Check Point Research Details Critical Vulnerabilities in PaperCut, Next.js, and ServiceNow AI Platform; Reports Disruption of China-Linked Hacking Platforms
Check Point Research's latest threat intelligence report highlights several critical cybersecurity developments. Emergency fixes were released for two actively exploited vulnerabilities in PaperCut NG and MF (CVE-2026-81578, CVE-2026-82078) that can lead to unauthenticated remote code execution. Vercel addressed critical flaws in Next.js, including a Windows-specific path traversal (CVE-2026-75604) and a libheif AVIF image-processing vulnerability, both allowing unauthenticated remote code execution. ServiceNow also patched three critical vulnerabilities (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820) in its AI Platform, all rated CVSS 10.0. Additionally, U.S. authorities announced the disruption of China-linked QScan and QTRouter platforms, which targeted critical infrastructure and government networks.
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.