PaperCut has issued urgent security updates to combat two critical zero-day vulnerabilities allowing remote code execution. Attackers are currently targeting print management systems globally, prompting immediate action from IT administrators.

  • Two critical zero-day vulnerabilities (CVE-2026-81578 and CVE-2026-82078) are being exploited in the wild.
  • Attackers can bypass authentication to achieve Remote Code Execution (RCE) on PaperCut NG/MF instances.
  • Emergency patches have been released for versions 24, 25, and 26 to harden system security.

PaperCut Software has escalated its defense strategy by releasing a second emergency patch following the discovery of sophisticated zero-day exploits targeting its NG and MF print management solutions. The vulnerabilities, which allow unauthenticated attackers to gain deep access to affected systems, have put thousands of organizations at risk, particularly those with internet-exposed print servers.

Initially, security researchers believed a single flaw was responsible. However, combined analysis from PaperCut and cybersecurity firms Huntress and WatchTowr revealed a dual-threat scenario. The first vulnerability, CVE-2026-81578, is a high-severity authentication bypass that enables remote attackers to manipulate system configurations. The second, CVE-2026-82078, is a critical flaw involving unsafe dynamic class loading in database connection utilities.

The synergy between these two flaws is particularly dangerous. By leveraging the authentication bypass, an attacker can modify system parameters, which then allows the execution of arbitrary Java bytecode under the security context of the PaperCut server process. This effectively gives the attacker full control over the server.

Why This Matters

BozokMedia analysis shows that print management software is often an overlooked vector in corporate security audits. Because these systems often have broad network permissions to communicate with various endpoints, a compromise here can serve as a beachhead for lateral movement within a corporate network. The fact that roughly 1,000 instances remain exposed to the internet—mostly in North America and Europe—creates a massive attack surface for state-sponsored actors or ransomware groups.

The ability to achieve remote code execution without authentication is the 'holy grail' for attackers, making immediate patching non-negotiable for enterprise security.

The timeline of the attack suggests a rapid exploitation cycle. Huntress reported seeing active attempts as early as August 26, focusing primarily on system discovery. While secondary malware or command-and-control traffic has not yet been widely observed, the potential for ransomware deployment remains high, given that previous PaperCut flaws have been linked to such attacks in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability ID Severity Primary Impact Mechanism
CVE-2026-81578 High Authentication Bypass System Configuration Modification
CVE-2026-82078 Critical Remote Code Execution Unsafe Dynamic Class Loading

WatchTowr's involvement was pivotal, as they discovered multiple patch bypasses and an additional authentication flaw, which forced PaperCut to release the second, more robust hardening patch. Organizations are urged to apply these updates immediately and monitor for the provided Indicators of Compromise (IoCs).

Did You Know?: Print servers are frequently targeted by hackers because they often run with high system privileges but rarely receive the same level of security monitoring as primary web servers.

Frequently Asked Questions

Q1: Which versions of PaperCut are affected?
Versions 24, 25, and 26 of PaperCut NG/MF are affected, and emergency patches have been issued for all of them.

Q2: What should I do if my server is internet-exposed?
Immediately restrict internet access to the PaperCut instance and apply the latest emergency patches provided by the vendor.