On August 5, 2026, researchers at Oasis Security disclosed CVE-2026-41679, a CVSS 10.0 unauthenticated remote code execution vulnerability in Paperclip, an open-source agent orchestration platform.