The seven completed days from August 29 through September 4, 2026 produced two immediate incident-response priorities and a major network-platform patch cycle. PaperCut disclosed confirmed attacks against NG/MF servers and released a third emergency patch. Google fixed a V8 vulnerability already exploited in the wild, only two days after an earlier Chrome 152 security release. Cisco published critical fixes for IOS XR and Nexus 9000 systems. NIST, meanwhile, issued work that belongs in the planning queue. The defender order is clear: fix the actively exploited systems now, verify whether attackers arrived first, then plan durable controls.
Fix now
1. Isolate and patch internet-facing PaperCut NG/MF
CISA added CVE-2026-81578 and CVE-2026-82078 to the Known Exploited Vulnerabilities catalog on August 31. PaperCut says it is investigating active exploitation and confirmed customer incidents affecting PaperCut NG and MF. The vendor states that the advisory applies to all versions of both products.
The network action comes first: if a PaperCut Application Server is reachable from the public internet, restrict web access to trusted IP addresses. PaperCut recommends firewall rules, network access controls, or equivalent measures even when no suspicious activity has been observed.
On September 1, PaperCut released Emergency Patch Release 3. It supersedes Release 2, corrects two regressions, and adds hardening against potential attack chains. Internet-facing customers should install Release 3 even if an earlier emergency patch is present, using the builds and checksums in the current vendor bulletin.
CVE-2026-81578 is an authentication bypass in the web management interface that can allow unauthenticated requests to modify certain configuration. CVE-2026-82078 concerns unsafe dynamic class loading in database connection utilities; manipulation of configuration can lead to Java bytecode execution as the PaperCut server process. The remediation record must therefore include both the emergency patch and a decision about whether public access remains necessary.
2. Upgrade Chrome again: the September 1 build is no longer enough
Google released Chrome 152.0.7977.75/.76 for Windows and macOS and 152.0.7977.75 for Linux on September 1, fixing 26 security issues. On September 3, Google followed with 152.0.7977.82/.83 for Windows and macOS and 152.0.7977.82 for Linux, fixing another 12.
The later release includes CVE-2026-85046, a high-severity type confusion vulnerability in V8. Google explicitly says an exploit exists in the wild, and CISA added the vulnerability to KEV on September 4. “Chrome 152 installed” is insufficient evidence, and even the September 1 build is stale. Deploy the September 3 release or later, require a restart, and verify the active process version.
For the complete fleet-verification and exception-handling workflow, use the full AboutInfoSec article Chrome Security Updates: Verify the Running Build. This digest does not repeat that implementation guide.
3. Apply Cisco’s September network-platform fixes
Cisco’s September 2 cycle includes two critical groups. The IOS XR Security Hardening Release addresses seven CVEs and carries a critical 9.8 rating. CVE-2026-20212 affects Cisco Nexus 9000 Series Switches using Silicon One and is also rated 9.8. Cisco additionally published a high-severity denial-of-service advisory for several phone families and medium-severity Secure Email S/MIME issues.
Cisco states there are no workarounds for the advisory set and strongly recommends upgrading to the fixed software specified for each product. Inventory chassis, supervisors, line cards, virtual instances, lab devices, standby units, and out-of-band management paths. Validate compatibility before the change, but prioritize exposed and high-trust systems. For the broader process of eliminating forgotten management exposure, refer to the full AboutInfoSec Router Hygiene in 2026 guide.
Verify
4. Hunt PaperCut before closing the incident
PaperCut has published concrete indicators. Review alerts involving the Application Server and suspicious child processes from pc-app.exe or pc-app. Examine server.log for deletion, unexpected truncation, database-driver errors, suspicious JDBC Derby strings, and random driver names. Look for unexpected .class, .cmd, and .out files in the vendor-listed locations.
PaperCut reports observed behavior in which the application process launched cmd.exe and commands such as whoami, ver, tasklist, and domain discovery. Attackers may remove created files, so their absence does not prove the server was clean.
Preserve endpoint, network, identity, and PaperCut logs before rebuilding or rotating credentials. Establish when the server was publicly reachable, compare that window with patch deployment, and identify every credential or downstream system accessible to the service account. If tokens or browser sessions may have been exposed, use the full AboutInfoSec Stolen Session Cookies Detection and Response Guide.
5. Verify browsers and network devices from running state
For Chrome, collect the running version after restart, not only the package staged on disk. Separate exceptions into pending restart, failed update service, unsupported operating system, unmanaged installation, and derivative Chromium browser awaiting its own vendor release.
For Cisco, compare the executing image and hardware combination with the exact advisory. Check redundant members individually and confirm the boot configuration points to the fixed image. Review administrative access, configuration changes, unexpected reloads, new accounts, and changes to trusted management sources. The full method for combining KEV status, exposure, privilege, and evidence is covered in CISA KEV: How to Prioritize Patch and Hunt Work.
Plan
6. Put hardware provenance and storage cryptography on the roadmap
NIST published IR 8615 on September 1 following its sustainable hardware security workshop. It identifies priorities across the semiconductor life cycle: common trust models, cryptographic identities, provenance, hardware bills of materials, attestation, scalable verification, supply-chain incentives, workforce development, and post-quantum preparation. This is not an emergency patch. Procurement, architecture, and product-security teams should use it to test whether hardware trust continues from manufacture through deployment, maintenance, transfer, and end-of-life.
On September 3, NIST released a draft revision of SP 800-38E for XTS-AES protection of storage devices. Revision 1 references IEEE 1619-2025 and clarifies approved use, data-unit and key-scope limits, key requirements, and ciphertext-stealing ordering. Public comment runs through October 16, 2026. Storage and cryptography owners should compare current designs with the draft while remembering that XTS-AES provides storage confidentiality, not a complete integrity, access-control, or key-management architecture.
Monday handoff
| Priority | Owner | Evidence required |
|---|---|---|
| PaperCut containment and Release 3 | Server, network, and IR teams | Restricted exposure, verified build, installation result |
| PaperCut compromise assessment | Incident response | Logs, process tree, exposure window, credential scope |
| Chrome CVE-2026-85046 | Endpoint management | 152.0.7977.82/.83 or later running after restart |
| Cisco September advisories | Network engineering | Asset mapping and executing fixed images |
| NIST hardware and storage work | Architecture and product security | Named reviewers and gap-assessment decisions |
This week shows why remediation evidence must be version-specific and time-aware. PaperCut’s third emergency patch superseded earlier releases, Chrome’s September 1 build became outdated within two days, and Cisco’s fixes vary by product and software train. “Patched” is not a durable fact unless the record identifies what is running now and whether the system was exposed before it.
Primary sources
- CISA PaperCut KEV additions, August 31, 2026
- PaperCut urgent advisory, updated September 5, 2026
- Google Chrome stable update, September 1, 2026
- Google Chrome stable update, September 3, 2026
- CISA CVE-2026-85046 KEV addition, September 4, 2026
- Cisco September 2 advisory summary
- NIST IR 8615, September 1, 2026
- NIST draft SP 800-38E Revision 1, September 3, 2026

