[REVISION HISTORY]
PaperCut software zero-day vulnerability exploitation
Updated 2 times since CLSTR started tracking revisions of this situation.
What changed
2026-09-01 08:13 UTC → 2026-09-05 09:41 UTC ·
added
removed
PaperCut, a print management software provider, identified and addressed two critical zero-day vulnerabilities in its NG and MF products. The flaws, identified as CVE-2026-81578 and CVE-2026-82078, allow unauthenticated attackers to bypass security controls and achieve remote code execution (RCE) by chaining authentication bypass with insecure dynamic class loading. Security researchers from Huntress and watchTowr confirmed real-world exploitation, noting that attackers used the vulnerabilities to execute arbitrary Java code, profile host operating systems, and delete server logs to hide their presence. In response, PaperCut issued emergency patches. Following reports of potential patch bypasses, the company released a second emergency patch to provide additional hardening for versions 24, 25, and 26. Administrators were advised to restrict web access to the PaperCut Application Server to trusted IP addresses as a temporary mitigation. Following the discovery of the exploit chain, CISA added these vulnerabilities to its Known Exploited Vulnerabilities Catalog. Additionally, Rapid7’s Metasploit Framework is incorporating an exploit module to assist authorized defenders in identifying vulnerable instances. The Recent reports from the Arctic Wolf Adversary Research Team indicate that attackers are specifically targeting educational institutions in the United States and Europe, ranging from K-12 schools to major universities. These actors use the vulnerabilities pose a high risk to organizations, including schools steal credentials, create privileged accounts, and government agencies, particularly those with application servers exposed collect Windows registry hives. Attackers have been observed searching PaperCut configuration files for sensitive terms such as ‘password’, ‘secret’, and ‘token’ to the public internet. expand their access.
Versions
- 2026-09-05 09:41 UTC PaperCut software zero-day vulnerability exploitation
- 2026-09-01 08:13 UTC PaperCut software zero-day vulnerability exploitation
- 2026-08-31 08:35 UTC PaperCut software zero-day vulnerability exploitation
Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.