🛡️ Cybersecurity Vulnerability Watch
Patch PaperCut NG and MF print servers now. Attackers are actively chaining two PaperCut flaws to gain unauthenticated remote control over PaperCut's trusted configuration and execute arbitrary Java…
🛡️ Cybersecurity Vulnerability Watch
Week of: 2026-08-23 to 2026-08-29 Reporting window: Most recently completed Sunday–Saturday (excludes the in-progress week).
1. Top Action Item
Patch PaperCut NG and MF print servers now. Attackers are actively chaining two PaperCut flaws to gain unauthenticated remote control over PaperCut's trusted configuration and execute arbitrary Java code, and the vendor has released a fresh emergency fix with additional hardening. Anyone running PaperCut NG or MF should apply that emergency update immediately, then verify no unauthorized accounts, scripts, or configuration changes were left behind. Also confirm your ownCloud instance is patched against CVE-2023-49105, which CISA added to its Known Exploited Vulnerabilities catalog this week after it was used to steal data from a Philippine nuclear research body.
2. Exploited This Week
PaperCut NG / MF — actively exploited chained flaws (CVE: see source)
- Source: The Hacker News
- Link: The Hacker News
- Severity: Unauthenticated remote code execution; score not stated (see source)
- What's happening: Malicious actors are exploiting a newly patched PaperCut flaw, chained with a second bug, to take unauthenticated control of PaperCut's trusted configuration and execute arbitrary Java code.
- Fix: Apply the vendor's fresh emergency fix and hardening update; treat any previously exposed instance as potentially compromised.
ownCloud — CVE-2023-49105
- Source: The Hacker News
- Link: The Hacker News
- Severity: Critical (CVSS 9.8)
- What's happening: CISA added this critical ownCloud flaw to its Known Exploited Vulnerabilities catalog following reports that a Chinese-speaking threat actor exploited it against a nuclear research body in the Philippines, stealing records.
- Fix: Upgrade ownCloud to the patched release that remediates CVE-2023-49105 (see source for the exact version).
Cosmos EVM module — GHSA-7g4w-cg88-2cq2
- Source: The Hacker News
- Link: The Hacker News
- Severity: Critical (vendor rating; advisory published without a CVE or CVSS score)
- What's happening: A critical balance-handling flaw in the shared Cosmos EVM module was exploited between August 20 and 25 to drain funds from six blockchains, after Cosmos Labs knew every chain running the module was exposed.
- Fix: Upgrade affected chains to the corrected Cosmos EVM module release (see source for affected version ranges).
3. Critical Patch Roundup
ServiceNow AI Platform — three CVSS 10.0 flaws (CVE: see source)
- Source: The Hacker News
- Link: The Hacker News
- Severity: Critical (three of four flaws rated CVSS 10.0)
- What's happening: The disclosed flaws can, in certain circumstances, let unauthenticated attackers execute code and run SQL against the ServiceNow AI Platform.
- Fix: ServiceNow has already updated hosted instances; partners and self-hosted customers must apply the update ServiceNow provided.
cPanel & WHM — CVE-2026-65643
- Source: The Hacker News
- Link: The Hacker News
- Severity: Critical (vendor rating)
- What's happening: A flaw in domain parking and addon domain functionality affects all supported cPanel & WHM versions and could let a single hosting customer execute code as root on the whole server.
- Fix: Apply the cPanel/WHM patch released this week (see source for the exact version).
WordPress plugins/themes: WPMU DEV Dashboard, Avada, TranslatePress, Pods, GiveWP — CVE-2026-76581 and related critical flaws
- Source: The Hacker News
- Link: The Hacker News
- Severity: Critical (CVE-2026-76581 rated CVSS 9.8; additional flaws disclosed by Wordfence and Patchstack, see source)
- What's happening: Multiple critical flaws in widely used WordPress plugins and the Avada theme can lead to authentication bypass, account takeover, and arbitrary code execution.
- Fix: Update all five products to their patched releases as soon as they are available.
ZBT routers (Shenzhen Zhibotong) — CVE-2026-74232, CVE-2026-74233
- Source: The Hacker News
- Link: The Hacker News
- Severity: Unauthenticated root access; no CVSS published (see source)
- What's happening: Two factory implants, named SPEAKINGSTONE and DARKLANTERN, ship in firmware for ZBT routers sold worldwide as white-label products and give unauthenticated remote attackers root command execution.
- Fix: No software patch is disclosed — identify and replace affected ZBT/white-label devices.
