A critical vulnerability in Apache Tomcat, identified as CVE-2025-48989, allows remote, unauthenticated attackers to degrade HTTP/2 service performance, potentially leading to a denial-of-service (DoS) condition. The flaw, caused by improper resource shutdown or release, affects Tomcat versions 11.0.0-M1 through 11.0.9, 10.1.0-M1 through 10.1.43, and 9.0.0.M1 through 9.0.107, with patches available in subsequent releases. F5 has confirmed that while some of its products use vulnerable Tomcat versions, not all are affected due to lack of HTTP/2 support. Organizations are advised to upgrade to the fixed versions to mitigate risk.
Separately, a use-after-free vulnerability in CUPS (CVE-2023-34241) impacts versions from 2.0.0 up to but not including 2.4.6, potentially allowing attackers to corrupt data, cause DoS, or execute unauthorized code. The issue arises from improper memory handling during logging operations after a connection is closed. Additionally, research has highlighted a severe vulnerability (CVE-2024-12649, CVSS 9.8) in Canon printers, where attackers can execute malicious code simply by sending a specially crafted XPS file containing a malicious TrueType Font (TTF). These vulnerabilities underscore the increasing focus of attackers on networked devices like printers and print services, which often lack robust endpoint protection and can serve as entry points into organizational networks.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
F5 published product advisory K000157836 regarding CUPS vulnerability CVE-2023-34241. No further technical details were provided in the reference content.
F5 published product advisory K000157302 regarding Apache Tomcat vulnerability CVE-2025-48989. No further technical details were provided in the reference content.
Canon recommended applying firmware updates and limiting printer internet exposure in response to CVE-2024-12649. Additional defensive guidance included network segmentation, disabling unused printer services, and using strong unique administrator passwords.
At Security Analyst Summit 2025, researcher Peter Geissler publicly described how a crafted XPS file containing a malicious TrueType font can trigger a stack buffer overflow and code execution on vulnerable Canon printers. The presentation highlighted that exploitation can occur even when printers are not internet-exposed if a user prints a malicious document from inside the network.
A critical Canon printer vulnerability, CVE-2024-12649, was identified affecting DryOS-based devices. The flaw involves insecure stack handling in the font-processing virtual machine and can lead to remote code execution via a crafted XPS document with a malicious TrueType font.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.