Back to Feed
VulnerabilitiesAug 31, 2026

More Details Emerge on Exploited PaperCut Vulnerabilities

PaperCut releases second patch for exploited zero-day vulnerabilities CVE-2026-82078 and CVE-2026-81578.

Summary

PaperCut has issued a second emergency patch for two zero-day vulnerabilities affecting its NG and MF print management solutions. These flaws, tracked as CVE-2026-82078 and CVE-2026-81578, allow unauthenticated attackers to bypass security and execute remote code. Security firms Huntress and WatchTowr confirmed exploitation, with initial attacks observed on August 26, targeting system discovery. The full scope of the threat actor and their motivations remain unclear.

Full text

PaperCut Software has released a second emergency patch for zero-day vulnerabilities exploited against users of its NG and MF print management solutions as more information has emerged about the flaws and their exploitation. The zero-days can be exploited by unauthenticated attackers to bypass authentication and achieve remote code execution on affected PaperCut NG/MF instances. The vendor issued a security bulletin on August 27 and released the first emergency patch the next day for PaperCut NG/MF versions 25 and 26. The second emergency patch was released later the same day to deliver additional hardening, including for version 24. Indicators of compromise (IoCs) have also been made available. It was initially believed that attackers had exploited a single vulnerability, but PaperCut and the security firms monitoring the situation, Huntress and WatchTowr, revealed that two zero-days have been exploited. One of them is tracked as CVE-2026-81578 and described as a high-severity authentication bypass that allows a remote, unauthenticated attacker to modify certain system configurations. The second flaw, CVE-2026-82078, is a critical issue related to unsafe dynamic class loading in the database connection utilities.Advertisement. Scroll to continue reading. “If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process,” PaperCut explained in its advisory. The company continues to update its advisory, noting on Sunday that its teams are still working on an official release that patches CVE-2026-82078 and CVE-2026-81578. WatchTowr reported discovering multiple patch bypasses and an additional authentication bypass flaw, which triggered the second emergency patch. Huntress has seen attacks against at least two customers, with the first exploitation attempts seen on August 26. “Observed activity focused on system discovery,” Huntress noted. “We have not observed secondary malware, further command-and-control traffic, or additional persistence or post-exploitation from the recovered payload.” It’s currently unclear who is behind the attacks exploiting the PaperCut NG/MF zero-days or what their motivation is. Threat actors exploiting PaperCut NG/MF vulnerabilities is not unheard of. CISA’s Known Exploited Vulnerabilities (KEV) catalog includes three other flaws, two of which have been exploited in ransomware attacks. Roughly 1,000 PaperCut instances are currently exposed to the internet, a majority in North America and Europe, according to data from the ShadowServer Foundation. Related: OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems Related: Recent Citrix NetScaler Vulnerability Exploited in the Wild Related: Adobe and Nvidia Patch Dozens of Vulnerabilities Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Australia Arrests 2 Alleged TeamPCP HackersOpenAI Agents Coordinated via Makeshift Message Board Ahead of Hugging Face HackCyberattack Causes Global Disruption at Boston ScientificUS Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure AttacksRecent Citrix NetScaler Vulnerability Exploited in the WildAI Speeds Up Malware Development, Not Its Success Rate: AnalysisAdobe and Nvidia Patch Dozens of VulnerabilitiesCISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks Latest News Hasbro Data Breach Exposed Employee Personal InformationIn Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker SanctionsATF Confirms Cyber Incident After Ransomware Group Claims AttackOpenAI Agents Exploited Linux Kernel Flaw on Company’s Own SystemsTech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense PledgeThink You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco SaysPaperCut Releases Emergency Patch for Exploited Zero-DayTrump Order Aims to Block Foreign Backdoors in US Power Grid Gear Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveSocial engineering protection company Doppel has promoted Alyssa Smrekar to Chief Marketing Officer.Naveen Bhateja has been appointed Chief People Officer at HackerOne.The Department of War has appointed Sonu Shankar as Principal Deputy Chief Information Officer.More People On The MoveExpert Insights The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Rethinking Application Security for the AI Era As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. (Joshua Goldfarb) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • cve — CVE-2026-82078
  • cve — CVE-2026-81578

Entities

PaperCut NG/MF (product)PaperCut (vendor)Unknown (threat_actor)Unknown (campaign)