ELEVATED 12 min read 31 Aug 2026

CC-4838 - PaperCut Releases Emergency Security Updates for Critical Vulnerabilities in PaperCut NG/MF Leads Today's Security Review

Threat Level: Elevated Tags: cve-2026-81578, cve-2026-82078, cwe-470, cve-2026-19685, cve-2025-9615, cwe-863, cve-2026-66787, cwe-345, cve-2026-75005, cwe-407

Key findings
01
CC-4838 - PaperCut Releases Emergency Security Updates for Critical Vulnerabilities in PaperCut NG/MF
CRITICAL
PaperCut NG/MF flaws permit configuration modification and arbitrary Java bytecode execution; NHS England reports active exploitation and confirmed customer incidents, and advises immediate Release 2 patching plus restriction of internet-accessible server interfaces.
02
NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties.
CRITICAL
NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.
03
lighthouse component of Red Hat Advanced Cluster Management for Kubernetes: Insufficient Verification of Data Authenticity
HIGH
A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP addresses within EndpointSlice objects. The assigned identifier is CVE-2026-66787.
04
Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% CPU for an extended period in graphql-limit-count routes.
HIGH
Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% CPU for an extended period in graphql-limit-count routes. The assigned identifier is CVE-2026-75005.
05
Multiple vulnerabilities in PLANET GS-4210-16P2S
HIGH
CVE coverage: CVE-2026-75121, CVE-2026-75122, CVE-2026-75123. The cited advisories disclose: /cgi-bin/dispatcher.cgi.
06
Undertow: Allocation of Resources Without Limits or Throttling
HIGH
A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. The assigned identifier is CVE-2026-5680.
07
n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the Send Email node, which does not enforce that its message fields are strings.
HIGH
n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the Send Email node, which does not enforce that its message fields are strings.
08
sos clean, a utility within the sos package: Improper Link Resolution Before File Access
HIGH
A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local attacker to perform arbitrary file creation or overwrite. The assigned identifier is CVE-2026-79655.
09
Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the datasource verify endpoint that allows builder-level users to supply arbitrary URLs without SSRF validation.
HIGH
Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the datasource verify endpoint that allows builder-level users to supply arbitrary URLs without SSRF validation.
10
gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability.
HIGH
gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule name validation function in gix-validate only checks the first occurrence of '..' via name.find(b".."), allowing crafted names such as 'a..b/../../../.git/' to bypass the check; additionally this validation is never invoked in production code paths.
11
Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability
MEDIUM
Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network. CVE coverage: CVE-2026-58616.
12
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Certificate Validation vulnerability.
MEDIUM
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. The assigned identifier is CVE-2026-74774.
13
RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service.
LOW
RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service. CVE coverage: CVE-2026-76888.
14
JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install().
INFO
JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install(). A missing 'await' caused the is_install_allowed coroutine to never execute, so the extension allowlist/blocklist check was not enforced for direct callers of install().

Executive assessment

Today's brief leads with CC-4838 - PaperCut Releases Emergency Security Updates for Critical Vulnerabilities in PaperCut NG/MF. All 14 selected findings retain their own technical scope, action, observed status, and evidence limits.

Finding 01 — CC-4838 - PaperCut Releases Emergency Security Updates for Critical Vulnerabilities in PaperCut NG/MF

What changed: PaperCut NG/MF flaws permit configuration modification and arbitrary Java bytecode execution; NHS England reports active exploitation and confirmed customer incidents, and advises immediate Release 2 patching plus restriction of internet-accessible server interfaces. CVE coverage: CVE-2026-81578, CVE-2026-82078.

Technical evidence: CVE-2026-82078; CVSS v4.0 9.4; weakness CWE-470; technical confidence Medium.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Not independently established here; see the analyst note below.

Analyst note: If patching is not immediately possible, remove public exposure and restrict PaperCut Application Server web interfaces to trusted IP addresses using firewall or network controls; monitor for pc-app or pc-app.exe spawning shells, missing or truncated server.log files, suspicious JDBC strings, and unexpected five-character .class, .cmd or .out files. Active exploitation is confirmed in the wild, with PaperCut reporting customer incidents and Huntress observing exploitation in two customer environments. PaperCut treats all PaperCut NG and MF versions as affected; Emergency Patch Release 2 builds are available for v24.1.9, v25.0.12 and v26.0.4. ([papercut.com](<https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/>), [huntress.com](<https://www.huntress.com/blog/papercut-actively-exploited>), [digital.nhs.uk](<https://digital.nhs.uk/cyber-alerts/2026/cc-4838>))

Action: Map CVE-2026-82078 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: affected product not structured

[Evidence source: digital.nhs.uk](<https://digital.nhs.uk/cyber-alerts/2026/cc-4838>)

Finding 02 — NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties.

