ELEVATED 7 min read 28 Aug 2026

Xiiaozet LK100W Leads Today's Security Review

Threat Level: Elevated Tags: cve-2026-78037, cve-2026-78239, cve-2026-76943, cwe-306, cve-2026-54718, cve-2026-54721, cwe-1336, cve-2018-19518, cve-2019-11043, cwe-120

Key findings
01
Xiiaozet LK100W
CRITICAL
Successful exploitation of these vulnerabilities could allow an attacker to take control over the device. The assigned identifier is CVE-2026-78239.
02
Multiple vulnerabilities in Silverstripe
HIGH
CVE coverage: CVE-2026-54718, CVE-2026-54721.
03
All-Line Equipment Company Fuel-Boss
HIGH
Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems. The assigned identifier is CVE-2019-11043.
04
Applied Systems Engineering ASE2000 V2 Communications Test Set
HIGH
Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the trusted peer, complete the TLS handshake, and read or modify the protected communications.
05
aiosmtplib: STARTTLS response injection
MEDIUM
Exploit availability / observed attacks: Observed in-the-wild exploitation status is unknown.
06
WebOb: Open redirect in Location header normalization via leading C0 control /
MEDIUM
Exploit availability / observed attacks: Observed in-the-wild exploitation status is unknown.
07
libreoffice-convert vulnerable to path traversal / arbitrary file write
MEDIUM
Exploit availability / observed attacks: Observed in-the-wild exploitation status is unknown.
08
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter
MEDIUM
Exploit availability / observed attacks: Observed in-the-wild exploitation status is unknown.
09
n8n-nodes-sqlite3 vulnerable to path traversal
MEDIUM
Exploit availability / observed attacks: Observed in-the-wild exploitation status is unknown.
10
Silverstripe Framework: Possible XSS attack through media embed
MEDIUM
Exploit availability / observed attacks: Observed in-the-wild exploitation status is unknown.
11
Rockwell Automation OTTO Fleet Manager
MEDIUM
Successful exploitation of this vulnerability could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. The assigned identifier is CVE-2026-75112.
12
Mitsubishi Electric CNC Series (Update A)
MEDIUM
Successful exploitation of this vulnerability could allow a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition in the affected products. The assigned identifier is CVE-2025-2399.
13
cakephp/queue’s Incomplete Comparison in getUniqueId vulnerable to collisions
LOW
Exploit availability / observed attacks: Observed in-the-wild exploitation status is unknown.
14
PaperCut warns of NG, MF flaw exploited in zero-day attacks
INFO
PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.
15
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
INFO
Brian Krebs reports: Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever.

Executive assessment

Today's brief leads with Xiiaozet LK100W. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.

Finding 01 — Xiiaozet LK100W

What changed: Successful exploitation of these vulnerabilities could allow an attacker to take control over the device.

Technical evidence: CVE-2026-78239; CVSS v3.1 9.8; weakness ['CWE-306']; technical confidence Medium.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-78239 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: www.cisa.gov](<https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-01>)

Finding 02 — Multiple vulnerabilities in Silverstripe

What changed: CVE coverage: CVE-2026-54718, CVE-2026-54721.

Technical evidence: CVE-2026-54718; CVSS v3.1 7.2; weakness ['CWE-1336']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-54718 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-39mm-rwm3-29jp>)

Finding 03 — All-Line Equipment Company Fuel-Boss

What changed: Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems.

Technical evidence: CVE-2019-11043; CVSS v3.1 8.7; weakness ['CWE-120']; technical confidence High.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: Observed in-the-wild exploitation is confirmed.

Action: Map CVE-2019-11043 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

affected product not structured

[Evidence source: www.cisa.gov](<https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-02>)

Finding 04 — Applied Systems Engineering ASE2000 V2 Communications Test Set

What changed: Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the trusted peer, complete the TLS handshake, and read or modify the protected communications.

Technical evidence: CVE-2026-18717; CVSS v3.1 7.4; weakness ['CWE-295']; technical confidence Medium.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-18717 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: www.cisa.gov](<https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-04>)

Finding 05 — aiosmtplib: STARTTLS response injection

What changed: CVE coverage: CVE-2026-55558.