Microsoft Edge (Chromium-based), Edge for iOS, and Copilot Chat — multiple CVEs
- Source: Microsoft MSRC
- Link: Microsoft MSRC — CVE-2026-72984 Edge (Chromium-based) RCE
- Severity: See source (includes remote code execution, spoofing, and information disclosure)
- What's happening: This week's Edge/Chromium update set includes RCE bugs (e.g., use-after-free and type confusion, CVE-2026-72984, CVE-2026-66798, CVE-2026-70341), a WebRTC buffer overflow assigned by Chrome (CVE-2026-78891), plus spoofing and information-disclosure issues in Edge for iOS (CVE-2026-70331) and Copilot Chat (CVE-2026-58616).
- Fix: Install the latest Microsoft Edge update; Chrome gets the same Chromium fixes via its own release channel.
4. Home / SOHO Impact
- Remove suspicious browser extensions. A cluster of 18 Chrome and 1 Edge extension was found harboring wallet-secret-stealing and crypto-draining code; if you installed any extension in the last six months that you don't fully trust, remove it and review your crypto/account activity.
- Update Microsoft Edge (and Chrome). This week's releases fix remote code execution and information-disclosure bugs in the browser, including a Chromium WebRTC buffer overflow.
- If you run WordPress for a small site, update WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP — these flaws enable site takeover and code execution.
- If your router is a ZBT or an unbranded white-label model, it may contain factory backdoors giving remote attackers root control; replace it and change any reused credentials.
- Small offices running PaperCut NG/MF on a print server: apply the emergency fix now — this is being actively exploited without authentication.
5. Enterprise Impact
- PaperCut NG/MF — patch immediately. Active exploitation chains two flaws for unauthenticated Java code execution inside the application; apply the emergency fix and audit the trusted configuration, accounts, and print scripts on affected servers.
- ownCloud — close CVE-2023-49105 now that it's in CISA KEV. The confirmed use against a nuclear research body shows file-sharing platforms are an espionage target; confirm your version is patched and review for signs of unauthorized file access.
- ServiceNow self-hosted customers: hosted instances are already updated, so the responsibility is on you — apply the ServiceNow AI Platform update covering the three CVSS 10.0 flaws.
- cPanel/WHM hosting providers: CVE-2026-65643 gives one tenant root on the whole server; patch all supported versions immediately and treat this as a cross-tenant containment risk.
- Cosmos chain operators: upgrade the shared EVM module to stop the balance-handling drain; treat any chain that ran the vulnerable module during August 20–25 as potentially financially compromised.
- Inventory and replace ZBT/white-label routers on your network edge — factory implants (CVE-2026-74232/CVE-2026-74233) provide unauthenticated root and cannot be trusted after a mere firmware update.
- Roll out the Microsoft Edge/Chromium update through your normal browser management channel.
6. What To Patch First
- PaperCut NG/MF emergency update — actively exploited unauthenticated RCE chain (see source for CVE).
- ownCloud patched release — CVE-2023-49105 (CISA KEV; exploited against nuclear research body).
- ServiceNow AI Platform update — three CVSS 10.0 flaws (critical; hosted already fixed).
- cPanel & WHM patch — CVE-2026-65643 (critical; tenant-to-root server takeover).
- Cosmos EVM module upgrade — GHSA-7g4w-cg88-2cq2 (actively exploited; funds drained).
- WordPress: WPMU DEV Dashboard, Avada, TranslatePress, Pods, GiveWP updates — CVE-2026-76581 and related (CVSS 9.8; site takeover/RCE).
- Microsoft Edge / Chromium update — CVE-2026-72984, CVE-2026-78891, and others (widely deployed browser RCE fixes).
- Replace ZBT/white-label routers — CVE-2026-74232, CVE-2026-74233 (factory backdoors; no patch available).
Sources
- Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication — https://thehackernews.com/2026/08/attackers-chain-two-papercut-flaws-to.html
- ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body — https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets.html
- Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable — https://thehackernews.com/2026/08/cosmos-evm-flaw-exploited-after-cosmos.html
- Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL — https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html
- Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server — https://thehackernews.com/2026/08/critical-cpanel-flaw-could-let-one.html
- Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE — https://thehackernews.com/2026/08/five-critical-wordpress-plugin-and.html
- China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access — https://thehackernews.com/2026/08/china-made-zbt-routers-ship-with-two.html
- 19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code — https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html
- CVE-2026-72984 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72984
- Chromium: CVE-2026-78891 Buffer overflow in WebRTC — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78891
More from News