What changed: NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.

Technical evidence: CVE-2026-19685; CVSS v3.1 9.8; weakness CWE-863; technical confidence Medium.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Analyst note: Until CVE-2026-19685 is fixed, use system-wide 802.1X profiles rather than per-user private profiles, or set 802-1x.system-ca-certs=yes so the compiled system CA path overrides a user-supplied ca-path; for CVE-2025-9615, Red Hat states that SELinux targeted enforcing mode mitigates the file-access attack. Red Hat's public bug record documents a reporter PoC that captured an MSCHAPv2 hash using hostapd-wpe. The upstream CVE-2026-19685 affected window is NetworkManager 1.57.1-dev through 1.58.0, and the first fixed release is 1.58.1. ([access.redhat.com](<https://access.redhat.com/security/cve/CVE-2026-19685>), [access.redhat.com](<https://access.redhat.com/security/cve/cve-2025-9615>), [bugzilla.redhat.com](<https://bugzilla.redhat.com/show_bug.cgi?id=2515042>))

Action: Map CVE-2026-19685 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-19685>)

Finding 03 — lighthouse component of Red Hat Advanced Cluster Management for Kubernetes: Insufficient Verification of Data Authenticity

What changed: A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP addresses within EndpointSlice objects.

Technical evidence: CVE-2026-66787; CVSS v3.1 8.7; weakness CWE-345; technical confidence Medium.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Not independently established here; see the analyst note below.

Analyst note: Red Hat says no mitigation is available that meets its usability, applicability or stability criteria; monitor EndpointSlice objects for IPs outside the source cluster’s allocated Pod, Service or Globalnet CIDRs, or for link-local, loopback and importing-cluster control-plane addresses. Neither in-the-wild exploitation nor a public PoC is identified by the retrieved sources: the CVE is absent from CISA’s KEV catalogue, and GitHub reports no known source code. Red Hat marks the lighthouse-agent, lighthouse-coredns, subctl and submariner-operator components in Advanced Cluster Management for Kubernetes 2 as affected, advises assuming all previous minor-stream versions are vulnerable, and states no fixed version or erratum. ([access.redhat.com](<https://access.redhat.com/security/cve/CVE-2026-66787>), [bugzilla.redhat.com](<https://bugzilla.redhat.com/show_bug.cgi?id=2507532>), [cisa.gov](<https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json>), [github.com](<https://github.com/advisories/ghsa-7fh9-j94v-w42j>))

Action: Map CVE-2026-66787 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: affected product not structured

[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-66787>)

Finding 04 — Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% CPU for an extended period in graphql-limit-count routes.

What changed: Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% CPU for an extended period in graphql-limit-count routes.

Technical evidence: CVE-2026-75005; CVSS v4.0 8.7; weakness CWE-407; technical confidence Medium.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-75005 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-75005>)

Finding 05 — Multiple vulnerabilities in PLANET GS-4210-16P2S

What changed: CVE coverage: CVE-2026-75121, CVE-2026-75122, CVE-2026-75123. The cited advisories disclose: /cgi-bin/dispatcher.cgi.

Technical evidence: CVE-2026-75121; CVSS v4.0 8.6; weakness CWE-78; technical confidence Medium.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Not independently established here; see the analyst note below.

Analyst note: Until patched, restrict the web-management interface to trusted sources and block access to the affected certificate-upload, VLAN-membership-edit and SMTP-test workflows. No confirmed in-the-wild exploitation or public PoC/exploit material is recorded for any of the three CVEs. GS-4210-16P2S V3 firmware v3.441b250922 and earlier is affected; the fixed version is v3.441b260626. ([planet.com.tw](<https://www.planet.com.tw/en/support/security-advisory/10>), [cve.blacktree.nl](<https://cve.blacktree.nl/cve/CVE-2026-75121>), [cve.blacktree.nl](<https://cve.blacktree.nl/cve/CVE-2026-75122>), [cve.blacktree.nl](<https://cve.blacktree.nl/cve/CVE-2026-75123>))

Action: Map CVE-2026-75121 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: affected product not structured

[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-75121>)

Finding 06 — Undertow: Allocation of Resources Without Limits or Throttling

What changed: A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated.

