Find notable cyber news and cases, enriched with sources, timelines, and signals.

Paperclip security patch release for CVE-2026-41679

Security Patch Release
First reported
Last updated
Happening score
H score 45
2 unique sources, 2 articles

Summary

Hide ▲

Paperclip shipped 2026.416.0 and 0.3.1 to close three disclosed vulnerabilities that could expose data and enable unauthenticated command execution. The release split remediation across authenticated deployments and local mode, with fixes covering CVE-2026-41679 and the DNS rebinding flaw. The patch set reduced risk for both server and developer-machine execution paths.

Related Happenings

Adobe security patch release for CVE-2026-48395

Security Patch Release
H score39 First: 01.08.2026 10:12 Last: 01.08.2026 10:12 Sources 1

About this happening: Adobe shipped a security update for Adobe Bridge on 2026-08-01 that closes eight critical-rated flaws with risk of privilege escalation and arbitrary code execut...

Arista VeloCloud Orchestrator security update for CVE-2026-16812

Security Patch Release
H score55 First: 28.07.2026 01:49 Last: 28.07.2026 01:49 Sources 1

About this happening: Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...

VBulletin 6.2.2 security patch release for template-engine flaw

Security Patch Release
H score32 First: 27.07.2026 17:40 Last: 27.07.2026 17:40 Sources 1

About this happening: vBulletin released security patches for 6.2.1, 6.2.0, and 6.1.6 and shipped 6.2.2 as the fixed build, closing a template-engine remote code execution flaw on s...

Ubuntu snap-confine patch release (CVE-2026-8933)

Security Patch Release
H score34 First: 22.07.2026 13:50 Last: 22.07.2026 13:50 Sources 1

About this happening: Canonical released snapd updates through the Ubuntu Security Team to fix CVE-2026-8933, a local privilege escalation in snap-confine that can let an unpriv...

Dify security patch release for CVE-2026-41947

Security Patch Release
H score34 First: 22.06.2026 19:13 Last: 22.06.2026 19:13 Sources 1

About this happening: Dify shipped version 1.14.2 to fix most of the DifyTap vulnerabilities, closing cross-tenant paths that could expose AI chats, uploaded files, and internal API...

Timeline

  1. 05.08.2026 17:30 1 articles · 2h ago

    Oasis Security discloses three Paperclip vulnerabilities

    Initial Disclosure

    Oasis Security publishes findings on Paperclip, an open-source AI agent orchestration platform, identifying three vulnerabilities in authenticated deployments and local development mode. CVE-2026-41679 (CVSS 10.0) lets self-registration without email verification and the CLI authorization flow turn a new user into a persistent board-level API key, while other flaws expose sensitive data and enable unauthenticated command execution.

    Show sources
  2. 05.08.2026 17:30 3 articles · 2h ago

    Paperclip patches authenticated-mode and local-mode flaws

    Mitigation Patch Update

    Paperclip fixes the disclosed vulnerabilities in versions 2026.416.0 and 0.3.1. The authenticated-mode fixes require instance administrator privileges for new-company imports, and the local-mode rebinding flaw adds hostname validation so a malicious webpage cannot use DNS rebinding to reach administrator actions on a developer's machine.

    Show sources