CVE-2023-27351Active Exploitation(papercut / papercut_mf)

MEDIUMCVSS 7.5 · HIGHCISA KEV

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch papercut papercut_mf systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter class. The issue results from improper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-19226.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-05-04. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-287

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • papercut_mf
  • papercut_ng

Threat summary

  • Active exploitation appears in 11 classified signals
  • Patch or workaround signal is available
  • 13 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 11 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 7 signals
  • General: 2 classified signals
  • Peaked 3d ago at 6 mentions (2026-04-21); latest day: 1
  • 13 total mentions across 5 days

Affected systems

Vendors
Products
papercut_mfpapercut_ng

Deep dive

Activity timeline13 mentions / 5d
02356Mentions · 2026-04-20: 2Mentions · 2026-04-21: 6Mentions · 2026-04-22: 3Mentions · 2026-08-31: 1Mentions · 2026-09-05: 1Active Exploitation · 2026-04-20: 1Active Exploitation · 2026-04-21: 6Active Exploitation · 2026-04-22: 3Active Exploitation · 2026-09-05: 1Patch / Workaround · 2026-04-21: 2Patch / Workaround · 2026-04-22: 2Patch / Workaround · 2026-08-31: 1Technical Details · 2026-04-21: 5Technical Details · 2026-04-22: 204-2004-2104-2208-3109-05
Signal classification2 categories
Active Exploitation
1184.6%
General
215.4%
Referenced assets23 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-202
Active Exploitation1General1
2026-04-216
Active Exploitation6
2026-04-223
Active Exploitation3
2026-08-311
General1
2026-09-051
Active Exploitation1
Full discourse13 posts
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(4/20追加) 🛡️No.1571 CVE-2026-20122 Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability ✅概要 ・深刻度:重要 7.1 (CVSS Base) / Cisco Systems, Inc. (CNA) ・種別:特権 API の不適切な使用 (CWE-648) ・CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Cisco Catalyst SD-WAN Manager の API において、認証されたリモートの攻撃者がローカルファイルシステム上の任意のファイルを上書きできる脆弱性。悪用には影響を受けるシステムに対する API アクセス権を持つ有効な読み取り専用資格情報が必要。事前認証されていない攻撃者により、任意ファイルの上書きに加え、vmanage ユーザー権限を取得される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・Cisco Catalyst SD-WAN Manager の脆弱バージョンが稼働していること。 ・攻撃者が対象システムへネットワーク越しに到達可能であること。 ・攻撃者が API アクセス権を持つ有効な読み取り専用資格情報を有していること。 ________________________________________ ✅悪用時影響 ・ローカルファイルシステム上の任意のファイルを上書き ・vmanage ユーザー権限を取得 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:確認済み。Cisco PSIRT は、2026年3月に、CVE-2026-20128 および CVE-2026-20122 の悪用を把握したと報告。 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-20122 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems https://www.cisa.gov/news-events/directives/supplemental-direction-ed-26-03-hunt-and-hardening-guidance-cisco-sd-wan-systems 🛡️No.1572 CVE-2026-20133 Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability ✅概要 ・深刻度:重要 7.5 (CVSS Base) / NVD ・種別:情報漏えい (CWE-200) ・CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Cisco Catalyst SD-WAN Manager において、事前認証されていない攻撃者により、機密情報を摂取される恐れがある。原因はファイルシステムのアクセス制限が不十分なためで、攻撃者は対象システムのAPIにアクセスして悪用。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・Cisco Catalyst SD-WAN Manager の脆弱バージョンが稼働していること。 ・攻撃者が対象システムへネットワーク越しに到達可能であること。 ・認証は不要。 ________________________________________ ✅悪用時影響 ・該当システム上の機密情報を閲覧 ・基盤となるオペレーティングシステム上の機密情報を読み取られる ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:公開情報確認できず ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-20133 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v 🛡️No.1573 CVE-2025-2749 Kentico Xperience Path Traversal Vulnerability ✅概要 ・深刻度:重要 7.2 (CVSS Base) / VulnCheck (CNA) ・種別:パス・トラバーサル、 危険なタイプのファイルの無制限アップロード(CWE-22,CWE-434) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H (NVD) Kentico Xperience 13.0.178以前に、認証済の攻撃者によって、Staging Sync Server経由で任意の相対パスへデータをアップロード可能な脆弱性が存在。パストラバーサルと任意ファイルアップロードを経てサーバサイドで実行可能なコンテンツ配置によるリモートコード実行を行われる恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・Kentico Xperience 13.0.177以前が稼働していること。 ・Staging Serviceが有効であること。 ・Staging Serviceがユーザー名/パスワード認証で構成されていること。 ・攻撃者がStaging Sync Serverに対する有効な認証済み権限を有すること。 ________________________________________ ✅悪用時影響 ・任意ファイルアップロードにより、サーバサイドで実行可能なコンテンツを配置 ・リモートコードの実行 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-2749 https://devnet.kentico.com/download/hotfixes 🛡️No.1574 CVE-2023-27351 PaperCut NG/MF Improper Authentication Vulnerability ✅概要 ・深刻度:重要 8.2 (CVSS Base) / NVD ・種別:不適切な認証 (CWE-287) ・CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N PaperCut NG/MFのApplication Serverにおいて、事前認証されていない攻撃者により、リモートからユーザー情報を取得される恐れがある。