Two vulnerabilities published on April 2, 2026 — CVE-2026-34980 and CVE-2026-34990 — chain into a complete unauthenticated remote-to-root exploit against any Linux server running CUPS with a shared PostScript queue reachable on the network. Active exploitation has been confi... (Read more)