September 1, 2026 | Jonathan Brown

Command View


Verification cutoff

September 1, 2026, 18:00 UTC. This edition prioritizes active exploitation of PaperCut management servers, a newly confirmed physical attack against a critical German transmission node, and a critical Veeam ONE authentication-coercion vulnerability affecting backup-management infrastructure.

Priority posture

  • RED: PaperCut NG and MF exploitation is confirmed. CISA added both components of the attack chain to the Known Exploited Vulnerabilities Catalog on August 31. PaperCut released Emergency Patch Release 3 today after observing additional attack vectors and regressions in earlier emergency fixes.
  • RED: Purpose-built devices caused short circuits at a critical German transmission connection and forced one generating unit offline. Electricity supply was restored quickly, but the event demonstrates a deliberate physical attack against a high-consequence grid junction.
  • AMBER: Veeam ONE contains a critical unauthenticated SMB authentication-coercion vulnerability. Fixed builds are available; no confirmed exploitation was identified by the cutoff.
  • WATCH: Community reports describe Chrome and Brave failing to start on some Linux systems after updates. A shared root cause, affected distribution range, and authoritative vendor resolution were not established sufficiently for operational escalation.

Today’s decisions

  • RED — Server and print-platform owners: Identify every PaperCut Application Server, Site Server, and secondary print server. Apply Emergency Patch Release 3, including where Release 1 or 2 was already installed.
  • RED — Incident response: Treat every internet-accessible or otherwise untrusted-accessible PaperCut server as potentially compromised. Preserve logs and forensic evidence before rebuilding or restoring affected systems.
  • RED — Identity and endpoint teams: Hunt for PaperCut service processes spawning shells, SimpleHelp or AnyDesk installation, suspicious database-driver artifacts, and missing or truncated PaperCut logs.
  • RED — Energy operators and physical-security owners: Inspect exposed transmission interfaces, substations, line approaches, and surveillance coverage for devices capable of producing conductive-line faults. Correlate physical alarms with protection-system telemetry.
  • AMBER — Backup and virtualization teams: Update affected Veeam ONE 13 deployments and prevent untrusted systems from coercing outbound SMB authentication from monitoring-service accounts.
  • WATCH — Linux endpoint administrators: Test Chromium-family browser updates before broad deployment where browsers support operational consoles. Do not attribute isolated launch failures to a common regression without matching crash evidence.

Threat and Resilience Ledger


RED — Management infrastructure | Global — PaperCut attack chain enters KEV as vendor issues third emergency patch

CISA added CVE-2026-81578 and CVE-2026-82078 to its Known Exploited Vulnerabilities Catalog on August 31 after PaperCut confirmed customer incidents involving PaperCut NG and PaperCut MF. CVE-2026-81578 is a missing-authentication flaw, rated 8.8 under CVSS 4.0, through which unauthenticated requests can cause administrative actions before access validation completes. CVE-2026-82078 is an unsafe dynamic-class-loading weakness, rated 9.4 under CVSS 4.0; an attacker able to manipulate the relevant configuration can cause arbitrary Java bytecode already placed on the application classpath to execute under the PaperCut server process. Chaining the unauthenticated configuration weakness with the class-loading flaw provides a path to pre-authentication server compromise.

PaperCut says the advisory applies to all versions of PaperCut NG and PaperCut MF. On September 1, the company published Emergency Patch Release 3 for supported version 24, 25, and 26 deployments. The third emergency release corrects SAML and legacy Microsoft SQL Server regressions introduced by the emergency-patch process while adding hardening against additional attack paths observed in exploitation. PaperCut explicitly recommends Release 3 even where an earlier emergency patch was installed. Site Servers and secondary or print servers must also be patched; Mobility Print, Print Deploy server components, User Client, Print Deploy client, and the Mobility Print installer are not affected.

