vulnerability Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication Attackers are chaining two PaperCut vulnerabilities – one related to dynamic class loading and another to improper access control – to execute arbitrary code on susceptible instances without authentication. The vulnerability allows for remote code execution, and threat actors have been observed exploiting these flaws t… The Hacker News · 1d ago High CVE-2026-82078CVE-2026-81578vulnerabilityremote code executionpatch
vulnerability Multiples vulnérabilités dans Oracle Java SE (19 août 2026) Multiple vulnerabilities have been discovered in Oracle Java SE, including those allowing for remote code execution, denial of service, and data confidentiality breaches. These vulnerabilities affect various Java SE vers… CERT-FR · Aug 19, 2026 High CVE-2026-60589CVE-2026-61308CVE-2026-62574javavulnerabilityoracle
threat-intel Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access Attackers exploited a SQL injection vulnerability in a public-facing web application to gain access to an Oracle database. They then leveraged a post-exploitation toolkit, ‘khunt,’ to execute commands on the underlying W… The Hacker News · Aug 6, 2026 High sql injectionkhuntpost-exploitation
vulnerability Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available A critical Remote Code Execution (RCE) vulnerability in Fastjson 1.x, a Java JSON library by Alibaba, is being actively exploited. Attackers are leveraging a type-resolution path to execute arbitrary code in Spring Boot… The Hacker News · Jul 25, 2026 High CVE-2026-16723USSGCArcejsonjava
vulnerability Multiples vulnérabilités dans Oracle Java SE (23 juillet 2026) Multiple vulnerabilities have been discovered in Oracle Java SE, potentially allowing an attacker to cause a denial of service, compromise data confidentiality, and damage data integrity. These vulnerabilities affect var… CERT-FR · Jul 23, 2026 High CVE-2026-41254CVE-2026-46917CVE-2026-46968javavulnerabilitysecurity
threat-intel New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS A new Java-based remote access trojan (RAT) called QuimaRAT, offered as a malware-as-a-service (MaaS), has been released by a threat actor. The tool is cross-platform, supporting Windows, Linux, and macOS, and is adverti… The Hacker News · Jul 6, 2026 High javaratmalware-as-a-service