Back to all lessons
Awareness Lessons
last month

Chained PaperCut Flaws Enable Unauthenticated Remote Code Execution

Attackers are actively chaining two unpatched vulnerabilities in PaperCut NG and MF print management software to bypass authentication entirely and execute arbitrary Java code on affected servers — all without valid credentials. This attack chain is particularly dangerous because it combines an authentication bypass with a server configuration manipulation flaw, meaning a single missed patch exposes organizations to full system compromise. Print management servers are often overlooked in patch cycles despite being internet-facing and privileged within the network. The active reconnaissance activity observed suggests attackers are preparing for broader, more destructive follow-on actions such as lateral movement or data exfiltration.

Tactical Insight

Immediate actions

  • Apply the latest PaperCut NG/MF patches addressing CVE-2026-82078 and CVE-2026-81578 immediately across all instances.
  • Restrict public internet access to PaperCut admin interfaces by placing them behind a VPN or firewall allowlist.
  • Audit current PaperCut user accounts and revoke any unauthorized or dormant accounts discovered during attacker reconnaissance.

Detection measures

  • Monitor PaperCut server logs for unusual authentication attempts, configuration changes, or unexpected Java process execution.
  • Deploy IDS/IPS signatures targeting known exploitation patterns for these CVEs on network segments hosting print servers.
  • Alert on any new user account creation or OS enumeration activity originating from the PaperCut server process.

Long-term improvements

  • Include print management servers and other non-traditional IT assets in your formal vulnerability management and patch cadence program.
  • Implement network segmentation to isolate print servers from sensitive internal systems, limiting lateral movement if compromise occurs.
  • Establish an emergency patching SLA (e.g., 24–48 hours) for critical vulnerabilities with public exploit activity on internet-facing systems.