Verified Release 3 builds are PaperCut MF 26 build 76531, MF 25 build 76532, MF 24 build 76534, PaperCut NG 26 build 76530, NG 25 build 76533, and NG 24 build 76535. Customers on version 23 or earlier should move to a supported major version.

Observed activity includes pc-app.exe or pc-app spawning command shells, reconnaissance commands, and subsequent installation of SimpleHelp and AnyDesk remote-access software. PaperCut also identifies suspicious database-driver strings and short randomly named .class, .cmd, and .out files in server directories. Attackers may remove those artifacts and truncate or delete server.log; their absence therefore does not clear a server. Where compromise is suspected, PaperCut recommends preserving current backups, completely wiping and rebuilding the Application Server, and restoring a clean backup from before the suspicious activity.

Evidence: confirmed.
Attribution: unknown.
Confidence: high.
Uncertainty: Public reporting does not yet establish the full victim population, initial exposure conditions across every incident, persistence mechanisms beyond observed remote-access tooling, or a responsible actor.
Sources: PaperCut — “URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026),” updated September 1, 2026; CISA — “CISA Adds Two Known Exploited Vulnerabilities to Catalog,” August 31, 2026; CISA — “Known Exploited Vulnerabilities Catalog,” accessed September 1, 2026.

RED — Electric power | Germany — Purpose-built devices disrupt critical Brandenburg transmission connection

Brandenburg Interior Minister Jan Redmann reported on September 1 that specially constructed rockets carrying conductive material had been fired into extra-high-voltage lines near the Turnow-Preilack substation. The devices caused two short circuits. The substation is a critical regional node connecting the Jaenschwalde power plant—Brandenburg’s largest generating plant—to the 50Hertz transmission grid.

Grid operator 50Hertz said the incident produced a brief power interruption, but the wider electricity supply was not affected and all transmission lines had returned to operation. Plant operator LEAG reported that one Jaenschwalde generating unit shut down spontaneously and was expected to return during the evening. Authorities found incendiary devices at the site in numbers reportedly reaching double digits.

The operational effect and deliberate mechanism are confirmed, but attribution is not. Redmann said investigators had not excluded either foreign involvement or domestic left-wing extremists. That statement defines investigative possibilities; it does not constitute attribution. No evidence available by the cutoff established that cyber access, manipulation of protection systems, or remote operational-technology interference contributed to the incident.

European transmission and generation operators should nevertheless treat the event as a hybrid-resilience warning. Physical attacks against conductors and exposed grid junctions can generate effects resembling equipment failure, including protection trips and generating-unit disconnection. Operators should preserve disturbance records, protective-relay event files, surveillance footage, access-control records, and communications logs before routine retention or maintenance processes overwrite them.

Evidence: confirmed operational event; attack mechanism reported by government and operators.
Attribution: unknown.
Confidence: high for the physical event and limited grid effect; low for any actor hypothesis.
Uncertainty: Investigators have not publicly established the perpetrators, strategic objective, complete device design, reconnaissance history, or whether additional sites were prepared or targeted.
Sources: Reuters — “German minister says Brandenburg power grid target of sabotage attack,” September 1, 2026; 50Hertz — operator statement cited September 1, 2026; Brandenburg Interior Ministry — ministerial press-conference statements reported September 1, 2026.

AMBER — Backup-management infrastructure | Global — Veeam ONE flaw can coerce privileged SMB authentication

Veeam disclosed CVE-2026-65641, a critical vulnerability through which an unauthenticated network attacker can cause the Veeam ONE service account to initiate SMB authentication. Veeam assigns the flaw a CVSS 4.0 score of 9.3. Depending on network and identity controls, coerced authentication material could support credential relay, capture, or subsequent lateral movement; Veeam’s advisory itself establishes authentication coercion but does not claim a specific universal post-exploitation result.

