< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

3 clusters · 16 sources · 9 days · First seen · Last updated

PaperCut software zero-day vulnerability exploitation

Overview

PaperCut, a print management software provider, identified and addressed two critical zero-day vulnerabilities in its NG and MF products. The flaws, identified as CVE-2026-81578 and CVE-2026-82078, allow unauthenticated attackers to bypass security controls and achieve remote code execution (RCE) by chaining authentication bypass with insecure dynamic class loading.

Security researchers from Huntress and watchTowr confirmed real-world exploitation, noting that attackers used the vulnerabilities to execute arbitrary Java code, profile host operating systems, and delete server logs to hide their presence. In response, PaperCut issued emergency patches. Following reports of potential patch bypasses, the company released a second emergency patch to provide additional hardening for versions 24, 25, and 26. Administrators were advised to restrict web access to the PaperCut Application Server to trusted IP addresses as a temporary mitigation.

Following the discovery of the exploit chain, CISA added these vulnerabilities to its Known Exploited Vulnerabilities Catalog. Additionally, Rapid7’s Metasploit Framework is incorporating an exploit module to assist authorized defenders in identifying vulnerable instances.

Recent reports from the Arctic Wolf Adversary Research Team indicate that attackers are specifically targeting educational institutions in the United States and Europe, ranging from K-12 schools to major universities. These actors use the vulnerabilities to steal credentials, create privileged accounts, and collect Windows registry hives. Attackers have been observed searching PaperCut configuration files for sensitive terms such as ‘password’, ‘secret’, and ‘token’ to expand their access.

Entities

PaperCut · WatchTowr · Huntress · Metasploit · Arctic Wolf

Timeline

  1. 7 days ago

    [TECHNOLOGY] 5 sources
    PaperCut vulnerabilities exploited to target schools and universities

    Attackers are exploiting PaperCut vulnerabilities (CVE-2026-81578 and CVE-2026-82078) to steal credentials from schools and universities across the US and Europe.

  2. 12 days ago

    [TECHNOLOGY] 9 sources
    PaperCut issues emergency patches for exploited zero-day vulnerabilities

    PaperCut has released emergency patches for its NG and MF software to address a critical zero-day vulnerability chain being actively exploited to achieve remote code execution.

  3. 15 days ago

    [TECHNOLOGY] 6 sources
    PaperCut issues emergency patches for exploited RCE vulnerabilities

    PaperCut is issuing emergency patches for its NG and MF software after hackers began exploiting two critical vulnerabilities to achieve unauthenticated remote code execution.

Sources

blogspan.net · borncity.com · cybernoz.com · cybersecuritydive.com · dev.to · flagthis.com · gotira.com · horizon3.ai · infoguerra.com.br · invitehealth.substack.com · ipaddisti.it · it-boltwise.de · it-connect.fr · thecannatareport.com · thecyberwire.com · thehackernews.com

This summary has been updated 2 times: see revision history