SAP Kernel RCE Vulnerability Hits 10,000+ Systems

SAP Kernel RCE Vulnerability Hits 10,000+ Systems

A maximum-severity SAP kernel RCE vulnerability, tracked as CVE-2026-44756 and named OVERPASS by Onapsis Research Labs, lets an unauthenticated attacker reach shared SAP kernel code before any session authenticates — and it is reachable over three separate protocol paths at once. SAP patched the CVSS 10.0 flaw on September 8, 2026, as part of its…

Read More

PaperCut RCE Vulnerability Actively Exploited

A PaperCut RCE vulnerability chain is under active exploitation on PaperCut NG and MF servers. Two flaws let attackers run code with no login. Patch now.

A newly disclosed PaperCut RCE vulnerability is already being exploited against PaperCut NG and PaperCut MF print management servers worldwide. PaperCut confirmed active attacks on August 27, 2026, shipped an emergency patch within hours, then replaced it with a hardened second patch the next morning after researchers found the first fix incomplete. Every organization running…

Read More

SAP Commerce Cloud CVE-2026-58231: CVSS 10.0 RCE

SAP Commerce Cloud CVE-2026-58231 (CVSS 10.0) lets unauthenticated attackers hit the Data Hub import endpoint for code execution. Patch and mitigation steps.

SAP Commerce Cloud CVE-2026-58231, a maximum-severity (CVSS 10.0) flaw disclosed on SAP’s August 2026 Security Patch Day, lets an unauthenticated attacker with network access reach the Data Hub import endpoint and potentially execute arbitrary code — no login, no user interaction, just a crafted request to a component many DACH e-commerce and manufacturing storefronts run…

Read More

Microsoft Teams Vishing Ransomware Hits in 17 Hours

A Microsoft Teams vishing ransomware campaign, STAC4749, breached dozens of firms via fake IT-helpdesk calls, encrypting networks within 17 hours.

A Microsoft Teams vishing ransomware campaign has hit dozens of North American organizations since February 2026, using two-minute fake IT-helpdesk phone calls to gain a foothold that, in the fastest confirmed case, ended in full Chaos ransomware encryption within 17 hours of first contact. What Happened Security vendor Sophos tracked the campaign to a financially…

Read More

ZEGO Cyberattack Insolvency: A Six-Week Shutdown

ZEGO cyberattack insolvency

ZEGO cyberattack insolvency is now a real-world case study, not a hypothetical: a 35-year-old German textile finisher in Aschaffenburg has filed for insolvency after a cyberattack in March 2026 halted production for nearly six weeks — and the type of attack that caused it still hasn’t been publicly disclosed. What Happened ZEGO Textilveredelungszentrum GmbH, founded…

Read More