PatchDay Alert

CVE

CVE-2026-41679

0field notes · 1digest CVSS 10.0


Daily digests

An unauthenticated attacker can get full remote code execution on any network-reachable Paperclip instance running the default 'authenticated' mode config. No credentials, no user interaction: just 6 API calls and the target's address. CVSS 10.0, and the attack is trivially automatable, so expect scanners to pick this up fast.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.