< Back to all clusters
[TECHNOLOGY] · 6 sources

started · updated

PaperCut issues emergency patches for exploited RCE vulnerabilities

PaperCut, a print management software provider, has issued urgent security advisories following the active exploitation of two critical vulnerabilities in its NG and MF products. The flaws, identified as CVE-2026-81578 and CVE-2026-82078, allow unauthenticated attackers to bypass security controls and achieve remote code execution (RCE) by chaining an authentication bypass with insecure dynamic class loading.

Security researchers from Huntress and watchTowr have confirmed real-world exploitation. Attackers have been observed using these vulnerabilities to execute arbitrary Java code, profile host operating systems, and delete server logs to conceal their activities. The vulnerabilities carry high severity scores, with CVE-2026-82078 rated at 9.4 and CVE-2026-81578 rated at 8.8.

PaperCut has released an emergency patch (Release 2) for versions 25 and 26, recommending that all customers install it even if they previously applied an earlier fix. For version 24, a fix is still in development. As a temporary mitigation, the company advises administrators to restrict web access to the PaperCut Application Server to trusted IP addresses only via firewalls or network access controls.

Entities

Huntress · PaperCut · WatchTowr