Technical evidence: CVE-2026-5680; CVSS v3.1 7.5; weakness CWE-770; technical confidence Medium.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Analyst note: If patching is not possible, configure PerMessageDeflateHandshake with a reasonable maxDecompressedBufferSize, such as 10 MB; restarting the affected application or service may be required. Debian lists Undertow 2.3.20-1 as vulnerable and the issue as unfixed, with no fixed version stated. ([access.redhat.com](<https://access.redhat.com/security/cve/CVE-2026-5680>), [security-tracker.debian.org](<https://security-tracker.debian.org/tracker/CVE-2026-5680>))

Action: Map CVE-2026-5680 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

affected product not structured

[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-5680>)

Finding 07 — n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the Send Email node, which does not enforce that its message fields are strings.

What changed: n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the Send Email node, which does not enforce that its message fields are strings. A crafted non-string value supplied from a workflow expression into the text or HTML body field can be interpreted by the underlying mail library (Nodemailer) as a file path or URL, allowing arbitrary local file disclosure and server-side request forgery (SSRF).

Technical evidence: CVE-2026-72766; CVSS v4.0 8.2; weakness CWE-843; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Not independently established here; see the analyst note below.

Analyst note: If patching is delayed, remove or restrict workflows whose Send Email nodes map untrusted webhook or external data into text or HTML fields, restrict public webhook access at the network or reverse-proxy layer, limit workflow editing to trusted users, and monitor unexpected outbound connections from n8n hosts. Italy’s ACN lists neither a public PoC nor exploitation for CVE-2026-72766. Affected releases are n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1; the respective fixed versions are 1.123.67, 2.31.5, and 2.32.1. ([github.com](<https://github.com/n8n-io/n8n/security/advisories/GHSA-2x35-3fw4-9jr4>), [cycognito.com](<https://www.cycognito.com/blog/emerging-threat-cve-2026-72766-n8n-arbitrary-file-read-and-ssrf-via-send-email-node/>), [acn.gov.it](<https://www.acn.gov.it/portale/en/w/rilevate-vulnerabilita-in-n8n-4>), [nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-72766>))

Action: Map CVE-2026-72766 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: affected product not structured

[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-72766>)

Finding 08 — sos clean, a utility within the sos package: Improper Link Resolution Before File Access

What changed: A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local attacker to perform arbitrary file creation or overwrite.

Technical evidence: CVE-2026-79655; CVSS v3.1 7.8; weakness CWE-59; technical confidence Medium.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Analyst note: Until patched, do not use sos clean to extract tar archives from untrusted or unknown sources; Red Hat states that exploitation requires an operator to process a specially crafted archive. A public reproducer is available in upstream issue #4460. Red Hat lists the sos component in RHEL 7, 8, 9 and 10 as affected and RHEL 6 as out of support scope; it lists no fixed package version or erratum, while the upstream fix PR remains open. ([access.redhat.com](<https://access.redhat.com/security/cve/CVE-2026-79655>), [github.com](<https://github.com/sosreport/sos/issues/4460>), [github.com](<https://github.com/sosreport/sos/pull/4461>))

Action: Map CVE-2026-79655 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-79655>)

Finding 09 — Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the datasource verify endpoint that allows builder-level users to supply arbitrary URLs without SSRF validation.

What changed: Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the datasource verify endpoint that allows builder-level users to supply arbitrary URLs without SSRF validation. Attackers can exploit this to leak internal CouchDB credentials by making requests to attacker-controlled servers, gaining full database access in cloud deployments.

Technical evidence: CVE-2026-82243; CVSS v4.0 8.3; weakness CWE-918; technical confidence Medium.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Not independently established here; see the analyst note below.

Analyst note: If patching is delayed, block access to /api/datasources/verify, /api/datasources/info, /api/datasources/views and /api/datasources/relationships, and restrict Budibase egress to approved destinations, including blocking internal networks and 169.254.169.254. The vendor advisory includes a public proof of concept; it does not report in-the-wild exploitation. Budibase Server versions before 3.41.3 are affected, and version 3.41.3 is fixed. ([github.com](<https://github.com/Budibase/budibase/security/advisories/GHSA-83m5-fvmg-r7xv>), [nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-82243>))

Action: Map CVE-2026-82243 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

affected product not structured

[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-82243>)

Finding 10 — gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability.

What changed: gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule name validation function in gix-validate only checks the first occurrence of '..' via name.find(b".."), allowing crafted names such as 'a..b/../../../.git/' to bypass the check; additionally this validation is never invoked in production code paths.

Technical evidence: CVE-2026-82253; CVSS v4.0 8.7; weakness CWE-22; technical confidence Medium.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Not independently established here; see the analyst note below.

