Rapid responses
runZero’s Rapid Response program provides immediate detection and notification of emerging threats. Older entries are migrated to standalone queries or templates.
PaperCut Software PaperCut NG and PaperCut MF are server-based software applications that track, manage, and secure network printing, with PaperCut MF additionally integrating directly into multifunction printer hardware to control copying, scanning, and faxing.
Certain versions of PaperCut NG and PaperCut MF are affected by undisclosed vulnerabilities. PaperCut Software indicated that its investigation is ongoing; while technical details remain non-public, initial findings suggest the flaw is remotely exploitable.
PaperCut Software has confirmed that the vulnerability is being actively exploited in the wild.
The following versions are affected:
- PaperCut NG & MF: All versions prior to the Emergency Patch Release
vendor:="PaperCut Software" AND (product:="PaperCut MF" OR product:="PaperCut NG") AND source:runzero
Ubiquiti UniFi OS is a Linux-based operating system and application server platform deployed across dedicated Cloud Gateways, hardware consoles, and self-hosted servers to manage and run individual network and security applications.
Certain versions of UniFi OS are affected by multiple vulnerabilities:
-
CVE-2026-77534: An improper access control vulnerability that allows a remote, low-privileged attacker to escalate privileges.
-
CVE-2026-77536: An improper access control vulnerability that allows a remote, low-privileged attacker to escalate privileges.
-
CVE-2026-77539: An improper input validation vulnerability that allows a remote, high-privileged attacker to execute arbitrary commands on the host device.
-
CVE-2026-77540: An improper input validation vulnerability that allows a remote, high-privileged attacker to execute arbitrary commands on the host device.
-
CVE-2026-77545: An active debug code vulnerability that allows a remote, low-privileged attacker under specific conditions to escalate privileges.
-
CVE-2026-77549: An improper neutralization of CRLF sequences vulnerability that allows a remote, unauthenticated attacker under specific conditions to bypass authentication.
-
CVE-2026-77550: An improper neutralization of CRLF sequences vulnerability that allows a remote, unauthenticated attacker under specific conditions to bypass authentication.
The following versions are affected:
- UniFi OS Server: Versions 5.1.21 and prior
- Cloud Keys, Network Video Recorders, Enterprise Network Video Recorders, Enterprise Network Attached Storage, Network Attached Storage, Dream Machines, Enterprise Firewall Core, Dream Routers, Enterprise Fortress Gateway, Cloud Gateways, Dream Wall, and Express 7: Versions 5.1.26 and prior
os:="Ubiquiti UniFi OS"
Ubiquiti UniFi Protect is a network video management application that operates on specialized local hardware to manage camera configurations, video recordings, and event-based analytics for an integrated surveillance system.
Multiple improper input validation vulnerabilities in certain versions of the UniFi Protect Application may allow remote attackers to execute arbitrary commands on the underlying host device:
- CVE-2026-77533: Exploitable by a low-privileged attacker.
- CVE-2026-77537: Exploitable by an unauthenticated attacker.
- CVE-2026-77548: Exploitable by a low-privileged attacker.
The following versions are affected:
- UniFi Protect Application: Versions 7.1.87 and prior
hw:="Ubiquiti _NVR%"
Zimbra Collaboration is a collaboration software suite, which provides users with a quickly deployable E-mail and webmail server.
Collaboration can be configured with SNMP alerting natively, and prior to versions 10.1.20 the server was vulnerable to unauthenticated command injection via the SNMP trap handling if the feature is enabled and used. A crafted SMTP message sent to the Zimbra server can reach the vulnerable logic of the SNMP notification handler and an attacker can achieve RCE unauthenticated.
There is evidence that these vulnerabilities are being actively exploited in the wild and the vulnerability has been added to the CISA KEV list August 21th, 2026.
The following versions are affected:
- Zimbra Collaboration: Versions prior to 10.1.20
vendor:=Zimbra AND product:=Collaboration AND _asset.protocol:smtp
Red Hat Keycloak is an open-source enterprise software platform that provides centralized authentication, single sign-on (SSO), and access management for web applications and microservices.
Certain versions of Keycloak are affected by a vulnerability in the reset-credentials authentication flow within the
keycloak-services component caused by improper state validation. Successful exploitation allows a remote,
unauthenticated attacker to gain full access to any user account by bypassing the email verification step during the
password recovery process.
The following versions are affected:
- Red Hat build of Keycloak 26.4: Versions prior to 26.4.15-1 (
rhbk/keycloak-operator-bundle) and 26.4-23 (rhbk/keycloak-rhel9,rhbk/keycloak-rhel9-operator) - Red Hat build of Keycloak 26.6: Versions prior to 26.6.6-1 (
rhbk/keycloak-operator-bundle) and 26.6-12 (rhbk/keycloak-rhel9,rhbk/keycloak-rhel9-operator)
vendor:="Red Hat" AND product:="Keycloak"
GitLab Community Edition (CE) provides core Git repository management and CI/CD pipelines, while Enterprise Edition (EE) includes all CE capabilities alongside advanced security, compliance, and enterprise scalability features.
Multiple vulnerabilities affect certain self-managed versions of GitLab CE and EE:
-
CVE-2026-19478: A code injection vulnerability via a GraphQL directive. Successful exploitation allows a remote, unauthenticated attacker to modify or delete public projects and user data.
