More Details Emerge on Exploited PaperCut Vulnerabilities
PaperCut Software released a second emergency patch for two zero-day vulnerabilities (CVE-2026-81578 and CVE-2026-82078) in its NG/MF print management solutions that allow unauthenticated remote code execution CVE-2026-81578 is a high-severity authentication bypass enabling attackers to modify system configurations, while CVE-2026-82078 is a critical flaw involving unsafe dynamic class loading in database connection utilities WatchTowr discovered additional patch bypasses and an extra authentica
Analysis
TL;DR
- PaperCut Software released a second emergency patch for two zero-day vulnerabilities (CVE-2026-81578 and CVE-2026-82078) in its NG/MF print management solutions that allow unauthenticated remote code execution
- CVE-2026-81578 is a high-severity authentication bypass enabling attackers to modify system configurations, while CVE-2026-82078 is a critical flaw involving unsafe dynamic class loading in database connection utilities
- WatchTowr discovered additional patch bypasses and an extra authentication bypass flaw, prompting the second emergency patch release
- Huntress reported active exploitation since August 26, with observed activity focused on system discovery but no secondary malware or persistence mechanisms detected
- Approximately 1,000 PaperCut instances remain exposed to the internet, predominantly in North America and Europe
Why It Matters
This incident highlights the critical risk posed by unpatched print management software exposed to the internet, as unauthenticated attackers can achieve full remote code execution with no user interaction required. The rapid emergence of patch bypasses discovered by WatchTowr underscores the importance of continuous security validation even after emergency patches are released. Organizations relying on PaperCut NG/MF must treat this as an urgent priority given the active exploitation in the wild.
Technical Details
- CVE-2026-81578: A high-severity authentication bypass vulnerability that allows remote, unauthenticated attackers to modify certain system configurations on PaperCut NG/MF instances, potentially leading to further exploitation
- CVE-2026-82078: A critical vulnerability involving unsafe dynamic class loading in database connection utilities; when combined with the authentication bypass, it enables execution of arbitrary Java bytecode under the PaperCut server process security context
- The initial patch released on August 28 for versions 25 and 26 was found to have multiple bypasses, leading to a second emergency patch later the same day that also addressed version 24
- PaperCut's advisory explains the attack chain: configuration manipulation via the auth bypass enables arbitrary Java bytecode execution on the application classpath under the server's security context
- Indicators of compromise (IoCs) have been made available by the vendor, and the company continues to work toward an official release that fully patches both vulnerabilities
Industry Insight
- Organizations should immediately audit their PaperCut NG/MF deployments for internet exposure and apply the latest emergency patch, while also monitoring for the additional authentication bypass discovered by WatchTowr that was not covered in the initial patch
- This incident reinforces the need for defense-in-depth strategies for internet-facing enterprise software, including network segmentation, web application firewalls, and regular vulnerability scanning, as print management tools are increasingly targeted by threat actors
- The pattern of patch bypasses discovered shortly after emergency releases suggests that vendors should adopt bug bounty programs and coordinated disclosure practices, while security teams should treat first-generation patches with caution and validate fixes in isolated environments before full deployment
Disclaimer: The above content is generated by AI and is for reference only.