対象となる情報に、PaperCutは、ユーザー名、氏名、メールアドレス、部署情報、カード番号に加え、内部作成ユーザーのハッシュ化パスワードを取得され得ると報告。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・PaperCut NG/MFのApplication Serverが脆弱バージョンで稼働していること。 ・攻撃者が対象サーバへネットワーク越しに到達可能であること。 ・認証は不要。 ________________________________________ ✅悪用時影響 ・認証を回避して、ユーザー名、氏名、メールアドレス、部署情報、カード番号などのユーザー情報を取得 ・内部作成ユーザーに限り、ハッシュ化されたパスワードを取得 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず (GitHub) ・ITW:未確認 (PaperCut) ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2023-27351 https://www.papercut.com/kb/Main/PO-1216-and-PO-1219 🛡️No.1575 CVE-2025-48700 Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability ✅概要 ・深刻度:注意6.1 (CVSS Base) / CISA-ADP ・種別:クロスサイトスクリプティング (CWE-79) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Zimbra Collaboration (ZCS) 8.8.15、9.0、10.0、10.1 の Classic UI において、HTMLコンテンツの不十分なサニタイズにより、ユーザーのセッション内で任意のJavaScriptを実行される恐れがある。細工されたタグ構造や属性値に含まれる @ import ディレクティブなどのスクリプト注入ベクトルが原因。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・Zimbra Collaboration (ZCS) 8.8.15、9.0、10.0、10.1 の脆弱バージョンが稼働していること。 ・攻撃者が細工した電子メールメッセージを対象ユーザーに閲覧させること。 ・Classic UI で細工された電子メールメッセージが閲覧されること。 ・追加の利用者操作は不要。 ________________________________________ ✅悪用時影響 ・ユーザーのセッション内で任意のJavaScriptを実行 ・機微情報への不正アクセスにつながる ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-48700 https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories 🛡️No.1576 CVE-2026-20128 Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability ✅概要 ・深刻度:重要 7.5 (CVSS Base) / Cisco Systems, Inc. (CNA) ・種別:復元可能な形式でのパスワード保存 (CWE-257) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Cisco Catalyst SD-WAN Manager の Data Collection Agent(DCA)機能において、事前認証されていない攻撃者により、リモートから DCA ユーザー権限を取得される恐れがある。影響を受けるシステム上に DCA ユーザーの認証情報ファイルが存在することで、細工された HTTP 要求により当該ファイルを読み取られる可能性。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・Cisco Catalyst SD-WAN Manager の脆弱バージョンが稼働していること。 ・攻撃者が対象システムへネットワーク越しに到達可能であること。 ・認証は不要。 ________________________________________ ✅悪用時影響 ・DCA パスワードを含むファイルを読み取られる ・別の影響を受けるシステムへアクセスされ、DCA ユーザー権限を取得される ・機密情報へアクセスされる ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み。Cisco PSIRT は、2026年3月に、CVE-2026-20128 および CVE-2026-20122 の悪用を把握したと報告。 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-20128 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v   🛡️No.1577 CVE-2025-32975 Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability ✅概要 ・深刻度:緊急 10.0 (CVSS Base) / CISA-ADP ・種別:不適切な認証 (CWE-287) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Quest KACE Systems Management Appliance (SMA) には、事前認証されていない攻撃者により、正規ユーザーになりすませる認証回避の脆弱性が存在。SSO認証処理に起因し他脆弱性で、完全な管理者乗っ取りをされる恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・Quest KACE Systems Management Appliance (SMA) の脆弱バージョンが稼働していること。 ・対象機器がネットワーク越しに到達可能であること。 ・認証は不要。 ________________________________________ ✅悪用時影響 ・正当な認証情報なしに正規ユーザーになりすまされる ・完全な管理者権限を取得される ・アプライアンスを全面的に掌握される ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:確認済み。Arctic Wolf は、2026年3月9日の週から、インターネット公開された未パッチのKACE SMAに対するCVE-2025-32975悪用の可能性がある不正活動を顧客環境で観測したと報告。 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-32975 https://support.quest.com/kb/4379499/quest-response-to-kace-sma-vulnerabilities-cve-2025-32975-cve-2025-32976-cve-2025-32977-cve-2025-32978 🛡️No.1578 CVE-2024-27199 JetBrains TeamCity Relative Path Traversal Vulnerability ✅概要 ・深刻度:重要 7.3 (CVSS Base) / JetBrains s.r.o. (CNA) (NVD) ・種別:相対パストラバーサル (CWE-23) (NVD) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L (NVD) JetBrains TeamCity 2023.11.4未満に相対パストラバーサルの脆弱性が存在。事前認証されていない攻撃者により、HTTP(S)経由で認証チェックを回避し、TeamCityサーバの管理権限を取得される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・TeamCity On-Premises 2023.11.3以前が稼働していること。 ・攻撃者が対象のTeamCityサーバへHTTP(S)アクセス可能であること。 ・認証は不要。 ________________________________________ ✅悪用時影響 ・認証チェックを回避され、限定的な管理者アクションを実行される ・TeamCityサーバの管理権限を取得される ・機密情報の取得、設定情報の改変、サービス影響につながる ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開済み (NVD) ・ITW:確認済み。トレンドマイクロは、CVE-2024-27198およびCVE-2024-27199を悪用しようとする攻撃者活動を確認したと報告。 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2024-27199 https://blog.jetbrains.com/teamcity/2024/03/additional-critical-security-issues-affecting-teamcity-on-premises-cve-2024-27198-and-cve-2024-27199-update-to-2023-11-4-now/ https://www.cisa.gov/news-events/alerts/2026/04/20/cisa-adds-eight-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    The post catalogs multiple CVEs, confirms active exploitation for several of them as reported by Cisco PSIRT and Arctic Wolf, and supplies links to vendor advisories and patch guidance, underscoring the immediacy of the threat landscape.

