Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
3 clusters · 16 sources · 9 days · First seen · Last updated
PaperCut software zero-day vulnerability exploitation
Overview
PaperCut, a print management software provider, identified and addressed two critical zero-day vulnerabilities in its NG and MF products. The flaws, identified as CVE-2026-81578 and CVE-2026-82078, allow unauthenticated attackers to bypass security controls and achieve remote code execution (RCE) by chaining authentication bypass with insecure dynamic class loading.
Security researchers from Huntress and watchTowr confirmed real-world exploitation, noting that attackers used the vulnerabilities to execute arbitrary Java code, profile host operating systems, and delete server logs to hide their presence. In response, PaperCut issued emergency patches. Following reports of potential patch bypasses, the company released a second emergency patch to provide additional hardening for versions 24, 25, and 26. Administrators were advised to restrict web access to the PaperCut Application Server to trusted IP addresses as a temporary mitigation.
Following the discovery of the exploit chain, CISA added these vulnerabilities to its Known Exploited Vulnerabilities Catalog. Additionally, Rapid7’s Metasploit Framework is incorporating an exploit module to assist authorized defenders in identifying vulnerable instances.
Recent reports from the Arctic Wolf Adversary Research Team indicate that attackers are specifically targeting educational institutions in the United States and Europe, ranging from K-12 schools to major universities. These actors use the vulnerabilities to steal credentials, create privileged accounts, and collect Windows registry hives. Attackers have been observed searching PaperCut configuration files for sensitive terms such as ‘password’, ‘secret’, and ‘token’ to expand their access.
Entities
PaperCut · WatchTowr · Huntress · Metasploit · Arctic Wolf
Timeline
-
7 days ago
[TECHNOLOGY] 5 sourcesPaperCut vulnerabilities exploited to target schools and universitiesAttackers are exploiting PaperCut vulnerabilities (CVE-2026-81578 and CVE-2026-82078) to steal credentials from schools and universities across the US and Europe.
-
12 days ago
[TECHNOLOGY] 9 sourcesPaperCut issues emergency patches for exploited zero-day vulnerabilitiesPaperCut has released emergency patches for its NG and MF software to address a critical zero-day vulnerability chain being actively exploited to achieve remote code execution.
-
15 days ago
[TECHNOLOGY] 6 sourcesPaperCut issues emergency patches for exploited RCE vulnerabilitiesPaperCut is issuing emergency patches for its NG and MF software after hackers began exploiting two critical vulnerabilities to achieve unauthenticated remote code execution.
Sources
blogspan.net · borncity.com · cybernoz.com · cybersecuritydive.com · dev.to · flagthis.com · gotira.com · horizon3.ai · infoguerra.com.br · invitehealth.substack.com · ipaddisti.it · it-boltwise.de · it-connect.fr · thecannatareport.com · thecyberwire.com · thehackernews.com
This summary has been updated 2 times: see revision history