PatchDayAlert
Daily Digest · 2 min read · 5 CVEs · Issue 03 By PatchDayAlert

Paperclip CVSS 10.0 unauth RCE, plus a 9.9 in FunnelFormsPro and Froxlor

Six API calls and no credentials give attackers full control of default Paperclip installs. FunnelFormsPro (WordPress) and Froxlor both carry 9.9 code execution bugs, and Borg SPM 2007 has two 9.8s that will never be patched.

Patch now
4
Within 24h
1
This week
0
Exploited
0
WordPressCMS

Five fresh CVEs today, and the top one deserves your full attention. CVE-2026-41679 is an unauthenticated RCE in Paperclip scoring a perfect CVSS 10.0. No creds, no user interaction, just 6 API calls. It's not exploited in the wild yet, but the attack is trivially automatable, so expect scanners to light up fast. Below that: a WordPress plugin RCE, a Froxlor path traversal to code execution, and two CVSS 9.8s in a product that's been dead since 2008.


Today's CVEs

Sorted by urgency

02

CVE-2026-39440

NVD
9.9
CVSS
Patch now CRITICAL
WordPressCMS

An attacker can inject and execute arbitrary code remotely through FunnelFormsPro, the WordPress plugin. This is a code injection bug with a CVSS of 9.9. All versions through 3.8.1 are vulnerable.

Affected estate
WordPress site owners and hosts running FunnelFormsPro plugin version 3.8.1 or earlier

Evidence trail

03

CVE-2026-41228

NVD
9.9
CVSS
Patch within 24h CRITICAL

An authenticated Froxlor customer (not just admins) can set their language preference to a path traversal payload. Froxlor then blindly passes that value into a PHP 'require' call on the next request, which lets the attacker execute arbitrary PHP code as the web server user. This requires a valid customer account and the ability to upload a file to a known path, but the exploitation itself is straightforward once those conditions are met. CVSS 9.9.

Affected estate
Anyone running Froxlor server management panel versions prior to 2.3.6

Evidence trail

04

CVE-2026-6887

NVD
9.8
CVSS
Patch now CRITICAL

Borg SPM 2007 has an unauthenticated SQL injection bug that lets a remote attacker read, modify, or delete anything in the database. No credentials needed. CVSS 9.8. This product's sales ended in 2008, so there will be no patch.

Affected estate
Anyone still running Borg SPM 2007 by BorG Technology Corporation

Evidence trail

05

CVE-2026-6886

NVD
9.8
CVSS
Patch now CRITICAL

Borg SPM 2007 has an authentication bypass that lets any remote attacker log in as any user without credentials. CVSS 9.8. Combined with CVE-2026-6887 (SQL injection in the same product), this thing is completely wide open. No patch is coming since the product has been end-of-life since 2008.

Affected estate
Anyone still running Borg SPM 2007 by BorG Technology Corporation

Evidence trail


One email, every Wednesday morning.

Subscribe