Find notable cyber news and cases, enriched with sources, timelines, and signals.

PaperCut NG and MF auth-bypass RCE chain (multiple vulnerabilities)

Vulnerability
First reported
Last updated
Happening score
H score 51
2 unique sources, 2 articles

Summary

Hide ▲

PaperCut NG and PaperCut MF are facing active exploitation of two newly patched flaws, allowing attackers to bypass authentication and reach remote code execution on susceptible instances. Huntress observed limited exploitation in two customer environments, including Base64-encoded commands and a Java `.class` file used for post-exploitation activity. PaperCut issued a second emergency patch with additional hardening, and exposed deployments should be removed from public access immediately.

Related Happenings

PaperCut customer confirmed compromise incidents

Incident
H score40 First: 27.08.2026 19:31 Last: 27.08.2026 19:31 Sources 1

How related: PaperCut told BleepingComputer that the attacks appear limited and targeted, and that it is withholding details about post-exploitation activity while it continues its investigation.

About this happening: PaperCut NG and PaperCut MF are under active zero-day exploitation, with confirmed customer incidents affecting all versions of the print management software....

Latest development: 28.08.2026 22:08

PaperCut released Emergency Patch Release 2 for PaperCut NG/MF after researchers and watchTowr found multiple ways to bypass the initial fix for CVE-2026-82078 and CVE-2026-81578. The updated advisory says the flaws can be chained for authentication bypass and remote code execution on vulnerable servers, and it urges customers to install Release 2, upgrade Site Servers and secondary/print servers, restrict web access to trusted IP addresses, and look for post-exploitation signs such as pc-app.exe activity and missing or truncated server.log files.

PaperCut NG and MF actively exploited zero-day security flaw

Vulnerability
H score53 First: 27.08.2026 19:31 Last: 27.08.2026 19:31 Sources 1

About this happening: PaperCut NG and PaperCut MF are facing active zero-day exploitation across all versions, putting Internet-exposed application servers at immediate compromise r...

Storm-1175 high-velocity zero-day and N-day intrusion campaign

Campaign
H score44 First: 07.04.2026 09:35 Last: 07.04.2026 09:35 Sources 1

About this happening: Storm-1175 is running a high-velocity intrusion campaign that chains zero-day and N-day vulnerabilities to gain initial access to exposed systems, raising the risk...

CISA BOD 22-01 federal remediation directive

Public Sector Action
H score89 First: 23.01.2026 20:47 Last: 23.01.2026 20:47 Sources 1

About this happening: CISA required federal agencies covered by BOD 22-01 to apply available security updates or vendor-suggested mitigations, or stop using the affected products by Febru...

Timeline

  1. 28.08.2026 20:12 2 articles · 4h ago

    Attackers run whoami, ver, and tasklist on a PaperCut server

    Exploitation Observed

    In an incident recorded on August 27, 2026, threat actors used a different Java `.class` file against a PaperCut target to run `whoami & ver & tasklist`, showing post-exploitation activity after limited exploitation in customer environments.

    Show sources
  2. 28.08.2026 20:12 2 articles · 4h ago

    PaperCut issues second emergency patch for CVE-2026-82078 and CVE-2026-81578

    Mitigation Patch Update

    PaperCut publicly disclosed CVE-2026-82078 and CVE-2026-81578 in PaperCut NG and PaperCut MF, said the fresh emergency fix adds additional hardening beyond the original emergency patch, and urged organizations to remove public exposure, restrict PaperCut Application Server web access to trusted IP addresses or a VPN, and apply the patch immediately.

    Show sources