A Print Server Zero-Day and Three Perfect Tens (08/28/2026)
- › A PaperCut zero-day is under active exploitation across all NG and MF versions, with emergency patches out for v25 and v26.
- › Three CVSS 10.0 flaws in ServiceNow allow unauthenticated code and SQL execution.
- › VulnCheck found two undocumented factory implants in Zbtlink router firmware, one beaconing outbound and one listening inbound.
- › A critical cPanel flaw lets one hosting customer take root control of an entire shared server.
- › CISA says most of what is being exploited should have been eradicated decades ago.
PaperCut is the one to act on before the weekend. The flaw affects every version of NG and MF, exploitation is confirmed against real customers, and the company has not published details of the vulnerability itself. Emergency patches exist for v25 and v26, and if your application server is reachable from the internet the immediate action is to make it not reachable.
Top 5 Critical Security Alerts
1. A PaperCut Zero-Day Is Being Exploited Across Every Version
PaperCut has confirmed customer incidents involving a zero-day affecting all versions of NG and MF, and has shipped emergency patches for v25 and v26 with a second patch following the first. The company has not disclosed the flaw, the exploitation method, or the actor. Indicators of compromise include suspicious activity from pc-app.exe, missing or deleted server.log files, and two specific error strings: a no suitable driver found for jdbc entry, and a database error looking up cardID. The Hacker News
Operator Note: Print management is the classic forgotten server, sitting in the middle of the network with credentials to a directory and a queue of documents passing through it. Check whether your application server web interface is reachable from untrusted addresses today, because that is the only mitigation available while details are withheld. Then check the three indicators, since a deleted log file is the cheapest thing to look for. BleepingComputer
2. Three Maximum-Severity ServiceNow Flaws
Three flaws scoring CVSS 10.0 in ServiceNow allow unauthenticated attackers to execute code and SQL. Maximum severity with no authentication required is the combination that removes every mitigating factor. The Hacker News
Operator Note: ServiceNow is where a great many organizations keep their asset inventory, their change records, and their access request history, which makes it a map of everything else you own. An unauthenticated maximum-severity flaw against that platform is worth an out-of-cycle change window rather than a queue entry.
3. Researchers Find Factory Implants in Cheap Routers
VulnCheck disclosed two previously undocumented factory implants in Zbtlink router firmware, found on an $88 white-labeled device bought from a US supplier with firmware built in 2019. SPEAKINGSTONE, tracked as CVE-2026-74232, beacons over UDP port 10000 to a hardcoded command server, executes arbitrary commands as root, and exfiltrates the WAN PPPoE username and password. DARKLANTERN, CVE-2026-74233, listens on UDP 9992, which the stock firewall opens to inbound connections from any internet address, with authentication defeated by a hardcoded salt and an all-zero wildcard MAC. Researchers observed 203 internet-facing DARKLANTERN instances across 22 countries between August 18 and 21, and note their counts are a floor rather than a total. The Hacker News
Operator Note: SPEAKINGSTONE is the design worth understanding, because it beacons outward and therefore works from behind network address translation and ordinary egress filtering. The vendor has previously described a similar component as an after-sales support tool used only with customer authorization, and has not commented on these two. If you have ever bought a white-labeled router on price, the label on the box is not the manufacturer.
4. A cPanel Flaw Lets One Customer Take Root of a Whole Server
A critical flaw in cPanel allows a single hosting customer to gain root control of an entire shared server. Isolation between tenants is the entire product on shared hosting, which makes this a failure of the thing being sold. The Hacker News
Operator Note: If any part of your estate sits on shared hosting, your exposure now includes every other tenant on the same box and none of them are your vendors. Ask your provider what they have patched and when, and treat the answer as the entire extent of your visibility, because it is.
5. CISA Says the Exploited Flaws Are Decades Old
CISA has pointed out that most of what is actively exploited consists of vulnerability classes that should have been eliminated long ago. The agency’s framing puts the failure on defect classes the industry knows how to prevent. The Register
Operator Note: This matches what we carried yesterday, where four of the six flaws CISA added to its exploited catalog were published between 2015 and 2022. The uncomfortable reading is that attacker sophistication is not the constraint on your risk, because the things working are old, well documented, and fixable.
Additional Security Alerts
Vulnerabilities & Exploits
- Over 8,300 Gitea servers are vulnerable to code execution: Source control as the target, which reaches everything built from it. BleepingComputer
- Two Unitree G1 EDU humanoid robot flaws allow root remote code execution, one over Bluetooth: Physical machines with a wireless attack surface and root available. The Hacker News
- A GiveWP WordPress donation plugin flaw allows server command execution: BleepingComputer
Threat Intelligence
- Nineteen Chrome and Edge extensions were found containing wallet-stealing and crypto-draining code: Browser extensions remain the least governed software in most organizations. The Hacker News
- The APT28-linked HOOKEDGE backdoor is targeting European government and diplomatic organizations: The Hacker News
- Fake voicemail SVG attachments are driving a large-scale phishing campaign: SVG renders as an image and executes as markup, which is why it keeps working. Infosecurity Magazine
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.