Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 10 MSF:EXPLOIT-LINUX-

Paperclip AI RCE using a chain of six API calls (CVE-2026-41679)._MSF:EXPLOIT-LINUX-HTTP-PAPERCLIPAI_UNAUTH_RCE_CVE_2026_41679-

Paperclip is the operating system for your AI company. You set the goals, hire AI agents as employees, and watch them plan and execute work. Prior ...

N/A N/A METASPLOIT
HIGH 8.8 428AF504-46AA-

aetherion_428AF504-46AA-5342-B996-9B28AD7932B2

/\ | | | | | | / \ | || | | | / /\ \ | | \ / \ | \| | / \ | \ / \ | || | | | / | | | | || || | | | // \\ \|| ||\| || ||| \/ || || Aetherion Android...

N/A N/A GITHUBEXPLOIT
MEDIUM 6.7 THN:8A77AE01FE4...

China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade_THN:8A77AE01FE4F3132EEE7710ECBA05C6E

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhxJqmKAQv_I_7JkmQwoIVSx2BkRPUEb9TTNOd2RkNqTg3tcLyZszN8KiXfUUeIBSPSoxjzMAn2inE6TL791l...

N/A N/A THN
NONE 26E3C9F4-BB6B-

sbom-risk-analyzer_26E3C9F4-BB6B-5FF9-AAB9-9A2A07DAD98A

SBOM-Risk-Analyzer Exploitability-weighted vulnerability prioritization for software bills of materials. --- Abstract Severity scores CVSS describe...

N/A N/A GITHUBEXPLOIT
NONE 24C26077-B16A-

katex-xss-test_24C26077-B16A-5313-96B8-E08C7903EAD5

KaTeX render test Inline href: $\hrefjavascript:alertdocument.domainCLICK-XSS$ htmlData: $\htmlDatafoo=barx$ htmlId: $\htmlIdpwny$ htmlClass: $\htm...

N/A N/A GITHUBEXPLOIT
HIGH 8.8 CVE-2026-7387

Mattermost group syncable endpoints allow privilege escalation via scheme_admin_CVE-2026-7387

Mattermost versions 11.6.x

Mattermost Mattermost 11.6.0 CVE
MEDIUM 6.5 CVE-2026-7184

Mattermost Remote Cluster PATCH API Leaks Authentication Tokens_CVE-2026-7184

Mattermost versions 11.6.x

Mattermost Mattermost 11.6.0 CVE
HIGH 7.6 CVE-2026-6961

CVE-2026-6961: Path traversal via unsanitized FileInfo.Name in Mattermost federation sync_CVE-2026-6961

Mattermost versions 11.6.x

Mattermost Mattermost 11.6.0 CVE
MEDIUM 6.7 CVE-2026-6739

Mattermost: Delegated admins could patch protected default system roles_CVE-2026-6739

Mattermost versions 11.6.x

Mattermost Mattermost 11.6.0 CVE
MEDIUM 4.3 CVE-2026-6689

*Missing* {{invite_user}} *permission check on team creation allows unprivileged users to set open-invite and allowed-domains team settings*_CVE-2026-6689

Mattermost versions 11.6.x

Mattermost Mattermost 11.6.0 CVE