PaperCut Reships Emergency Patch for Exploited RCE Chain, GiveWP Fixes CVSS 10.0 Object Injection, McKesson Breach Hits SEC Filing

The trailing 48 hours were dominated by PaperCut’s scramble to contain an actively exploited pre-auth RCE chain, a maximum-severity object-injection bug in a WordPress donation plugin with six-figure install counts, and two large data-theft disclosures. Every item below was checked against the vendor advisory, researcher write-up, or regulatory filing that originated it.

PaperCut ships a second emergency patch after researchers bypass the first one

PaperCut · August 28, 2026

PaperCut assigned CVE identifiers to the zero-day chain it disclosed on August 27 and shipped Emergency Patch Release 2 for PaperCut NG and MF versions 24, 25, and 26 across Windows, Linux, and macOS. CVE-2026-81578 is an authentication bypass in the NG/MF web management interface rated 8.8, and CVE-2026-82078 is a critical unsafe dynamic class-loading flaw in the database connection utilities rated 9.4; chained, they give an unauthenticated attacker remote code execution. The second release followed after watchTowr reproduced the bugs and found multiple bypasses of the original patch, and Huntress independently found bypasses plus an additional authentication bypass while observing exploitation in two customer environments. PaperCut is urging every customer to install Release 2 even if the first patch is already applied, and to restrict web interface access to trusted IP ranges; version 23 and earlier get no patch and should be upgraded.

“Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks.” — PaperCut security bulletin

Source: PaperCut security bulletin · BleepingComputer

GiveWP WordPress donation plugin patches a CVSS 10.0 object-injection-to-RCE chain

Patchstack · August 28, 2026

Patchstack published its write-up of CVE-2026-82222, a deserialization-of-untrusted-data flaw in the GiveWP donation plugin rated CVSS 10.0 and affecting all versions through 4.16.7.1. The plugin has more than 100,000 active installs. Exploitation chains three issues: an unsafe unserialize helper, a donation flow that stores attacker-controlled serialized objects, and a gadget chain in bundled libraries that reaches arbitrary system commands. The account requirement is not a barrier, because the plugin exposes a registration endpoint that ignores whether WordPress registration is disabled. GiveWP fixed it in 4.16.7.2, released August 27, which also strips serialized payloads already written to affected databases. No in-the-wild exploitation has been reported; the bug was reported by researcher Udin Chan on July 28.

“Even on a site that has registration disabled, the attacker can create an account and receive an authentication cookie, then carry out the rest of the attack in the same sequence.” — Patchstack

Source: Patchstack advisory · BleepingComputer

McKesson confirms an intrusion in an SEC filing as ShinyHunters claims 284 million patient records

McKesson (SEC Form 8-K) · August 28, 2026

Pharmaceutical distributor McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, filing a Form 8-K after the extortion group ShinyHunters claimed to hold 284 million patient records. McKesson says it discovered the incident on August 25 and that its investigation is in the early stages, so the attacker’s record count is unverified. Reporting on the claimed data set describes identity and contact fields including Social Security numbers, healthcare identifiers such as patient IDs and Medicaid numbers, and clinical detail including diagnoses, medications, and appointment notes. The group’s described access path — vishing against employee Okta single sign-on accounts, then Salesforce and Snowflake environments — matches ShinyHunters’ pattern across 2026 but has not been confirmed by McKesson.

Source: BleepingComputer · DataBreaches.net

Manchester Airports Group says attackers stole data on 8.7 million travelers and refuses a ransom

Manchester Airports Group · August 28, 2026

MAG disclosed that intruders took customer data tied to car park, lounge, and Fast Track bookings and to in-airport Wi-Fi sign-ups at Manchester, Stansted, and East Midlands airports, affecting roughly 8.7 million people. The exposed fields are email addresses, phone numbers, vehicle registrations, and postcodes; MAG states that neither the group nor the affected system holds bank or payment card data. The company says it restricted access to the affected systems, brought in external responders, and notified law enforcement, and it temporarily suspended its online “Manage My Booking” service. MAG confirmed a ransom was demanded and declined to pay.

Source: Help Net Security · BleepingComputer

Still developing

Citrix NetScaler CVE-2026-8452 — federal remediation deadline landed August 29. CISA added the NetScaler ADC and Gateway memory-buffer flaw to the KEV catalog on August 26 with a three-day fix deadline for federal civilian agencies. Citrix originally patched the bug on June 30 as a denial-of-service issue; researchers later showed it yields unauthenticated remote code execution, and webshells and discovery activity have been seen on compromised appliances. Source: CISA · The Hacker News

Three more KEV additions carry an August 30 deadline. On August 27 CISA added CVE-2023-49105 (ownCloud improper authentication, versions 10.6.0 through 10.13.0), CVE-2026-53362 (Linux kernel), and CVE-2026-66384 (JFrog Artifactory path traversal). The ownCloud and kernel entries are due August 30; the Artifactory entry is due September 10. Source: CISA · Security Affairs

ServiceNow patched three CVSS 10.0 flaws. The August 27 advisory covers CVE-2026-18885 (code injection in the Now Platform), CVE-2026-18886 (code injection in the ServiceNow AI Platform enabling privilege escalation), CVE-2026-74820 (SQL injection in the AI Platform), and CVE-2026-6876 (sandbox escape). Three are rated 10.0 and reachable by an unauthenticated attacker under certain conditions; self-hosted customers need to patch or upgrade. Source: ServiceNow · The Hacker News


This brief covers the trailing ~48 hours (August 28–29, 2026).

Primary sources:

Leave a Reply