The affected scope is Veeam ONE 13.1.0.7034 and all earlier version 13 builds. Veeam states that older major releases, including version 12, are not affected. Corrected builds are Veeam ONE 13.1 Patch 0, build 13.1.0.7233, and Veeam ONE 13.0.2 Patch 1, build 13.0.2.7159. The vulnerability was reported through HackerOne. No confirmed exploitation or public exploit was identified in authoritative material by the cutoff.

Because Veeam ONE observes backup, virtualization, and recovery environments, its service identities and network reach may provide access paths into systems whose integrity is essential during incident recovery. Defenders should patch, review the privileges of the Veeam ONE service account, restrict unnecessary outbound SMB, and verify that NTLM relay protections are enforced on reachable services.

Evidence: confirmed vulnerability and fixed builds.
Attribution: not applicable.
Confidence: high.
Uncertainty: Veeam has not publicly described the complete request path, practical relay conditions, or whether attackers have privately reproduced the issue.
Sources: Veeam — “KB4905: Vulnerability Resolved in Veeam ONE 13.1 Patch 0,” August 25, 2026; Veeam — “List of Security Fixes and Improvements in Veeam ONE,” accessed September 1, 2026.

Defensive Posture Changes


Emergency patches require lineage verification

The PaperCut sequence demonstrates why “patched” is not a sufficiently precise asset state. Release 1, Release 2, and Release 3 do not provide equivalent assurance. Inventories and change records should identify the exact emergency release and build installed on every Application Server, Site Server, and secondary server. Validate SAML authentication and any external card-number lookup after installation, because Release 3 specifically addresses regressions affecting those functions.

Patch installation does not close a PaperCut incident

A vulnerable server may already contain remote-access software or other persistence. Preserve server.log, endpoint telemetry, Windows service creation, process trees, PowerShell history, network connections, and authentication records before rebuilding. Search for PaperCut processes launching cmd.exe, powershell.exe, whoami, tasklist, nltest, or download utilities. Unexpected AnyDesk or a SimpleHelp service named Remote Access Service warrants investigation, but neither artifact alone proves that this particular campaign caused the installation.

If compromise is supported, rebuild rather than trusting an in-place patch. Rotate credentials, tokens, database secrets, and service-account material accessible to the PaperCut host; validate adjacent systems reached from it.

Prevent authentication-coercion flaws from becoming identity compromise

Treat outbound SMB from management and monitoring servers as an exception requiring explicit justification. Segment Veeam ONE from user networks, constrain the service account, require SMB signing where supported, disable obsolete NTLM use where operationally feasible, and monitor for unexpected authentication attempts from the Veeam ONE host. These controls reduce the consequence of authentication coercion but do not replace the Veeam update.

Preserve cyber-physical evidence across organizational boundaries

The Brandenburg incident crossed physical security, generation operations, transmission operations, protection engineering, and law enforcement. Critical-infrastructure response plans should assign ownership for collecting relay oscillography, supervisory control and data acquisition alarms, surveillance footage, access records, and physical debris on a common timeline. Without that coordination, routine restoration can destroy evidence needed to distinguish equipment failure, sabotage, and combined cyber-physical action.

Regional and Sector Pulse


Europe and the United Kingdom — RED

The Turnow-Preilack attack establishes a confirmed physical attack with limited operational effect against a strategically important German grid connection. Operators elsewhere should not infer a coordinated regional campaign, but the device preparation and selection of a critical junction justify immediate review of comparable exposed sites. Attribution remains open.

North America — RED

PaperCut is widely used in education, government, healthcare, and enterprise environments, making active exploitation relevant to organizations that may regard print management as secondary infrastructure. CISA’s KEV additions and PaperCut’s confirmed incidents remove uncertainty about whether exploitation is occurring. Exposure discovery, Release 3 deployment, and compromise assessment take priority over routine vulnerability-queue handling.

Indo-Pacific — RED

PaperCut’s advisory is global, and its emergency releases were issued from an Australian vendor response process. The same immediate response applies to reachable deployments throughout the region. No region-specific victim count or campaign attribution was verified.