    000415.9K
    43.6K followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Active Exploitation

    CISAが既知の悪用された脆弱性8件をカタログに追加 https://www.cisa.gov/news-events/alerts/2026/04/20/cisa-adds-eight-known-exploited-vulnerabilities-catalog CVE-2023-27351 PaperCut NG/MF 認証エラーの脆弱性 CVE-2024-27199 JetBrains TeamCity 相対パストラバーサル脆弱性 CVE-2025-2749 Kentico Xperienceのパストラバーサル脆弱性

    Post summary

    CISA announces that eight known exploited vulnerabilities, including CVE-2023‑27351 (PaperCut NG/MF authentication error), CVE-2024‑27199 (JetBrains TeamCity relative path traversal), and CVE-2025‑2749 (Kentico Xperience path traversal), have been added to its catalog, indicating active exploitation in the wild.

    20000304
    40 followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISAが既知の悪用された脆弱性8件をカタログに追加 CISA Adds Eight Known Exploited Vulnerabilities to Catalog #CISA (Apr 20) CVE-2023-27351 PaperCut NG/MF 認証エラーの脆弱性 CVE-2024-27199 JetBrains TeamCity 相対パストラバーサル脆弱性 CVE-2025-2749 Kentico Xperienceのパストラバーサル脆弱性 CVE-2025-32975 Quest KACEシステム管理アプライアンス(SMA)の認証エラーの脆弱性 CVE-2025-48700 Synacor Zimbra Collaboration Suite (ZCS) のクロスサイトスクリプティング脆弱性 CVE-2026-20122 Cisco Catalyst SD-WAN Managerにおける特権APIの不適切な使用に関する脆弱性 CVE-2026-20128 Cisco Catalyst SD-WAN Managerにおける、パスワードを回復可能な形式で保存する脆弱性 CVE-2026-20133 Cisco Catalyst SD-WAN Managerにおける機密情報が不正アクセス者に漏洩する脆弱性 https://www.cisa.gov/news-events/alerts/2026/04/20/cisa-adds-eight-known-exploited-vulnerabilities-catalog

    Post summary

    CISA has announced adding eight CVEs that are documented as being actively exploited in the wild, but no PoC, exploit code, patches, or false‑positive claims are provided in the brief.

    00010559
    4.8K followersView on X
  • kokumօtօ@__kokumoto
    General

    CVE-2023-27351 PaperCut NG/MF CVE-2024-27199 JetBrains TeamCity CVE-2025-2749 Kentico Xperience CVE-2025-32975 Quest KACE Systems Management Appliance (SMA) CVE-2025-48700 Zimbra Collaboration Suite (ZCS) CVE-2026-20122/CVE-2026-20128/CVE-2026-20133 Cisco Catalyst SD-WAN Manager

    Post summary

    The text provides a simple list of CVE identifiers and associated products without any accompanying technical detail, exploitation information, or mitigation steps.

