Weekly Cybersecurity Update: 24-31 August 2026
- SOC Team

- 2 days ago
- 3 min read
1. PaperCut Zero-Day Exploited in Active Attacks
Attackers are actively exploiting vulnerabilities in PaperCut NG and PaperCut MF in zero-day attacks. PaperCut released emergency security updates after confirming customer incidents involving the vulnerable print-management software.
The exploitation involves a chain of two vulnerabilities that can enable remote code execution on affected PaperCut Application Servers. Organisations with PaperCut servers exposed to the internet have been advised to immediately restrict access to trusted IP addresses.
CVE ID: CVE-2026-81578 and CVE-2026-82078
Why It Matters: PaperCut servers can have access to sensitive documents, user information and enterprise infrastructure. Successful exploitation could allow attackers to execute malicious code on the Application Server and establish a foothold for further compromise.
Actions: Apply the latest PaperCut emergency security updates immediately. Restrict access to PaperCut web interfaces from untrusted networks and review server logs for suspicious activity, unexpected processes or evidence of post-exploitation.
Source: The Hacker News – PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions thehackernews.com/2026/08/papercut-zero-day-exploited-in-attacks.html
2. Critical Gitea Vulnerability Actively Exploited in Remote Code Execution Attacks
A critical vulnerability in Gitea, a self-hosted Git service, is being actively exploited in remote code execution attacks. More than 8,000 internet-exposed Gitea servers were identified as vulnerable, with Shadowserver reporting thousands of vulnerable instances still exposed online.
The vulnerability can allow attackers with repository write access to execute arbitrary shell commands with the privileges of the Gitea service account. Because Gitea allows self-registration by default, attackers may be able to create an account and repository to obtain the required access.
CVE ID: CVE-2026-60004
Why It Matters: Gitea is used to host source code and development infrastructure. Successful exploitation could allow attackers to execute commands on the server, deploy malware or cryptocurrency miners, steal source code, and use the compromised system to move further into an organisation's environment.
Actions: Upgrade Gitea to version 1.27.1 or later. Disable unnecessary self-registration, restrict internet access to Gitea instances and review repositories, accounts and server processes for suspicious activity.
Source: BleepingComputer – Over 8,300 Gitea servers vulnerable to code execution attacks bleepingcomputer.com/news/security/over-8-300-gitea-servers-vulnerable-to-code-execution-attacks/
3. Critical ServiceNow Vulnerabilities Allow Unauthenticated Code Execution
ServiceNow has patched four vulnerabilities affecting its AI Platform, including three critical flaws rated CVSS 10.0. Under certain conditions, unauthenticated attackers could exploit the vulnerabilities to execute arbitrary code, execute SQL queries, or access and modify sensitive instance data.
The vulnerabilities affect ServiceNow AI Platform functionality and could expose enterprise environments to unauthorized access if left unpatched.
CVE ID: CVE-2026-18885, CVE-2026-18886, and related vulnerabilities (CVSS Score: up to 10.0)
Why It Matters: ServiceNow environments can contain sensitive business information, workflows, credentials and configuration data. Successful exploitation could allow attackers to access or manipulate enterprise information and potentially compromise the ServiceNow environment.
Actions: Apply the latest ServiceNow security updates and prioritise affected internet-accessible instances. Review API activity, authentication logs, and configuration changes for suspicious or unauthorized activity.
Source: The Hacker News – Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html
4. ownCloud Vulnerability Exploited to Steal Sensitive Nuclear Research Data
A critical vulnerability affecting ownCloud has been exploited by a Chinese-speaking threat actor to target a nuclear research organisation in the Philippines. CISA added the vulnerability to its Known Exploited Vulnerabilities catalogue following reports of exploitation.
The flaw can allow attackers to gain unauthorised access to sensitive information stored on vulnerable ownCloud servers. The incident demonstrates the potential impact of exploiting internet-facing file-sharing infrastructure.
CVE ID: CVE-2025-49103
Why It Matters: File-sharing platforms can contain highly sensitive corporate, government and research information. Successful exploitation could allow attackers to access confidential files and use compromised infrastructure as a foothold for further attacks.
Actions: Update affected ownCloud installations to the latest supported versions, restrict access to administrative interfaces and review authentication and access logs for suspicious activity. Organisations handling sensitive information should also verify whether any data was accessed or exfiltrated.
Source: The Hacker News – ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body thehackernews.com/2026/08/snowflake-github-actions-flaw-lets.html
Key Recommendations
Prioritise actively exploited vulnerabilities: Review exposure to CVE-2026-81578, CVE-2026-82078, CVE-2026-60004 and CVE-2025-49103 and apply available security updates as a priority.
Secure internet-facing infrastructure: Restrict external access to PaperCut, Gitea, ownCloud and ServiceNow management interfaces wherever possible.
Review exposed applications: Identify internet-facing instances and confirm that vulnerable versions are not accessible from untrusted networks.
Strengthen monitoring: Monitor for suspicious processes, unexpected accounts, unusual authentication activity, malicious files, unexpected outbound connections and abnormal API requests.
Protect sensitive data: Review access to source code, corporate documents, credentials and other sensitive information stored on affected platforms.
Maintain incident-response readiness: If any vulnerable system was exposed during the exploitation period, investigate for persistence, privilege escalation, data access and possible exfiltration.
