Multiple vulnerabilities in the Common Unix Printing System (CUPS) were publicly disclosed, including flaws that can be chained into remote code execution on affected Linux and Unix systems. Reporting described the issue as a critical CUPS-based RCE risk, while an oss-security disclosure listed multiple CVEs tied to the print server and related components, expanding the scope from a single bug to a broader set of weaknesses in widely deployed printing infrastructure.
Subsequent coverage said AI agents were able to identify vulnerabilities in the same Linux and Unix print server stack, underscoring how quickly offensive research techniques can surface exploitable flaws in foundational services. Because CUPS is commonly enabled across enterprise and workstation environments, the disclosures raised concern that exposed or reachable print services could provide attackers with a path to execute code remotely, making patching, service exposure review, and printer-related attack surface reduction urgent priorities.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
An oss-security posting on Openwall published consolidated details for the multiple CUPS CVEs, providing a formal public reference for the vulnerabilities and affected software. This helped document the issues for defenders and downstream vendors.
Reporting in April 2026 said AI agents were able to independently identify the previously disclosed vulnerabilities in the Linux and Unix print server software. The finding highlighted that automated AI systems could rediscover real-world exploitable flaws in widely used infrastructure software.
The disclosed CUPS-related vulnerabilities were later cataloged as multiple CVEs in the public record, formalizing the tracking of the bugs across affected components. This marked the transition from initial disclosure to standardized vulnerability identification.
Security researcher Simone Margaritelli publicly disclosed multiple vulnerabilities in the CUPS printing stack, including issues in cups-browsed and related components that could be chained for remote code execution on Linux and Unix-like systems. The disclosure established that exposed systems could be attacked remotely under certain conditions.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
theregister.com
Open sourceopenwall.com
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.