Analyst note: Until patched, disable submodule open/status operations in gitoxide-based tools for untrusted repositories, or reject .gitmodules entries whose submodule names contain parent-directory traversal sequences. The vendor advisory includes a public proof of concept. Affected versions are gix <= 0.72.0 and gix-validate <= 0.10.0; fixes are available in gix 0.82.0 and gix-validate 0.11.1. ([github.com](<https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-p3hw-mv63-rf9w>), [nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-82253>))

Action: Map CVE-2026-82253 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

affected product not structured

[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-82253>)

Finding 11 — Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability

What changed: Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network. CVE coverage: CVE-2026-58616.

Technical evidence: CVE-2026-58616; CVSS v3.1 4.4; weakness CWE-362; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Not independently established here; see the analyst note below.

Analyst note: Until patching, block delivery or opening of untrusted files and access to attacker-controlled webpages, as exploitation requires a victim to open a maliciously crafted file, visit such a page and perform two tap gestures that activate autofill. Microsoft reports no exploitation, no public disclosure and no publicly available exploit code. Microsoft Edge (Chromium-based) versions from 1.0.0.0 to before 152.0.4191.53 are affected; 152.0.4191.53 contains the fix. ([msrc.microsoft.com](<https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58616>), [cve.org](<https://www.cve.org/CVERecord?id=CVE-2026-58616>))

Action: Map CVE-2026-58616 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: msrc.microsoft.com](<https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58616>)

Finding 12 — Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Certificate Validation vulnerability.

What changed: Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.

Technical evidence: CVE-2026-74774; CVSS v3.1 5.9; weakness CWE-295; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Analyst note: Dell PowerProtect One versions 20.1.0.0 and earlier are affected; Dell remediates the vulnerability in version 20.3.0.0. ([dell.com](<https://www.dell.com/support/kbdoc/en-us/000500902/dsa-2026-369-security-update-for-dell-powerprotect-one-multiple-vulnerabilities>))

Action: Map CVE-2026-74774 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

affected product not structured

[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-74774>)

Finding 13 — RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service.

What changed: RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service. CVE coverage: CVE-2026-76888.

Technical evidence: CVE-2026-76888; CVSS v3.1 3.1; weakness CWE-122; technical confidence High.

Why it matters: The cited reporting affects widely deployed technology, so exposure validation and source verification need explicit ownership.

Observed status: Not independently established here; see the analyst note below.

Analyst note: Until patched, do not open untrusted packet-capture files or capture traffic from untrusted networks with Wireshark. A self-contained public proof of concept is available in Wireshark's GitLab issue, while Wireshark says it is unaware of any exploits for this issue. Wireshark lists 4.6.0 to 4.6.7 and 4.4.0 to 4.4.17 as affected, with 4.6.8 and 4.4.18 fixed. ([access.redhat.com](<https://access.redhat.com/security/cve/cve-2026-76888>), [gitlab.com](<https://gitlab.com/wireshark/wireshark/-/work_items/21396>), [wireshark.org](<https://www.wireshark.org/security/wnpa-sec-2026-67.html>))

Action: Map CVE-2026-76888 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

affected product not structured

[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-76888>)

Finding 14 — JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install().

What changed: JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install(). A missing 'await' caused the is_install_allowed coroutine to never execute, so the extension allowlist/blocklist check was not enforced for direct callers of install().

Technical evidence: CVE-2026-73626; weakness CWE-284; technical confidence Low.

Why it matters: The cited reporting affects widely deployed technology, so exposure validation and source verification need explicit ownership.

Observed status: Not independently established here; see the analyst note below.

Analyst note: If patching is not immediately possible, disable programmatic extension installation with --LabApp.extension_manager=readonly (or c.LabApp.extension_manager = 'readonly') and monitor for RuntimeWarning: coroutine 'is_install_allowed' was never awaited. The vendor advisory and NVD record do not report exploitation in the wild or a public PoC. Affected releases are JupyterLab 4.6.0-4.6.1 and all releases through 4.5.9; fixes are 4.6.2 and 4.5.10. ([github.com](<https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-whvh-wf3x-g77j>), [nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-73626>))

Action: Map CVE-2026-73626 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

affected product not structured

[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-73626>)

cve-2025-9615cve-2026-19685cve-2026-5680cve-2026-58616cve-2026-66787cve-2026-73626cve-2026-74774cve-2026-75005cve-2026-75121cve-2026-76888

Act on this brief

Map detection coverage gaps for the techniques above, or generate Sigma rules from the named CVEs.