The cyber threat environment heading into September 2026 demands immediate action from network administrators. Threat actors are exploiting brand-new software flaws and simultaneously hunting for forgotten, decade-old vulnerabilities on enterprise networks. Incident telemetry captured today confirms active exploitation of critical zero-days in enterprise print servers, severe bugs in artificial intelligence platforms, and a massive push by federal authorities to clean up legacy hardware.
Administrators must verify their asset inventories and patch exposed systems before automated botnets weaponize these flaws. Reading official alerts from the Cybersecurity and Infrastructure Security Agency gives defenders the exact technical specifications needed to secure vulnerable networks right now.
Active Exploitation of PaperCut Zero-Days
Print management software remains a highly attractive target for cybercriminals. Security researchers confirmed that attackers are actively exploiting two zero-day vulnerabilities in PaperCut NG and MF servers. Threat actors chain together an access control flaw, tracked as CVE-2026-81578, with a dangerous database vulnerability, CVE-2026-82078.
By combining these two bugs, an unauthenticated attacker achieves full remote code execution on the target server. The attackers use this access to plant hidden remote access tools deep inside the corporate network. Once established, they can steal documents, monitor internal communications, or deploy ransomware across connected devices. Administrators must restrict web access to the PaperCut Application Server immediately, allowing only trusted IP addresses to connect until they apply the latest vendor patch. Tracking these intrusion methods through our active virus campaigns database helps defenders spot early warning signs before data theft occurs.
The Resurgence of Decade-Old Vulnerabilities
Zero-day exploits grab headlines, but cybercriminals still rely heavily on forgotten infrastructure. Late last week, federal authorities added six active threats to the Known Exploited Vulnerabilities catalog. Surprisingly, the list includes a Microsoft SQL Server remote code execution flaw from 2019 and a Red Hat privilege escalation bug that traces back to 2015.
Hackers do not always need fresh exploits when decade-old code still works. Scanning tools operate at a massive scale today, allowing attackers to find the one legacy server a company forgot to patch five years ago. This concept of vulnerability debt creates a severe blind spot for IT departments. Security teams must scan their entire network infrastructure, including retired projects and shadow IT assets, to guarantee no legacy systems remain exposed to the public internet. Checking the latest hardware patch notes on the National Vulnerability Database helps you apply the correct security updates for these older operating systems.

ServiceNow AI Platform Faces Critical Flaws
The push to integrate artificial intelligence into enterprise workflows introduces severe security risks. ServiceNow recently addressed three critical vulnerabilities inside its AI Platform. Tracked as CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, all three flaws carry a maximum severity score of 10.0.
These vulnerabilities involve code injection and broken access controls. An unauthenticated attacker can exploit these flaws to execute malicious scripts, escalate their privileges, and modify sensitive data stored within the AI instance. As companies feed more proprietary data into these machine-learning models, securing the hosting platforms becomes a top priority.
September 1 Active Threat Data
Security teams must prioritize the immediate dangers circulating today. The table below outlines the primary targets and methods of these active threats.
| Threat Target / Flaw | Primary Attack Method | Main Operational Goal |
| PaperCut Servers | CVE-2026-81578 access bypass | Deploying remote access tools and stealing files |
| Microsoft SQL Server | CVE-2019-1068 exploit | Using forgotten legacy flaws for remote code execution |
| ServiceNow AI | CVE-2026-18885 code injection | Modifying AI instances and escalating privileges |
| Critical Infrastructure | QScan botnet infections | Concealing network intrusions from federal agencies |
Steps to Secure Your Network Today
Administrators must enforce strict security protocols to survive this environment. Never assume your servers are safe using default firewall configurations. The ongoing attacks on print management tools and legacy databases prove that modern threats easily bypass standard defenses.
Update all external software immediately. Prioritize patches for internet-facing systems like PaperCut servers and AI development platforms. Run a comprehensive network scan to identify and isolate any legacy hardware running outdated operating systems. Implementing strong multi-factor authentication across all administrative accounts prevents attackers from using stolen credentials to move laterally. Reviewing independent cybersecurity threat reports provides your team with the analytical data necessary to harden your infrastructure against these advanced extortion groups.