Sale of 0-day exploits: macOS LPE and several pre-auth/post-auth RCE vulnerabilities
Dark Web2026-07-15, 22:14
Sale of 0-day exploits: macOS LPE and several pre-auth/post-auth RCE vulnerabilities
For informational purposes only.
- 0-day LPE for macOS
Vulnerability type: Local Privilege Escalation
According to StatCounter, macOS accounts for approximately 15% of desktop operating systems worldwide, making it the second most popular desktop OS after Windows. According to JumpCloud SME IT Trends, on average, the IT infrastructure of small and medium-sized businesses includes about 24% macOS devices (worldwide).
- Pre-auth RCE for PaperCut
Vulnerability type: Remote Code Execution without authentication
According to the vendor's own data, PaperCut is installed in more than 70,000 organizations in 195 countries, with a total of over 100 million users – including educational institutions, corporations, and government agencies worldwide.
It is worth noting that PaperCut has already been a real, not hypothetical, target for hacker groups. In the "Current Cyber Threats: Q2 2023" report, Positive Technologies classifies CVE-2023-27350 and CVE-2023-27351 as critically dangerous – these vulnerabilities were actively exploited by ransomware groups Bl00dy and Cl0p against educational and government institutions.
- Vulnerability in F5 BIG-IP
Vulnerability type: Remote Code Execution without authentication
BIG-IP is one of the most widely used products for load balancing and WAF in the world, installed in major banks, telecommunications companies, and corporations. According to Shadowserver Foundation, after the disclosure in October 2025 of the F5 internal network breach (attributed to China), the number of BIG-IP instances detected on the internet exceeded 266,000 IP addresses – over 142,000 in the United States, and approximately 100,000 in Europe and Asia. F5 serves more than 23,000 customers worldwide, including 48 companies from the Fortune 50 list.
- Vulnerability in Adobe ColdFusion
Vulnerability type: Remote Code Execution without authentication
ColdFusion remains a niche but stable player in the enterprise web application segment on the Java stack.
Vulnerabilities
Researchers
Vendors
Products