilities in ServiceNow AI Platform — Three vulnerabilities affecting the ServiceNow AI Platform have each received a CVSS score of 10.0.
CVE-2026-18885 and CVE-2026-18886 are code injection vulnerabilities that may allow unauthenticated attackers to execute arbitrary code, modify instance data, or escalate privileges under certain circumstances.

CVE-2026-74820 is a SQL injection vulnerability that may allow an unauthenticated attacker to execute arbitrary SQL statements against the underlying database and access or modify instance data.

ServiceNow has released updates addressing all three vulnerabilities. Customers should verify their instance against the fixed versions provided in ServiceNow's August 2026 advisory. Hosted instances enrolled in ServiceNow's Patching Program received updates automatically, while self-hosted customers should apply the appropriate patched release immediately.

No known exploitation has been reported at this time.


Three critical ServiceNow AI Platform vulnerabilities (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820) may enable code injection, privilege escalation, or SQL injection. Update immediately.

Security Bulletin: Citrix NetScaler Memory Overflow Vulnerability — NetScaler ADC and NetScaler Gateway (CVE-2026-8452) ...
08/27/2026

Security Bulletin: Citrix NetScaler Memory Overflow Vulnerability — NetScaler ADC and NetScaler Gateway (CVE-2026-8452) contain a high-severity vulnerability affecting appliances configured as a Gateway or AAA virtual server. CVSS 8.8.
CVE-2026-8452 is actively exploited in the wild and has been added to CISA's Known Exploited Vulnerabilities (KEV) Catalog.

Organizations should immediately update affected NetScaler deployments to the applicable fixed version and verify whether Gateway or AAA functionality is enabled.

Teams should also check affected appliances for webshells or other unauthorized files and review system logs for unexpected Packet Engine restarts, crashes, or anomalous inbound traffic.


Citrix NetScaler vulnerability (CVE-2026-8452) affects Gateway and AAA configurations and is actively exploited. Apply the applicable fixed version immediately.

Security Bulletin: Multiple Critical Vulnerabilities Affecting Ubiquiti Products — Three vulnerabilities affecting UniFi...
08/26/2026

Security Bulletin: Multiple Critical Vulnerabilities Affecting Ubiquiti Products — Three vulnerabilities affecting UniFi Protect, UniFi OS devices, and UniFi Talk have received CVSS scores of 10.0.

CVE-2026-77537 and CVE-2026-77554 are command injection vulnerabilities that may allow an attacker with network access to execute commands on the host device without privileges.

CVE-2026-77550 affects multiple UniFi OS device families and may allow an attacker with network access to bypass authentication.
Ubiquiti has released fixed versions addressing all three vulnerabilities. Organizations should update affected UniFi products immediately and restrict management interfaces to trusted networks. No known exploitation has been reported at this time.


Multiple critical Ubiquiti vulnerabilities (CVE-2026-77537, CVE-2026-77550, CVE-2026-77554) may allow command ex*****on or authentication bypass. Update affected UniFi products immediately

Security Bulletin:  Zimbra Collaboration Suite OS Command Injection — Zimbra Collaboration Suite (CVE-2026-73570) contai...
08/25/2026

Security Bulletin: Zimbra Collaboration Suite OS Command Injection — Zimbra Collaboration Suite (CVE-2026-73570) contains a high-severity vulnerability that may allow unauthenticated attackers to execute arbitrary operating system commands. CVSS 8.9.
The flaw affects the SNMP monitoring component when the optional zimbra-snmp package is installed and SNMP notifications are enabled. An attacker can exploit improper input sanitization without credentials or user interaction to execute commands with the privileges of the Zimbra user.

CVE-2026-73570 is actively exploited in the wild. Organizations should immediately upgrade to Zimbra Collaboration Suite 10.1.20 or later, confirm whether zimbra-snmp and SNMP notifications are enabled, and review affected servers for suspicious activity, unauthorized files, webshells, or other persistence mechanisms.


Zimbra Collaboration Suite vulnerability (CVE-2026-73570) allows unauthenticated OS command ex*****on through SNMP notification processing. Actively exploited—update immediately.

Emergency Security Advisory: Citrix NetScaler Authentication Bypass (CVE-2026-19490)Cloud Software Group has released se...
08/20/2026

Emergency Security Advisory: Citrix NetScaler Authentication Bypass (CVE-2026-19490)
Cloud Software Group has released security updates for a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway deployments configured for Gateway or AAA functionality.

Successful exploitation could allow a remote attacker to bypass authentication and gain unauthorized access to affected appliances.

Recommended actions:
• Upgrade affected NetScaler ADC and Gateway deployments to the latest fixed release
• Verify whether your appliance configuration meets the conditions required for exploitation
• Prioritize internet-facing SSL VPN, ICA Proxy, CVPN, RDP Proxy, and AAA deployments
• Restrict management interface access to trusted networks until updates are fully deployed • Review authentication logs for suspicious or unexpected activity

Although no active exploitation has been reported, organizations should prioritize remediation given the critical severity and the role NetScaler often plays in remote access infrastructure.


