Multiples vulnérabilités dans Papercut (28 août 2026)
Multiple vulnerabilities have been discovered in Papercut MF and NG, allowing attackers to bypass security policies and execute arbitrary code remotely. The vulnerabilities are actively being exploited, and Papercut recommends applying security patches immediately. The CERT-FR urges swift action to mitigate the risk.
Multiple vulnerabilities exist within Papercut MF and NG, presenting a significant security risk. These flaws enable attackers to circumvent security policies and execute code remotely. Papercut has indicated that these vulnerabilities are currently being actively exploited. The vulnerabilities stem from a lack of proper input validation, specifically related to SQL injection attempts targeting Card/ID number data from external databases. The security bulletin highlights the need to apply the latest security patches to address these issues. Papercut recommends restricting access to the application server to trusted IP addresses as a temporary mitigation measure. The CERT-FR advises monitoring for suspicious activity, particularly related to pc-app.exe, and checking for missing, truncated, or deleted server.log files, as well as searching for specific error messages within the logs (e.g., 'ERROR No suitable driver found for jdbc:no:x' or 'ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST'). It is important to note that the absence of these indicators does not guarantee that the vulnerabilities are not being exploited. The security bulletin provides links to the original security advisory and related blog posts from Huntress and Rapid7, and includes the CVE identifiers CVE-2026-81578 and CVE-2026-82078.