Middle East and Africa — WATCH

The PaperCut and Veeam products create global exposure, but no authoritative evidence reviewed by the cutoff establishes a region-specific campaign or operational incident in this region. Organizations should act according to product exposure rather than assuming geographic targeting.

Latin America and the Caribbean — WATCH

No distinct regional incident meeting the evidence threshold was identified. PaperCut and Veeam remediation remains applicable wherever the affected products are deployed, particularly in government, education, healthcare, and managed-service environments.

Vulnerability and Supplier Watchlist


PaperCut NG and PaperCut MF

Issue: CVE-2026-81578 missing authentication for a critical function and CVE-2026-82078 unsafe dynamic class loading; exploited as an attack chain.
Affected scope: All PaperCut NG and MF versions; Application Servers, Site Servers, and secondary or print servers require remediation.
Fixed release: Emergency Patch Release 3 for supported version 24, 25, and 26 branches; exact builds are listed in the ledger.
Severity: CVSS 4.0 scores 8.8 and 9.4 respectively.
Status: RED — confirmed customer incidents, active exploitation, KEV inclusion, and observed remote-access deployment.

Veeam ONE

Issue: CVE-2026-65641 permits unauthenticated SMB authentication coercion from the service account.
Affected scope: Veeam ONE 13.1.0.7034 and earlier version 13 builds; version 12 is not affected according to Veeam.
Fixed release: 13.1.0.7233 or 13.0.2.7159.
Severity: Critical; CVSS 4.0 score 9.3.
Status: AMBER — high-consequence management-system exposure with fixes available, but no verified exploitation by the cutoff.

Chromium-family browsers on Linux

Issue: Reports of Chrome and Brave failing to start following updates on some Linux installations.
Affected scope: Not authoritatively established; available reports do not support a complete distribution, library, browser-build, or shared-dependency matrix.
Fixed release: No generally applicable vendor fix verified by the cutoff.
Severity: Operational reliability issue; no security severity assigned.
Status: WATCH — potentially disruptive where browsers provide access to administrative consoles, but evidence is insufficient to characterize a widespread common regression.

Outlook and Uncertainty


Next 24 hours

PaperCut is the principal intelligence-development area. Watch for a normal quality-assured maintenance release, new indicators, clarification of Release 3 deployment requirements, victim-scope reporting, public exploit material, or attribution. Release 3 should not be assumed to end the emergency response while the vendor describes the investigation as active.

Monitor CISA and Rockwell Automation for detailed publication of September 1 industrial-control-system advisories and assess them against actual plant inventories before assigning urgency.

German authorities may provide forensic findings concerning the Turnow-Preilack devices, evidence of reconnaissance, or links to other infrastructure incidents. Until then, claims identifying Russia, domestic activists, or another perpetrator remain speculative.

What is not known

The number of compromised PaperCut environments, duration of attacker access, full post-exploitation toolset, and identity of the operators remain unknown. The vendor’s indicators are not exhaustive, and their absence cannot establish system integrity.

For the Brandenburg attack, public information does not establish the perpetrators, whether other devices remain undiscovered, or whether the location formed part of a wider operation.

No authoritative evidence confirms exploitation of CVE-2026-65641. Absence of public reporting does not prove that private exploitation has not occurred.

Trigger for escalation

Additional PaperCut payloads, credential theft, lateral movement, destructive actions, compromise of connected identity systems, or exploitation bypassing Release 3 would expand containment and recovery requirements.

Confirmed exploitation of CVE-2026-65641, release of a reliable exploit, or evidence of successful relay into backup or virtualization control systems would move Veeam ONE to RED.

Discovery of related devices at other power facilities, evidence of coordinated reconnaissance, repeated conductive-line attacks, or verified cyber manipulation accompanying the German incident would elevate it from a localized sabotage event to a broader campaign assessment.


Jonathan Brown is a cybersecurity researcher and investigative journalist at bordercybergroup.com.

