[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":54,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":61,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":67,"vulnerability-29717":74},[4,15,21,27,33,39,44],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Network Scanner","compliance-pages-launch-network-scanner","Scheduled scans are the spine of every compliance framework. Are you audit-ready?","https:\u002F\u002Fpentest-tools.com\u002Fusage\u002Fcompliance",false,[11],"\u002Fnetwork-vulnerability-scanning\u002Fnetwork-security-scanner-online","Get compliance evidence","secondary","compliance-pages-launch",{"title":16,"slug":17,"text":18,"link":8,"external":9,"targets":19,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Website Scanner","compliance-pages-launch-website-scanner","Authenticated web-app scans show up in SOC 2, NIS2, and CRA Annex I. See why this is crucial for the business.",[20],"\u002Fwebsite-vulnerability-scanning\u002Fwebsite-scanner",{"title":22,"slug":23,"text":24,"link":8,"external":9,"targets":25,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Advanced Pentest Reporting","compliance-pages-launch-reporting","Editable DOCX. Immutable PDF. JSON for the GRC tool. See why these formats are on every auditor's checklist.",[26],"\u002Ffeatures\u002Fpentest-reporting",{"title":28,"slug":29,"text":30,"link":8,"external":9,"targets":31,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Integrations","compliance-pages-launch-integrations","Vanta, Jira, webhooks - they all route back to DORA, NIS2, SOC 2, ISO 27001, CRA. See why this is crucial for the business.",[32],"\u002Ffeatures\u002Fintegrations",{"title":34,"slug":35,"text":36,"link":8,"external":9,"targets":37,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Sniper","compliance-pages-launch-sniper","Five compliance framework pages now reference Sniper as the source of validated exploitability evidence. See them all.",[38],"\u002Fexploit-helpers\u002Fsniper",{"title":40,"slug":14,"text":41,"link":8,"external":9,"targets":42,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Homepage","Turn confirmed vulnerabilities into evidence your auditor accepts. Testing requirements for DORA, NIS2, SOC 2, ISO 27001, and CRA.",[43],"\u002F",{"title":45,"slug":46,"text":47,"link":48,"external":49,"targets":50,"cta":53,"variant":13,"campaign_id":46},"Office Hours #11 - Compliance cycle survey","office-hours-11","[Live Office Hours, Wed Sept 16] Continuous compliance evidence: from automated tools or tired humans?","https:\u002F\u002Fzoom.us\u002Fwebinar\u002Fregister\u002F5117815316917\u002FWN_FLMs2-vyQbCTB67guMJH-Q",true,[51,52],"\u002Finsights\u002Fcompliance-cycles-survey","\u002Finsights","Save your spot",["Island",55],{"key":56,"params":57,"result":59},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":58},"{}",{"head":60},{},["Island",62],{"key":63,"params":64,"result":65},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":58},{"head":66},{},["Island",68],{"key":69,"params":70,"result":72},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":71},"{\"text-color\":\"gray\"}",{"head":73},{},{"id":75,"detectable_with":76,"vuln_details":83,"vuln_id":102,"name":103,"published":104,"updated":84},29717,{"tool":77,"engine":80},{"id":78,"name":79},1,"Network Scanner",{"id":81,"name":82},2,"Nuclei",{"id":75,"codename":84,"description":84,"severity":85,"risk_description":86,"public_description":87,"public_recommendation":88,"recommendation":84,"references":89,"cvssv3":94,"epss_score":95,"epss_percentile":96,"cve":97,"in_cisa_catalog":49,"date":99,"software_type":84,"vendor":100,"product":101,"ptt_exploit_capabilities":84},null,"critical","The risk exists that a remote unauthenticated attacker can fully compromise the server to steal confidential information, install ransomware, or pivot to the internal network.","PaperCut NG and PaperCut MF versions 24.x through 26.x contain an authentication bypass vulnerability in the Apache Tapestry-based web interface. By crafting a complex-direct service request that specifies the public Home page as the render target while invoking the privileged ConfigEditor page's form listeners, an unauthenticated remote attacker can search and modify server configuration options. PaperCut's access control validates the render page but fails to validate the component page, allowing full configuration access without authentication. When chained with CVE-2026-82078, an attacker reconfigures external user lookup to use a malicious JDBC URL whose initialization SQL evaluates arbitrary Groovy code, achieving unauthenticated remote code execution. This vulnerability is actively exploited in the wild.","Update to PaperCut NG\u002FMF version 26.0.5, 25.0.13, or 24.1.10 or later. As an immediate mitigation, restrict network access to the PaperCut web management interface (default ports 9191 and 9192) to trusted administrative IPs only.",[90,91,92,93],"https:\u002F\u002Fwww.papercut.com\u002Fkb\u002FMain\u002Fsecurity-bulletin-27-aug-2026-urgent-security-advisory\u002F","https:\u002F\u002Fwww.rapid7.com\u002Fblog\u002Fpost\u002Fetr-papercut-ng-mf-critical-zero-day-exploited-in-the-wild\u002F","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-81578","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-82078",9.8,0.01617,0.74671,[98],"CVE-2026-81578","2026-08-28T00:00:00Z","papercut","papercut_ng,papercut_mf","NETSCAN-NUCLEI-CVE-CVE-2026-81578","PaperCut NG\u002FMF \u003C=26.0.4 - Unauthenticated ConfigEditor Access via Tapestry Complex-Direct","2026-09-15T00:00:00Z"]