VYPR
AI Brief2026-09-02· generated Sep 2, 2026

PaperCut Exploited; Tenda, Totolink Routers Hit

PaperCut vulnerabilities are actively exploited, while numerous critical flaws hit Tenda and Totolink routers.

CISA has added two vulnerabilities in PaperCut NG and MF to its Known Exploited Vulnerabilities (KEV) catalog, signaling active exploitation in the wild. The flaws, identified as CVE-2026-81578, allow unauthenticated remote attackers to perform backend actions through the web management interface. Exploitation chains have been observed where attackers leverage these vulnerabilities to deploy remote access tools on compromised PaperCut servers, indicating a significant threat to organizations relying on this print management software. Patches and mitigations should be prioritized immediately.

A batch of critical vulnerabilities has been disclosed across several Tenda router models, including the AC18 and AC1206, and the HG10. These flaws, such as CVE-2026-82695, CVE-2026-82694, CVE-2026-82693, and CVE-2026-82542, primarily involve missing authentication and improper access controls in various web interface components. Attackers can exploit these remotely to gain unauthorized access or execute arbitrary commands. Given the widespread use of these devices in homes and small businesses, these vulnerabilities pose a substantial risk if left unaddressed.

Multiple critical vulnerabilities have been disclosed in Totolink T6 routers, with CVE-2026-51740, CVE-2026-51734, CVE-2026-51724, CVE-2026-51718, CVE-2026-51709, CVE-2026-51708, CVE-2026-51674, and CVE-2026-51670 among them. These flaws are primarily due to incorrect access control in various functions within the router's web interface, allowing unauthenticated attackers to terminate services, trigger updates, remove security configurations, or reconfigure Wi-Fi settings. The sheer number of disclosed vulnerabilities in a single product highlights a systemic security weakness that could be leveraged for widespread disruption or network compromise.

A critical sandbox escape vulnerability, CVE-2026-75874, has been identified in Mozilla's Remote Settings Client component, affecting Firefox, Thunderbird, and Firefox ESR. This flaw allows for a sandbox escape, a severe security risk that could enable attackers to break out of the browser's security sandbox and potentially compromise the underlying system. While patches are available in updated versions of the affected software, users must ensure they are running the latest releases to protect themselves from potential exploitation.

Several critical vulnerabilities have been reported in various industrial and embedded systems. CVE-2026-84147 in an unnamed ERP system allows arbitrary file uploads due to improper authentication and file validation. CVE-2026-78012 in NetStaX EtherNet/IP Stack could lead to memory corruption and denial of service through malformed explicit-message requests. Additionally, CVE-2026-18808 in Klemsan KIO allows for code injection, and CVE-2026-18210 in TRtek products is susceptible to SQL injection. These vulnerabilities highlight ongoing risks in specialized software and hardware, often with significant operational impacts.

Synthesized by Vypr AI
PaperCut Exploited; Tenda, Totolink Routers Hit · VYPR