Severity Daily

IT and AI security incidents, checked against the primary source

Tag: TranslatePress

  • PaperCut needed a second emergency patch, and the record spent the day contradicting its own authors

    PaperCut needed a second emergency patch, and the record spent the day contradicting its own authors

    The most consequential item on the site today is that PaperCut’s zero-day now needs a second emergency patch, because researchers bypassed the first one. Anyone who patched on August 27 is not protected. The flaw now has two numbers — CVE-2026-81578, an unauthenticated access-control bypass in the web management interface, and CVE-2026-82078, unsafe dynamic class loading — and they chain. Huntress has found evidence of exploitation in two customer environments. That outranks the bigger-sounding story of the day. Manchester Airports Group confirmed that roughly 8.7 million customers’ details were taken from a third-party-hosted database, and the number is real, but nobody reading this can act on it tonight. An internet-facing print server running a build that a public bypass defeats is a task, not a headline.

    The day had a thread, and it is a sharper version of yesterday’s: the record did not merely lag the risk, it contradicted its own authors. CISA’s machine-readable assessment of both PaperCut CVEs, timestamped August 28, records exploitation as “none” — written a day after PaperCut told its own customers they were under attack. Wordfence’s advisory for a CVSS 9.8 unauthenticated remote code execution flaw in the Avada theme conditions exploitation on site content an administrator has to have created, while the researchers who found it told reporters that any site with the theme installed is exploitable. GiveWP shipped the fix for an unauthenticated CVSS 10.0 remote code execution chain and called it “additional hardening” in its changelog. TranslatePress’s fixing release does not appear in the vendor changelog at all. In each case the authoritative document disagrees with something the same organization said out loud.

    Order of business after PaperCut. Gitea’s three-day federal deadline for CVE-2026-60004 expired on August 28 with Shadowserver counting 8,393 vulnerable instances the day before; the fix shipped on July 27, so this is a patch nobody applied rather than a patch nobody had. Then ServiceNow, which published four of its own CVEs on August 27 and scored three of them at a flat CVSS v4.0 10.0 with byte-identical vectors, all unauthenticated, all citing one knowledge base article. Then the WordPress set — GiveWP on more than 100,000 sites, Avada, and TranslatePress on more than 400,000, where what leaked was administrator password-reset links readable by any visitor. Cosmos EVM operators should read the post-mortem: Cosmos Labs confirmed on August 13 that every EVM chain was exposed and began notifying operators on August 21, after exploitation had begun. Below that, VulnCheck’s two new Zbtlink router implants — one a service that runs commands as root on an unauthenticated UDP port, though VulnCheck’s own internet-facing count is 203 devices — and the deleted Log4j deserialization report that Apache says is a known non-finding while the public exploit labs stay up.

    Three disclosures moved today without handing anyone a task: ATF confirmed a breach of a standalone system that the Justice Department has already designated a major incident, Berlin confirmed it is being extorted and rejected the ultimatum eleven days after announcing the compromise without mentioning it, and Hasbro’s employee notification letters surfaced in a state attorney general filing.

    Still open. CISA’s assessment of the PaperCut chain still records exploitation as “none” — the field that drives federal prioritization, on the one item confirmed under attack. ATF has not said what was on the standalone system, and no data has appeared. Zbtlink disputes VulnCheck’s characterization, and no CVE has been assigned to either implant. Hasbro’s own public account of the March breach has not moved since April 4, while the letters go out now. And the ICO has asked MAG not to name the group behind the theft, so the attribution most readers want is the one thing that will not be published.