Pegasus delivered device-wide surveillance; coding-agent remediation remains partial, and PaperCut says Release 2 must be replaced by Release 3.
The demonstrated access was tied to a Pegasus operator.
Apple iPhones running an iOS build vulnerable to the undisclosed iMessage chain
Zero-click installation of Pegasus with access to private data, encrypted messages, microphone and camera
Forensic evidence confirmed that a no-interaction iMessage chain installed Pegasus, which could access files, private and encrypted messages, the microphone, and the camera.
The operator only had to address the target through iMessage. Exploit content arrived without an open or acknowledgment, executed the undisclosed chain, and installed Pegasus.
Once installed, Pegasus could reach files, private and encrypted messages, the microphone, and the camera.
Signing-status findings reflect the pages checked on 2026-09-02; the undisclosed affected-device and version range limits the final capability conclusion.
The malicious .git configuration must survive delivery; an ordinary clone does not carry it.
Claude Code, Goose, Hermes Agent, Qwen Code, Grok Build, Codex and Cursor command-line AI coding agents on developer workstations.
Pre-trust arbitrary code execution as the developer
The changed boundary is execution before the agent asks for trust, authentication, or command approval across multiple products.
The attacker prepares a directory whose .git/config selects a helper through core.fsmonitor or another command-bearing Git setting. The directory must arrive through an archive, shared drive, synchronization folder, or removable media with both the local configuration and helper intact.
When an affected agent gathers context with git status, git diff, or an equivalent command, Git executes the selected helper outside the sandbox as the developer. Manifold’s September 1 retest found current unpatched paths still exposed, so received repositories should be treated as executable content before an agent opens them.
Answers assess the cross-product finding as a whole; vendor-specific evidence is identified in each reason.
Unauthenticated HTTP access can cross administrative configuration into JDBC-backed operating-system execution.
PaperCut NG and PaperCut MF print-management application servers on Windows, Linux and macOS.
Unauthenticated configuration takeover followed by code execution in the PaperCut server process despite installation of an earlier emergency patch
Release 2 was not merely superseded: PaperCut says Release 3 closes additional attack vectors observed in the wild and instructs Release 2 users to replace it.
A direct-component request can show a public page while invoking an administrative ConfigEditor or UserList component. Because authorization follows the displayed page, an unauthenticated requester can alter external-user configuration and steer JDBC class loading or SQL execution into an operating-system process.
The public Metasploit test reached LocalSystem on Windows and the PaperCut service account on Linux. Release 2 users are not fully protected; Release 3 is the replacement.
Assessment current to the cited sources as read on 2026-09-02; Release 3 had not yet completed PaperCut's normal QA and release process.
SonicWall SMA 1000 Series enterprise remote-access VPN appliances, including physical and virtual deployments.
An Internet user can reach the Work Place portal without credentials. Public analysis shows how the SSRF and alternate access path could reach the separate operating-system command-injection flaw.
SonicWall confirms exploitation of both vulnerabilities and identifies fixed releases. We do not know whether observed intrusions completed this exact chain or which UID would run the command.
vm2, an in-process Node.js library used by plugin systems, code runners, CI tools and AI applications to execute untrusted JavaScript.
The remaining path requires NodeVM with require.external enabled and an allowed root containing a helper loaded in the host context. Importing a helper that exposes child_process or equivalent authority returns a capability the outer sandbox does not constrain.
GitLab validated that alternate path on 3.11.7. The configuration is narrower than a default sandbox escape, but the upstream README still presents require.external with root './' and warns against relying on vm2 alone.
JFrog Artifactory Self-Managed, an enterprise repository for software packages, binaries, containers, and AI models.
On affected self-managed installations, the default phantom or blank join-key condition permits a forged cluster JWT, a service administrator token, and then a platform administrator token. That identity can reach users, credentials, federated topology, and stored artifacts.
An independent test created an administrator token on a vulnerable build and saw the request rejected on a fixed one.
Virtualizor, Linux-based virtualization and hosting-control software installed on hypervisor-management servers.
The attacker announced a more-specific route, diverted vendor traffic, and obtained a valid TLS certificate while certificate validation followed the diversion. Virtualizor then accepted a modified update package without independently checking a package signature.
The malicious update executed as root and established persistence through an SSH key, an unauthorized account, and a systemd service.
Mozilla Thunderbird, a desktop email and calendar client on Windows, macOS and Linux.
A crafted MIME body can enter the affected error path. Public material does not say whether background synchronization is enough, whether preview or opening is required, or whether the stale value controls a security-sensitive operation.
Mozilla shipped fixes across release and ESR channels on September 1. Until trigger timing and the stale value’s consumer are known, this is a memory-safety primitive rather than an established receipt-only compromise.
libheif, the HEIF/AVIF decoding library used by desktop and server image-processing applications, including ImageMagick-backed WordPress media processing.
WordPress automatically passed the uploaded image through Imagick, ImageMagick, and libheif. Unequal component bit depths then made the mixed-interleave decoder write two-byte samples into a one-byte allocation, producing a controlled heap overwrite.
The researcher demonstrated file disclosure and command execution on WordPress 7.1. The path depends on a specific codec stack, and libheif 1.23.3 followed the 1.23.2 security release with a fix one week later.
No new boot-chain capability was confirmed; incomplete access to the cited U-Boot fix history prevents full closure.
PaperCut, Nexus Silicon One, and Cleo Harmony each crossed an authentication or role boundary into service-account or root execution.
fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place. A CVE is an input, not an event. When nothing qualifies, the brief says so. Every morning.