PaperCut NG and MF auth-bypass RCE chain (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
PaperCut NG and PaperCut MF are facing active exploitation of two newly patched flaws, allowing attackers to bypass authentication and reach remote code execution on susceptible instances. Huntress observed limited exploitation in two customer environments, including Base64-encoded commands and a Java `.class` file used for post-exploitation activity. PaperCut issued a second emergency patch with additional hardening, and exposed deployments should be removed from public access immediately.
Related Happenings
PaperCut customer confirmed compromise incidents
Incident
H score40
First: 27.08.2026 19:31
Last: 27.08.2026 19:31
Sources 1
How related:
PaperCut told BleepingComputer that the attacks appear limited and targeted, and that it is withholding details about post-exploitation activity while it continues its investigation.
About this happening:
PaperCut NG and PaperCut MF are under active zero-day exploitation, with confirmed customer incidents affecting all versions of the print management software....
PaperCut customer confirmed compromise incidents
IncidentHow related: PaperCut told BleepingComputer that the attacks appear limited and targeted, and that it is withholding details about post-exploitation activity while it continues its investigation.
About this happening: PaperCut NG and PaperCut MF are under active zero-day exploitation, with confirmed customer incidents affecting all versions of the print management software....
Latest development: 28.08.2026 22:08
PaperCut released Emergency Patch Release 2 for PaperCut NG/MF after researchers and watchTowr found multiple ways to bypass the initial fix for CVE-2026-82078 and CVE-2026-81578. The updated advisory says the flaws can be chained for authentication bypass and remote code execution on vulnerable servers, and it urges customers to install Release 2, upgrade Site Servers and secondary/print servers, restrict web access to trusted IP addresses, and look for post-exploitation signs such as pc-app.exe activity and missing or truncated server.log files.
PaperCut NG and MF actively exploited zero-day security flaw
Vulnerability
H score53
First: 27.08.2026 19:31
Last: 27.08.2026 19:31
Sources 1
About this happening:
PaperCut NG and PaperCut MF are facing active zero-day exploitation across all versions, putting Internet-exposed application servers at immediate compromise r...
PaperCut NG and MF actively exploited zero-day security flaw
VulnerabilityAbout this happening: PaperCut NG and PaperCut MF are facing active zero-day exploitation across all versions, putting Internet-exposed application servers at immediate compromise r...
Storm-1175 high-velocity zero-day and N-day intrusion campaign
Campaign
H score44
First: 07.04.2026 09:35
Last: 07.04.2026 09:35
Sources 1
About this happening:
Storm-1175 is running a high-velocity intrusion campaign that chains zero-day and N-day vulnerabilities to gain initial access to exposed systems, raising the risk...
Storm-1175 high-velocity zero-day and N-day intrusion campaign
CampaignAbout this happening: Storm-1175 is running a high-velocity intrusion campaign that chains zero-day and N-day vulnerabilities to gain initial access to exposed systems, raising the risk...
CISA BOD 22-01 federal remediation directive
Public Sector Action
H score89
First: 23.01.2026 20:47
Last: 23.01.2026 20:47
Sources 1
About this happening:
CISA required federal agencies covered by BOD 22-01 to apply available security updates or vendor-suggested mitigations, or stop using the affected products by Febru...
CISA BOD 22-01 federal remediation directive
Public Sector ActionAbout this happening: CISA required federal agencies covered by BOD 22-01 to apply available security updates or vendor-suggested mitigations, or stop using the affected products by Febru...
Timeline
-
28.08.2026 20:12 2 articles · 4h ago
Attackers run whoami, ver, and tasklist on a PaperCut server
Exploitation ObservedIn an incident recorded on August 27, 2026, threat actors used a different Java `.class` file against a PaperCut target to run `whoami & ver & tasklist`, showing post-exploitation activity after limited exploitation in customer environments.
Show sources
- Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication — thehackernews.com — 28.08.2026 20:12
- Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication — thehackernews.com — 28.08.2026 20:12
-
28.08.2026 20:12 2 articles · 4h ago
PaperCut issues second emergency patch for CVE-2026-82078 and CVE-2026-81578
Mitigation Patch UpdatePaperCut publicly disclosed CVE-2026-82078 and CVE-2026-81578 in PaperCut NG and PaperCut MF, said the fresh emergency fix adds additional hardening beyond the original emergency patch, and urged organizations to remove public exposure, restrict PaperCut Application Server web access to trusted IP addresses or a VPN, and apply the patch immediately.
Show sources
- Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication — thehackernews.com — 28.08.2026 20:12
- PaperCut releases second emergency patch for exploited flaws — www.bleepingcomputer.com — 28.08.2026 22:08