Today’s Field Note

Two print servers and a package registry are the story today, and all three are the kind of software that sits quietly in the middle of everything. PaperCut NG and MF zero-days (CVE-2026-82078 and CVE-2026-81578) have escalated from patched flaws to active intrusions with confirmed data theft, and CISA has added both to the KEV catalog. Separately, JFrog Artifactory’s authentication bypass CVE-2026-82329 is being exploited in the wild, exploitation starting just days after public disclosure, which is roughly how long it takes attackers to read a changelog. Artifactory is a supply-chain chokepoint: a foothold there means access to your build artifacts and credentials, not just one box. None of this is exotic, which is exactly why it works.

Today’s Action

  • Patch PaperCut NG/MF now and treat any unpatched instance as already compromised; hunt for reverse-tunnel activity and unexpected admin sessions before you close the door.
  • Upgrade JFrog Artifactory to the fixed release addressing CVE-2026-82329, and rotate any tokens, API keys, or CI/CD credentials that instance could reach.
  • Confirm both PaperCut CVEs against your KEV-driven remediation SLA; the federal deadline is your excuse to move today.
  • Pull PaperCut and Artifactory management interfaces off the public internet entirely, then verify with an external scan rather than a config review.
  • Review build pipeline logs for anomalous artifact pulls or new service accounts created around the disclosure window.

Resources

Verified links for the CVEs mentioned above: official advisories, and a live search for public detection rules if any exist yet.

Patch Tuesday is a schedule; exploitation is not.

More: Issues · Field Notes · RTFM


Daily field notes, weekly Issues. Follow @itsalreadywhen or subscribe via RSS.