Technical evidence: CVE-2026-55558; CVSS v3.1 5.9; weakness ['CWE-74']; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-55558 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-vxj7-4xrp-5vr4>)

Finding 06 — WebOb: Open redirect in Location header normalization via leading C0 control /

What changed: CVE coverage: CVE-2026-54770.

Technical evidence: CVE-2026-54770; CVSS v3.1 6.1; weakness ['CWE-601']; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-54770 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-6hx8-3wjj-gr8g>)

Finding 07 — libreoffice-convert vulnerable to path traversal / arbitrary file write

What changed: CVE coverage: CVE-2026-54732.

Technical evidence: CVE-2026-54732; CVSS v3.1 6.5; weakness ['CWE-22']; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-54732 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-gmxc-r82q-347r>)

Finding 08 — Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter

What changed: CVE coverage: CVE-2026-42350.

Technical evidence: CVE-2026-42350; CVSS v4.0 5.1; weakness ['CWE-601']; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-42350 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-g7gw-m874-7rmf>)

Finding 09 — n8n-nodes-sqlite3 vulnerable to path traversal

What changed: CVE coverage: CVE-2026-54687.

Technical evidence: CVE-2026-54687; CVSS v4.0 6.1; weakness ['CWE-22']; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-54687 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-q7m3-rhxg-7vxr>)

Finding 10 — Silverstripe Framework: Possible XSS attack through media embed

What changed: CVE coverage: CVE-2026-54720.

Technical evidence: CVE-2026-54720; CVSS v3.1 5.4; weakness ['CWE-79']; technical confidence Medium.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-54720 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-gvrw-qqp5-jgc5>)

Finding 11 — Rockwell Automation OTTO Fleet Manager

What changed: Successful exploitation of this vulnerability could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes.

Technical evidence: CVE-2026-75112; CVSS v4.0 6.9; weakness ['CWE-916']; technical confidence Medium.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-75112 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: www.cisa.gov](<https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-03>)

Finding 12 — Mitsubishi Electric CNC Series (Update A)

What changed: Successful exploitation of this vulnerability could allow a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition in the affected products.

Technical evidence: CVE-2025-2399; CVSS v3.1 5.9; weakness ['CWE-1285']; technical confidence Medium.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2025-2399 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: www.cisa.gov](<https://www.cisa.gov/news-events/ics-advisories/icsa-26-078-05>)

Finding 13 — cakephp/queue’s Incomplete Comparison in getUniqueId vulnerable to collisions

What changed: CVE coverage: CVE-2026-54713.

Technical evidence: CVE-2026-54713; CVSS v3.1 3.7; weakness ['CWE-1023']; technical confidence High.

Why it matters: The cited reporting affects widely deployed technology, so exposure validation and source verification need explicit ownership.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-54713 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-r5pm-vrc5-3m73>)

Finding 14 — PaperCut warns of NG, MF flaw exploited in zero-day attacks

What changed: PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: The cited source reports active in-the-wild exploitation; independent corroboration (CISA KEV or grounded vendor data) is not yet available.

Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.

Evidence limits: grounded severity unavailable

exploitation reported by the source, not independently corroborated

fixed version or patch state unknown

affected product not structured

[Evidence source: www.bleepingcomputer.com](<https://www.bleepingcomputer.com/news/security/papercut-warns-of-ng-mf-flaw-exploited-in-zero-day-attacks/>)

Finding 15 — Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

What changed: Brian Krebs reports: Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever.

Why it matters: The cited reporting affects widely deployed technology, so exposure validation and source verification need explicit ownership.

Observed status: The cited source reports an active supply-chain compromise; exposure depends on use of the affected packages rather than exploitation of a single vulnerability.

Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.

Evidence limits: grounded severity unavailable

exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: databreaches.net](<https://databreaches.net/2026/08/27/two-alleged-teampcp-hackers-arrested-in-australia/>)

cve-2018-19518cve-2019-11043cve-2025-2399cve-2026-18717cve-2026-42350cve-2026-54687cve-2026-54713cve-2026-54718cve-2026-54720cve-2026-54721

Act on this brief

Map detection coverage gaps for the techniques above, or generate Sigma rules from the named CVEs.