tag: Remote-Code-Execution · 3 items
- Engineer — Act: Unauthenticated RCE via chained flaws in PaperCut NG/MF is being actively exploited; apply the emergency patch immediately and audit PaperCut server logs for unexpected Java process execution or outbound connections predating the patch.
- SOC/IR — Act: Active exploitation of PaperCut print servers means assumed-breach posture is warranted — hunt for anomalous Java child processes or unusual network activity originating from PaperCut hosts since before the emergency patch date, and check EDR telemetry on any print-management systems.
- Leader — Plan: PaperCut NG/MF is common in enterprise and education environments; confirm with engineering that all instances are patched this week and verify no lateral movement occurred from print servers — prior PaperCut exploits (2023) drew board attention, so have a status update ready if asked.
- Engineer — Act: If you self-host Gitea, check your version immediately and patch to the latest release — Shadowserver confirms ongoing RCE exploitation against exposed instances, meaning unpatched servers are actively being targeted now.
- SOC/IR — Act: Audit your estate for internet-exposed Gitea instances and hunt for signs of RCE compromise (unexpected processes, new admin accounts, modified repos) since exploitation is described as active; a compromised source-code platform carries serious supply-chain risk.
- Leader — Plan: Confirm with engineering whether your organization runs self-hosted Gitea and verify patching status this week; a compromised internal code repository would pose a supply-chain risk worth flagging to leadership if exposure is confirmed.
- Engineer — Act: CVSS 9.0 with a public PoC on GitHub means opportunistic exploitation is imminent; update Elementor Pro to the latest patched release immediately and audit WordPress upload directories for any unexpected PHP files already dropped via the Forms module.
- SOC/IR — Act: A public PoC for unauthenticated RCE means mass scanning is likely underway; hunt for unauthorized PHP files in WordPress upload paths and review web server and WAF logs for suspicious POST requests targeting the Elementor Pro Forms endpoint since the disclosure date.
- Leader — Skip
- Signals: CVE-2026-32475 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub