PaperCut NG/MF: The Print Server That Learned Remote Code Execution Again

By George Bailey   Published: 09/08/26   3 min read

What Changed

PaperCut NG and PaperCut MF are under active exploitation for a two-bug chain: CVE-2026-81578, a missing-authentication / improper access-control issue in the web management interface (CVSS ~8.8), and CVE-2026-82078, an unsafe dynamic class-loading flaw in database connection utilities (CVSS ~9.4). Chained, they give pre-authentication remote code execution under the PaperCut Application Server process.

PaperCut’s urgent bulletin landed August 27 after Huntress observed exploitation in customer environments as early as August 26. CVE identifiers and technical detail followed shortly after. Emergency Patch Release 1 shipped, then researchers and PaperCut’s own follow-on work with Huntress and watchTowr produced Emergency Patch Release 2 with additional hardening after bypass paths against the first fix were found. Release 2 covers NG/MF versions 24, 25, and 26 on Windows, Linux, and macOS. Installations on version 23 or earlier are directed to upgrade to a current major rather than wait for a backport.

CISA added both CVEs to the KEV catalog (reported August 31), with federal remediation expectations extending through mid-September under BOD 26-04 guidance. PaperCut has confirmed active exploitation and customer incidents. Public attribution remains sparse; the operational fact does not: print-management servers with a web console are back on the “internet-facing was a choice” list.

Why This Matters Operationally

Print servers are the classic underestimated domain citizen. PaperCut often runs with broad reach into Active Directory, print queues across sites, and sometimes payment or follow-me print integrations. RCE on that host is lateral movement wearing a help-desk costume. Organizations that “only expose it internally” still lose when VPN, flat networks, or a compromised jump box make “internal” a courtesy title.

The second emergency patch is the part operators should not skim. If your change ticket closed on Release 1, reopen it. Bypass research turned “we patched” into “we patched the first story.” Confirm the exact build against PaperCut’s current bulletin, not last week’s Slack screenshot.

What Defenders Should Verify First

Source Context

Print is supposed to be boring. When the print console starts executing Java bytecode for strangers, boredom is the goal you patch back toward—with Release 2, not vibes.

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.