Upwind Security MDR[verified]@UpwindMDRPatch
The post alerts about a critical Paperclip RCE (CVE-2026-41679) with CVSS 10.0 that requires a patch immediately.
Checkmarx Zero[verified]@CheckmarxZeroDisclosure
The post announces CVE-2026-41679, a critical unauthenticated RCE via import authorization bypass, provides a working PoC, and advises upgrading to a patched release.
White Rabbitx 🏴☠️[verified]@TheRabbitPyPatch
The post alerts that Paperclip’s default configuration allows unauthenticated RCE through a short API chain and urges an immediate patch.
Mark E. Jeftovic[verified]@jeftovicGeneral
The user simply alerts Paperclip agents about two CVE numbers without providing details or guidance.
IntegSec[verified]@integ_secDisclosure
The post announces CVE‑2026‑41679 as an unauthenticated remote code execution in Paperclip AI Orchestration and outlines response considerations, but provides no explicit patch, exploit, or evidence of active exploitation.
TECHEPAGES[verified]@techepagesDisclosure
Oasis publicly disclosed three severe Paperclip vulnerabilities, including a CVSS 10.0 unauthenticated RCE through open registration, a CVSS 8.3 cross‑tenant data leak, and a CVSS 9.6 DNS rebinding exploit that can silently deploy an agent with developer privileges.
Cybersecurity News Everyday[verified]@TweetThreatNewsDisclosure
The post announces CVE-2026-41679, detailing how remote attackers can self-register and execute code with server permissions, and also highlights related data exposure and DNS rebinding issues.
pdnuclei-bot@pdnuclei_botPoC
CVE‑2026‑41679 is a critical RCE flaw in Paperclip versions older than 2026.416.0, with a Nuclei template PoC linked; no patch, active exploitation or false‑positive claim is reported.