What Changed
PaperCut NG and PaperCut MF are under active exploitation for a two-bug chain: CVE-2026-81578, a missing-authentication / improper access-control issue in the web management interface (CVSS ~8.8), and CVE-2026-82078, an unsafe dynamic class-loading flaw in database connection utilities (CVSS ~9.4). Chained, they give pre-authentication remote code execution under the PaperCut Application Server process.
PaperCut’s urgent bulletin landed August 27 after Huntress observed exploitation in customer environments as early as August 26. CVE identifiers and technical detail followed shortly after. Emergency Patch Release 1 shipped, then researchers and PaperCut’s own follow-on work with Huntress and watchTowr produced Emergency Patch Release 2 with additional hardening after bypass paths against the first fix were found. Release 2 covers NG/MF versions 24, 25, and 26 on Windows, Linux, and macOS. Installations on version 23 or earlier are directed to upgrade to a current major rather than wait for a backport.
CISA added both CVEs to the KEV catalog (reported August 31), with federal remediation expectations extending through mid-September under BOD 26-04 guidance. PaperCut has confirmed active exploitation and customer incidents. Public attribution remains sparse; the operational fact does not: print-management servers with a web console are back on the “internet-facing was a choice” list.
Track the Vulnerabilities That Actually Need Your Attention
The brief highlights new CVEs, KEV additions, active exploitation, and patch urgency without the usual noise.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
Why This Matters Operationally
Print servers are the classic underestimated domain citizen. PaperCut often runs with broad reach into Active Directory, print queues across sites, and sometimes payment or follow-me print integrations. RCE on that host is lateral movement wearing a help-desk costume. Organizations that “only expose it internally” still lose when VPN, flat networks, or a compromised jump box make “internal” a courtesy title.
The second emergency patch is the part operators should not skim. If your change ticket closed on Release 1, reopen it. Bypass research turned “we patched” into “we patched the first story.” Confirm the exact build against PaperCut’s current bulletin, not last week’s Slack screenshot.
What Defenders Should Verify First
- Confirm Emergency Patch Release 2 (or newer) on v24/v25/v26. Older majors should upgrade. Record the Application Server build from About → Version info.
- Assume exposure if the admin interface was reachable from untrusted networks during late August. Preserve Application Server logs, IDS/EDR alerts tied to the PaperCut host, and authentication anomalies before rotating evidence away.
- Hunt post-compromise. Unexpected processes spawned by the PaperCut service account, new scheduled tasks, unusual outbound connections, modified scripts under the PaperCut directory, and sudden configuration changes to drivers or database settings.
- Reduce reachability. Restrict the web admin interface to management networks; remove public exposure; require MFA where available; segment print infrastructure from tier-0 identity systems where practical.
- Rotate secrets the server could touch. Service account passwords, database credentials, LDAP binds, and any API keys integrated with PaperCut.
Source Context
- BleepingComputer: PaperCut releases second emergency patch for exploited flaws
- Horizon3: PaperCut RCE | CVE-2026-81578 & CVE-2026-82078
- Qualys ThreatPROTECT: PaperCut NG/MF Zero-day Vulnerability Exploited
- PaperCut urgent security bulletin (vendor): https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/
Print is supposed to be boring. When the print console starts executing Java bytecode for strangers, boredom is the goal you patch back toward—with Release 2, not vibes.
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
Free. Weekday mornings. Unsubscribe anytime.
Built from 100+ trusted cybersecurity sources.