The trailing 48 hours were dominated by PaperCut’s scramble to contain an actively exploited pre-auth RCE chain, a maximum-severity object-injection bug in a WordPress donation plugin with six-figure install counts, and two large data-theft disclosures. Every item below was checked against the vendor advisory, researcher write-up, or regulatory filing that originated it.
PaperCut ships a second emergency patch after researchers bypass the first one
PaperCut · August 28, 2026
PaperCut assigned CVE identifiers to the zero-day chain it disclosed on August 27 and shipped Emergency Patch Release 2 for PaperCut NG and MF versions 24, 25, and 26 across Windows, Linux, and macOS. CVE-2026-81578 is an authentication bypass in the NG/MF web management interface rated 8.8, and CVE-2026-82078 is a critical unsafe dynamic class-loading flaw in the database connection utilities rated 9.4; chained, they give an unauthenticated attacker remote code execution. The second release followed after watchTowr reproduced the bugs and found multiple bypasses of the original patch, and Huntress independently found bypasses plus an additional authentication bypass while observing exploitation in two customer environments. PaperCut is urging every customer to install Release 2 even if the first patch is already applied, and to restrict web interface access to trusted IP ranges; version 23 and earlier get no patch and should be upgraded.
“Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks.” — PaperCut security bulletin
Source: PaperCut security bulletin · BleepingComputer
GiveWP WordPress donation plugin patches a CVSS 10.0 object-injection-to-RCE chain
Patchstack · August 28, 2026
Patchstack published its write-up of CVE-2026-82222, a deserialization-of-untrusted-data flaw in the GiveWP donation plugin rated CVSS 10.0 and affecting all versions through 4.16.7.1. The plugin has more than 100,000 active installs. Exploitation chains three issues: an unsafe unserialize helper, a donation flow that stores attacker-controlled serialized objects, and a gadget chain in bundled libraries that reaches arbitrary system commands. The account requirement is not a barrier, because the plugin exposes a registration endpoint that ignores whether WordPress registration is disabled. GiveWP fixed it in 4.16.7.2, released August 27, which also strips serialized payloads already written to affected databases. No in-the-wild exploitation has been reported; the bug was reported by researcher Udin Chan on July 28.
“Even on a site that has registration disabled, the attacker can create an account and receive an authentication cookie, then carry out the rest of the attack in the same sequence.” — Patchstack
Source: Patchstack advisory · BleepingComputer
McKesson confirms an intrusion in an SEC filing as ShinyHunters claims 284 million patient records
McKesson (SEC Form 8-K) · August 28, 2026
Pharmaceutical distributor McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, filing a Form 8-K after the extortion group ShinyHunters claimed to hold 284 million patient records. McKesson says it discovered the incident on August 25 and that its investigation is in the early stages, so the attacker’s record count is unverified. Reporting on the claimed data set describes identity and contact fields including Social Security numbers, healthcare identifiers such as patient IDs and Medicaid numbers, and clinical detail including diagnoses, medications, and appointment notes. The group’s described access path — vishing against employee Okta single sign-on accounts, then Salesforce and Snowflake environments — matches ShinyHunters’ pattern across 2026 but has not been confirmed by McKesson.
Source: BleepingComputer · DataBreaches.net
Manchester Airports Group says attackers stole data on 8.7 million travelers and refuses a ransom
Manchester Airports Group · August 28, 2026
MAG disclosed that intruders took customer data tied to car park, lounge, and Fast Track bookings and to in-airport Wi-Fi sign-ups at Manchester, Stansted, and East Midlands airports, affecting roughly 8.7 million people. The exposed fields are email addresses, phone numbers, vehicle registrations, and postcodes; MAG states that neither the group nor the affected system holds bank or payment card data. The company says it restricted access to the affected systems, brought in external responders, and notified law enforcement, and it temporarily suspended its online “Manage My Booking” service. MAG confirmed a ransom was demanded and declined to pay.
Source: Help Net Security · BleepingComputer
Still developing
Citrix NetScaler CVE-2026-8452 — federal remediation deadline landed August 29. CISA added the NetScaler ADC and Gateway memory-buffer flaw to the KEV catalog on August 26 with a three-day fix deadline for federal civilian agencies. Citrix originally patched the bug on June 30 as a denial-of-service issue; researchers later showed it yields unauthenticated remote code execution, and webshells and discovery activity have been seen on compromised appliances. Source: CISA · The Hacker News
Three more KEV additions carry an August 30 deadline. On August 27 CISA added CVE-2023-49105 (ownCloud improper authentication, versions 10.6.0 through 10.13.0), CVE-2026-53362 (Linux kernel), and CVE-2026-66384 (JFrog Artifactory path traversal). The ownCloud and kernel entries are due August 30; the Artifactory entry is due September 10. Source: CISA · Security Affairs
ServiceNow patched three CVSS 10.0 flaws. The August 27 advisory covers CVE-2026-18885 (code injection in the Now Platform), CVE-2026-18886 (code injection in the ServiceNow AI Platform enabling privilege escalation), CVE-2026-74820 (SQL injection in the AI Platform), and CVE-2026-6876 (sandbox escape). Three are rated 10.0 and reachable by an unauthenticated attacker under certain conditions; self-hosted customers need to patch or upgrade. Source: ServiceNow · The Hacker News
This brief covers the trailing ~48 hours (August 28–29, 2026).
Primary sources:
- PaperCut — URGENT Security Advisory: PaperCut NG/MF Security Bulletin
- Huntress — PaperCut actively exploited
- Patchstack — Unauthenticated PHP Object Injection to RCE on GiveWP
- CISA — Adds Six Known Exploited Vulnerabilities to Catalog (Aug 26)
- CISA — Adds Three Known Exploited Vulnerabilities to Catalog (Aug 27)
- CISA — Known Exploited Vulnerabilities Catalog
- ServiceNow — Security advisory KB3137947