Exploited PaperCut Vulnerabilities: New Details and Security Flaws

www.news4hackers.com-exploited-papercut-vulnerabilities-new-details-and-security-flaws-exploited-papercut-vulnerabilities-new-details-and-security-flaws

PaperCut Software has issued a second urgent update to address zero-day vulnerabilities being actively exploited in its NG and MF print management systems.

Overview of the Vulnerabilities

PaperCut Software has issued a second urgent update to address zero-day vulnerabilities being actively exploited in its NG and MF print management systems. The flaws allow unauthenticated attackers to bypass authentication mechanisms and execute arbitrary code remotely on affected systems. The vendor released a security advisory on August 27 and deployed the first emergency patch the following day for PaperCut NG/MF versions 25 and 26. A second update was released later that same day to address additional risks, including for version 24.

Key Vulnerabilities Identified

CVE-2026-81578

One, tracked as CVE-2026-81578, is a high-severity authentication bypass that enables remote, unauthenticated users to alter specific system configurations.

CVE-2026-82078

The second, CVE-2026-82078, involves unsafe dynamic class loading within database connection utilities. The advisory explained that compromising system configuration parameters could allow execution of arbitrary Java bytecode from the application classpath within the PaperCut server’s security context.

Security Implications and Response

Indicators of compromise (IoCs) related to the vulnerabilities have been published. Initial reports suggested a single flaw was being exploited, but subsequent analysis by PaperCut and security firms Huntress and WatchTowr confirmed two distinct zero-day vulnerabilities. WatchTowr identified multiple methods to bypass the initial patch and an additional authentication flaw, prompting the second update. Huntress confirmed attacks on at least two clients, with the first exploitation attempts detected on August 26. The firm reported that the activity centered on system reconnaissance, without evidence of secondary malware or further command-and-control interactions.

Current Status and Recommendations

The identity of the attackers and their objectives remain unknown. However, prior incidents involving PaperCut vulnerabilities highlight the risks, as CISA’s Known Exploited Vulnerabilities (KEV) catalog includes three other flaws, two of which have been linked to ransomware campaigns. ShadowServer Foundation data indicates approximately 1,000 PaperCut installations are accessible online, with the majority located in North America and Europe. The company continues to refine its advisory, emphasizing the need for immediate patching and monitoring for signs of compromise. Security teams are urged to review the provided IoCs and implement mitigations to prevent exploitation.



About Author

en_USEnglish