CVE-2026-19490 is a critical authentication bypass vulnerability in Citrix NetScaler ADC and Gateway. Apply updates immediately to protect exposed remote access systems.

Security Bulletin: Security Bulletin: macOS Screen Sharing Pre-Authentication Bypass — Apple macOS (CVE-2026-65400) cont...
08/18/2026

Security Bulletin: Security Bulletin: macOS Screen Sharing Pre-Authentication Bypass — Apple macOS (CVE-2026-65400) contains a critical authentication bypass vulnerability that may allow unauthorized remote access. CVSS 9.8.

The flaw affects the Screen Sharing service (screensharingd) and results from an error in the implementation of Secure Remote Password authentication. An attacker on the network can establish a Screen Sharing session without valid credentials, and the session continues without cryptographic protection.

Apple has confirmed active exploitation in the wild. Organizations should immediately update affected macOS systems to the latest fixed versions. If immediate patching is not possible, disable Screen Sharing, ensure TCP port 5900 is not exposed to the internet, and review systems for indicators of compromise such as cryptomining activity, unexpected high CPU utilization, unfamiliar scheduled tasks, or unrecognized root-level processes.


Apple macOS Screen Sharing vulnerability (CVE-2026-65400) allows pre-authentication bypass and unauthorized remote access. Actively exploited. Update immediately.

Security Bulletin: VMware vCenter Syslog Server Remote Code Ex*****on — VMware vCenter Server (CVE-2026-59310) contains ...
08/14/2026

Security Bulletin: VMware vCenter Syslog Server Remote Code Ex*****on — VMware vCenter Server (CVE-2026-59310) contains a critical directory traversal vulnerability that may allow unauthenticated remote code ex*****on. CVSS 9.8.

The flaw exists in the Syslog server component and results from improper pathname validation. An attacker with network access can exploit the vulnerability without authentication or user interaction to execute arbitrary code on the vCenter server, potentially leading to full compromise of the virtualization management environment.

Broadcom has confirmed active exploitation in the wild. Organizations should immediately upgrade to the appropriate fixed vCenter release, identify all internet-accessible or network-reachable vCenter instances, and review systems for indicators of compromise, including unexpected outbound connections, reverse SSH persistence, unauthorized cron jobs, or suspicious scheduled tasks.


VMware vCenter vulnerability (CVE-2026-59310) allows unauthenticated remote code ex*****on through directory traversal. Actively exploited. Patch immediately.

Security Bulletin: FortiWeb RADIUS Type Admin Authentication Vulnerability — FortiWeb (CVE-2026-26035) contains a high-s...
08/13/2026

Security Bulletin: FortiWeb RADIUS Type Admin Authentication Vulnerability — FortiWeb (CVE-2026-26035) contains a high-severity improper authentication vulnerability that may allow unauthenticated administrative access under a specific configuration. CVSS 8.8.

The flaw affects the Remote RADIUS Type Admin Authentication feature when a Remote Type administrator account has the non-default Wildcard setting enabled. In this scenario, an attacker may authenticate to the FortiWeb GUI or CLI using arbitrary credentials and obtain administrative access.

Organizations should immediately upgrade to the appropriate fixed FortiWeb version or apply Fortinet's recommended workaround by disabling the Wildcard setting on Remote Type administrator accounts. Administrators should also audit existing Remote Type accounts and review authentication logs for unexpected or unrecognized administrative logins.


FortiWeb vulnerability (CVE-2026-26035) may allow unauthenticated administrative access when a specific RADIUS wildcard configuration is enabled. Update or apply the vendor workaround.

Security Bulletin: Windows Ancillary Function Driver for WinSock Privilege Escalation — Microsoft Windows (CVE-2026-6882...
08/12/2026

Security Bulletin: Windows Ancillary Function Driver for WinSock Privilege Escalation — Microsoft Windows (CVE-2026-68820) contains a local elevation of privilege vulnerability in http://AFD.sys that may allow attackers to obtain SYSTEM privileges. CVSS 7.0.

The flaw is caused by a use-after-free condition that can be triggered by a low-privileged authenticated attacker through a specially crafted application. Successful exploitation enables privilege escalation to SYSTEM without requiring user interaction. Microsoft confirmed the vulnerability was actively exploited as a zero-day at the time of disclosure.

Organizations should immediately deploy the August 2026 cumulative updates across affected Windows systems, prioritize high-value endpoints, monitor for anomalous SYSTEM-level activity following low-privileged process ex*****on, and investigate suspicious privilege escalation events.


https://hubs.li/Q04sLr4j0

Windows AFD.sys vulnerability (CVE-2026-68820) allows local privilege escalation to SYSTEM. Actively exploited as a zero-day. Apply the August 2026 cumulative updates immediately.

Address

902 S RANDALL Road STE C319
Saint Charles, IL
60174

Alerts

Be the first to know and let us send you an email when RedLegg posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to RedLegg:

Shortcuts

Share