VYPR
AI Brief2026-09-02· generated Sep 2, 2026

What you need to know today.

PaperCut exploitation escalates, CISA adds KEVs, and critical flaws hit Tenda and Totolink routers.

PaperCut MF and NG are facing active exploitation due to an improper access control vulnerability in their web management interface. This flaw allows unauthenticated remote attackers to perform backend actions, leading to potential compromise. CISA has added CVE-2026-81578 to its Known Exploited Vulnerabilities (KEV) catalog, highlighting the urgency for patching. Multiple security outlets, including SecurityWeek and The Hacker News, report on the escalating attacks, with some noting that attackers are chaining vulnerabilities to achieve code execution. Rapid7 also confirmed active exploitation of this zero-day flaw.

A critical authentication bypass vulnerability (CVE-2026-82695) has been discovered in Tenda AC18 routers, specifically affecting the Telnet Handler component. This flaw allows unauthenticated remote attackers to gain unauthorized access. Similar authentication bypass issues were found in Tenda AC1206 routers (CVE-2026-82694 and CVE-2026-82693), impacting their Web UI and Telnet components. Additionally, a buffer overflow vulnerability (CVE-2026-82542) in Tenda HG10 routers could be triggered remotely by manipulating arguments in the Boa Web Server, potentially leading to further system compromise. Vypr Intelligence detailed these Tenda vulnerabilities, emphasizing the critical nature of the authentication bypasses.

Multiple critical vulnerabilities have been disclosed in Totolink T6 routers, primarily stemming from incorrect access control within various functions of the device's web interface. These flaws, including CVE-2026-51740, CVE-2026-51734, CVE-2026-51724, CVE-2026-51718, CVE-2026-51709, CVE-2026-51708, CVE-2026-51674, and CVE-2026-51670, allow unauthenticated remote attackers to perform actions such as terminating services, triggering updates, removing security configurations, reconfiguring Wi-Fi settings, and scheduling reboots. Vypr Intelligence reported on these findings, noting the large number of access control vulnerabilities disclosed in a single batch.

Mozilla has released patches for a critical sandbox escape vulnerability (CVE-2026-75874) in the Remote Settings Client component affecting Firefox, Thunderbird, and Firefox ESR. This vulnerability could allow attackers to break out of the browser's sandbox, potentially leading to further system compromise. The Hacker News and Vypr Intelligence highlighted this vulnerability, with the latter noting it was among 25 disclosed vulnerabilities affecting Mozilla Thunderbird.

Several other critical vulnerabilities have been reported, including an ERP system vulnerability (CVE-2026-84147) allowing arbitrary file uploads due to improper authentication and file type validation. Additionally, a memory corruption vulnerability (CVE-2026-78012) in NetStaX EtherNet/IP Stack could lead to denial of service or potential code execution. Code injection vulnerabilities were also found in Klemsan Electrical Electronics Inc. KIO (CVE-2026-18808), and SQL injection vulnerabilities were identified in TRtek Technological Products (CVE-2026-18210) and Teracity Software Technologies Inc. E-OSB (CVE-2026-18765). OpenThread also faces multiple denial-of-service vulnerabilities (CVE-2025-36939) related to MLE packet handling.

Synthesized by Vypr AI
PaperCut Exploitation Surges Amidst Critical Router Flaws · VYPR