-
CVE-2026-19650: A Cross-Site Request Forgery (CSRF) vulnerability in the GraphQL multiplex query handler. Improper request validation allows a remote, unauthenticated attacker to execute arbitrary GraphQL mutations via standard
GETrequests.
The following versions are affected:
- GitLab CE & EE 18.x: Versions 18.2 through 18.11.10
- GitLab CE & EE 19.0.x: Versions 19.0 through 19.0.7
- GitLab CE & EE 19.1.x: Versions 19.1 through 19.1.5
- GitLab CE & EE 19.2.x: Versions 19.2 through 19.2.3
vendor:="GitLab" AND product:="GitLab"
Citrix NetScaler ADC (formerly Citrix ADC) is an application delivery controller that provides load balancing, traffic optimization, and web application security, while Citrix NetScaler Gateway (formerly Citrix Gateway) is a secure remote access solution that handles user authentication and encrypted connections to internal applications and virtual desktops.
Certain versions of customer-managed NetScaler ADC and NetScaler Gateway are affected by multiple vulnerabilities:
-
CVE-2026-19489: A memory overflow vulnerability leading to unpredictable behavior or a denial-of-service (DoS) condition when the Session Initiation Protocol (SIP) Application Layer Gateway (ALG) is enabled on a Large Scale NAT (LSN) group configuration. Successful exploitation allows a remote, unauthenticated attacker to cause a DoS and potentially achieve remote code execution (RCE), though RCE has not been confirmed.
-
CVE-2026-19490: An authentication bypass vulnerability using an alternate path in appliances configured as a gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an Authentication, Authorization, and Auditing (AAA) virtual server. Affected instances are subject to version-specific prerequisites; please review the vendor advisory for specific details. Successful exploitation allows a remote, unauthenticated attacker to gain unauthorized access to the system.
The following versions are affected:
- NetScaler ADC and NetScaler Gateway 14.1: Versions prior to 14.1-73.32
- NetScaler ADC and NetScaler Gateway 13.1: Versions prior to 13.1-63.21
- NetScaler ADC 14.1-FIPS: Versions prior to 14.1-73.32 FIPS
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP: Versions prior to 13.1-37.277
hw:="Citrix NetScaler%" OR hw:="Citrix ADC%" OR os:="Citrix NetScaler%" OR os:="Citrix ADC"
Apple macOS Screen Sharing is a built-in utility that allows users to remotely view and control another Mac over a local network or the Internet using the VNC protocol.
Certain versions of macOS Screen Sharing are affected by an authentication bypass vulnerability, due to underlying state management issues. Successful exploitation allows a remote, unauthenticated attacker to bypass credential checks and gain unauthorized access to the system.
There is evidence that CVE-2026-65400 is being actively exploited in the wild, prompting its addition to the CISA Known Exploited Vulnerabilities (KEV) catalog on August 18, 2026.
The following versions are affected:
- macOS Tahoe 26.x: Versions prior to 26.6.1
- macOS Sequoia 15.x: Versions prior to 15.7.9
- macOS Sonoma 14.x: Versions prior to 14.8.9
os:="Apple macOS%" AND port:5900 AND protocol:vnc
Metabase is an open-source business intelligence tool used by organizations to visualize data and share insights through interactive dashboards. It is typically deployed in corporate environments to provide a graphical interface for querying databases such as PostgreSQL or MySQL.
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the /reset_password database
endpoint and gain administrator access to the connected Metabase instance.
There is evidence that these vulnerabilities are being actively exploited in the wild and the vulnerability has been added to the CISA KEV list August 11th, 2026.
The following versions are affected:
- Metabase: Versions x.63.0 through x.63.4
- Metabase: Versions x.62.0 through x.62.8
- Metabase: Versions x.61.0 through x.61.10
- Metabase: Versions x.60.0 through x.60.16
- Metabase: Versions x.59.0 through x.59.20
- Metabase: Versions x.58.0 through x.58.23
vendor:=Metabase AND product:=Metabase
runZero has identified multiple vulnerabilities in a large subset of major baseboard management controllers (BMCs) that can lead to device compromise or segmentation breakdowns. Details of individual vulnerabilities will be published as the disclosure process completes.
BMCs are embedded into every modern enterprise server. These devices run their own OS, have their own network interfaces, and are network-reachable even when the server is powered off. The devices speak a protocol called IPMI that was thoroughly trashed by Dan Farmer’s ground-breaking research in 2013. Since Farmer’s original research into Cipher Zero authentication bypass and RAKP password hash disclosure, dozens of new vulnerabilities have been identified in these devices, but none of this research revisits the IPMI protocol itself.
High level details of our findings will be presented at Black Hat 2026 & DEF CON 34.
(protocol:ipmi OR type:=BMC) AND ( hw:=OpenBMC OR hw:="Super Micro IPMI" OR hw:="HP% iLO%" OR hw:="Dell iDRAC%" OR hw:="AMI MegaRAC" OR (hw:="Raritan%" AND type:="Power Device") OR hw:="H3C HDM" OR hw:="Fujitsu%")
Each Rapid Response includes a query to find matching assets, a trigger to analyze all inventories for exposure, and a corresponding blog post with the details of the issue. This program focuses on helping customers mitigate exposures before compromise.