If you would like to support our work — useful, well-researched, ad-free cybersecurity intelligence — subscribe, comment, or buy us a coffee! Thanks.

© 2026 Border Cyber Group. All rights reserved.Sources — September 1, 2026

1. PaperCut NG/MF Exploitation Chain (CVE-2026-81578 / CVE-2026-82078)

PaperCut Official Urgent Security Advisory and Emergency Patch Release 3:
https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/

PaperCut Security Vulnerability Log:
https://www.papercut.com/kb/Main/security-vulnerability-log/

PaperCut Behind-the-Scenes Incident Account:
https://www.papercut.com/blog/news/behind-the-scenes-august-security-incident/

CISA: Two PaperCut Vulnerabilities Added to the Known Exploited Vulnerabilities Catalog:
https://www.cisa.gov/news-events/alerts/2026/08/31/cisa-adds-two-known-exploited-vulnerabilities-catalog

Huntress Technical Analysis and Observed Exploitation:
https://www.huntress.com/blog/papercut-actively-exploited

Rapid7 Emergency Threat Response Analysis:
https://www.rapid7.com/blog/post/etr-papercut-ng-mf-critical-zero-day-exploited-in-the-wild/

NIST National Vulnerability Database (CVE-2026-81578):
https://nvd.nist.gov/vuln/detail/CVE-2026-81578

NIST National Vulnerability Database (CVE-2026-82078):
https://nvd.nist.gov/vuln/detail/CVE-2026-82078

2. Turnow-Preilack Substation and Jänschwalde Power-Plant Sabotage

Reuters Incident Report:
https://www.reuters.com/world/german-police-probe-unexploded-incendiary-device-brandenburg-power-substation-2026-09-01/

Tagesschau Report on the Explosive Devices and Attempted Attack:
https://www.tagesschau.de/inland/sprengvorrichtung-umspannwerk-brandenburg-100.html

Rundfunk Berlin-Brandenburg Report on the Turnow-Preilack Devices:
https://www.rbb24.de/panorama/beitrag/2026/09/sprengvorrichtung-umspannwerk-brandenburg-kraftwerk-jaenschwalde.html

MDR Report on Damaged Transmission Lines and the Block B Shutdown:
https://www.mdr.de/nachrichten/sachsen/news-anschlag-kraftwerk-jaenschwalde-rakete%2Csprengvorrichtung-umspannwerk-100.html

Deutsche Welle Report on the Police and 50Hertz Response:
https://amp.dw.com/de/brandenburg-sprengvorrichtung-lka/a-78619084

Deutschlandfunk Report on the Jänschwalde Block B Operational Effect:
https://www.deutschlandfunk.de/sprengvorrichtungen-an-umspannwerk-in-brandenburg-gefunden-100.html

3. Veeam ONE SMB Authentication-Coercion Vulnerability (CVE-2026-65641)

Veeam Official Security Advisory (KB4905):
https://www.veeam.com/kb4905

Veeam ONE Security Fixes and Build History (KB4858):
https://www.veeam.com/kb4858

Veeam ONE 13 Release and Patch Information (KB4762):
https://www.veeam.com/kb4762

NIST National Vulnerability Database (CVE-2026-65641):
https://nvd.nist.gov/vuln/detail/CVE-2026-65641

Qualys Threat Analysis:
https://threatprotect.qualys.com/2026/08/31/veeam-released-patches-for-critical-vulnerability-cve-2026-65641/

Tenable Detection and Remediation Record:
https://www.tenable.com/plugins/nessus/339475

4. Chromium-Family Browser Operational Reliability Watch

Google Chrome 152 Stable Channel Release:
https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html

OpenSUSE Community Report — Chrome and Brave Failing After Updates:
https://forums.opensuse.org/t/after-chrome-update-8-21-it-does-not-run/195620/12

This final item remains a WATCH-level operational-reliability lead, not a confirmed common vendor regression. No authoritative source had established a shared root cause or universally applicable fix by the briefing cutoff.