    10000812
    7.4K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers chained CVE-2023-27350 and CVE-2023-27351 to compromise PaperCut servers at educational institutions, then deployed registry harvesting tools to extract Windows credentials. Campaign demonstrates how third-party application compromises enable credential theft across academic networks. #CloudSecurity 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/papercut-cve-2026-81578-82078-credential-theft-education-sector-2026

    Post summary

    The post reports attackers chaining CVE-2023-27350 and CVE-2023-27351 to compromise PaperCut servers in educational institutions, then harvesting credentials via registry tools—demonstrating active exploitation, with no patch or technical details provided.

    0000074
    2.0K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    General

    TRC analysis shows attackers chaining two PaperCut vulnerabilities (CVE-2023-27350, CVE-2023-27351) to gain initial access then pivot across network segments. Runtime segmentation limits blast radius when print management systems become pivot points for lateral movement. #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/cisa-kev-papercut-vulnerabilities-cve-2026-81578-82078-august-2026

    Post summary

    The post describes a TRC analysis of attackers chaining two PaperCut CVEs, highlights runtime segmentation as a mitigation, but provides no evidence of active exploitation, patches, or PoC.

    0000063
    2.0K followersView on X
  • Technoholic.me@technoholic_me
    Active Exploitation

    CISA added 8 new vulnerabilities to KEV, including 3 in Cisco Catalyst SD-WAN Manager, and PaperCut CVE-2023-27351 (score 8.2), with active exploitation reported. Stay protected! https://thehackernews.com/2026/04/cisa-adds-8-exploited-flaws-to-kev-sets.html

    Post summary

    CISA added eight new vulnerabilities to KEV, including PaperCut CVE-2023-27351 with a CVSS score of 8.2, and reports active exploitation, though no PoC, exploit code, patch, or additional technical details are provided.

    00000117
    159 followersView on X
  • Nicolas Coolman@NicolasCoolman
    Active Exploitation

    🚨 Alerte CISA : Exploitation Active de la Vulnérabilité PaperCut CVE-2023-27351 – Correctif Urgent Requis avant le 4 Mai 2026 (zoneantimalware..com) https://t.co/bmYTB8wNnd

    Post summary

    The tweet alerts that PaperCut CVE-2023-27351 is currently being exploited in the wild and urges users to apply the urgent patch before the specified date.

    00000126
    85 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2023-27351 in PaperCut servers to bypass authentication, then escalating privileges and moving laterally across networks. Runtime segmentation can help contain these post-compromise attack chains. #Vulnerability 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/cisa-adds-8-exploited-flaws-to-kev-sets-april-may-2026-federal-deadlines

    Post summary

    The post confirms CVE-2023-27351 is actively exploited against PaperCut servers, enabling authentication bypass, privilege escalation and lateral movement, while suggesting runtime segmentation as a containment mitigation.

    0000090
    1.9K followersView on X
  • CCB Alert@CCBalert
    Active Exploitation

    Warning: Authentication bypass vulnerability in #PaperCut NG . #CVE-2023-27351 CVSS: 7.5. This vulnerability is #actively exploited and now on the #KEV list! #Patch #Patch #Patch

    Post summary

    PaperCut NG’s CVE-2023-27351 is an authentication bypass flaw (CVSS 7.5) that is actively exploited and listed on the KEV; patches are available.

    00000156
    7.2K followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Active Exploitation

    🔒 #CyberSecurity CVE-2023-27351: PaperCut RCE and Cisco SD-WAN Flaws Added to CISA KEV "CISA flags CVE-2023-27351 in PaperCut as actively exploited. Federal agencies…" 🔗 https://securityarsenal.com/blog/cve-2023-27351-papercut-rce-and-cisco-sd-wan-flaws-added-to-cisa-kev #CyberSecurity #ThreatIntel #penetrationtesting #redteam #offensivesecurity

    Post summary

    The tweet announces that CISA has added CVE-2023-27351 to the KEV list, marking it as actively exploited in PaperCut. No PoC, exploit code, or mitigation instructions are provided.

    0000057
    11 followersView on X
  • ScyScan@ScyScan
    Active Exploitation

    Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2023-27351 #PaperCut #NG/MF Improper Authentication Vulnerability https://www.scyscan.com/cve-2023-27351/papercut-ngmf-improper-authentication-vulnerability/

    Post summary

    The post presents CVE‑2023‑27351 as a known exploited, improper‑authentication flaw, yet it offers no PoC, exploit code, patch, or false‑positive detail.

    0000048
    61 followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    🚨 BREAKING: CISA has added eight new vulnerabilities to its Known Exploited Vulnerabilities Catalog, including CVE-2023-27351 and CVE-2024-27199, due to active exploitation. Stay vigilant and update systems promptly. #NerdieNews #CyberSecurity #BreakingNews #InfoSec #Cisco https://t.co/iWQb6A7Sri

    Post summary

    CISA confirms that CVE-2023-27351 and CVE-2024-27199 are being actively exploited, urging timely system updates.

    0000061
    55 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apppapercutpapercut_mf---
Apppapercutpapercut_ng---

Explore more