news.mlab.sh
Back to the feed
threat-intel

More Details Emerge on Exploited PaperCut Vulnerabilities

CriticalCVSS 9.4
Summary

PaperCut Software has released a second emergency patch to address two zero-day vulnerabilities exploited by attackers, allowing remote code execution and bypassing authentication. The vulnerabilities have been actively exploited, with approximately 1,000 PaperCut instances exposed, primarily in North America and Europe. The vendor is continuing to investigate and release updates.

PaperCut Software has released a second emergency patch for zero-day vulnerabilities affecting its NG and MF print management solutions. The vulnerabilities allow unauthenticated attackers to bypass authentication and achieve remote code execution on affected PaperCut NG/MF instances. The vendor initially issued a security bulletin on August 27 and released the first emergency patch the next day for versions 25 and 26.

It was initially believed that a single vulnerability was being exploited, but PaperCut and security firms Huntress and WatchTowr have revealed that two zero-days are actively being used. CVE-2026-81578 is a high-severity authentication bypass, enabling remote modification of system configurations. CVE-2026-82078 is a critical issue related to unsafe dynamic class loading in the database connection utilities, allowing arbitrary Java bytecode execution under the PaperCut server process.

WatchTowr reported discovering multiple patch bypasses and an additional authentication bypass flaw, triggering the second emergency patch. Huntress has observed attacks against at least two customers, beginning on August 26, with initial activity focused on system discovery. No secondary malware, command-and-control traffic, or post-exploitation activity has been detected.

CISA’s Known Exploited Vulnerabilities (KEV) catalog includes three other PaperCut vulnerabilities, two of which have been exploited in ransomware attacks. Approximately 1,000 PaperCut instances are currently exposed to the internet, with a majority located in North America and Europe.

Related: OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems

Related: Recent Citrix NetScaler Vulnerability Exploited in the Wild

Related: Adobe and Nvidia Patch Dozens of Vulnerabilities

Read the full article at SecurityWeek