Security advisories

PaperCut Discloses Zero-Day Vulnerabilities (CVE-2026-82078 and CVE-2026-81578)

August 28, 2026

3 MINS READ

THE THREAT

On August 27th, 2026, PaperCut Software disclosed two zero-day vulnerabilities, impacting its PaperCut NG and PaperCut MF products. The vulnerabilities are CVE-2026-82078 (CVSS: 9.4) and CVE-2026-81578 (CVSS: 8.8), which can be leveraged by an unauthenticated attacker to modify system configurations and potentially lead to Remote Code Execution (RCE). PaperCut noted that they are "aware of confirmed customer incidents" involving the flaws and are investigating active exploitation.

PaperCut has released emergency patches for both PaperCut NG and PaperCut MF in versions 24, 25, and 26, and recommends that any Internet-facing PaperCut NG/MF Application Server be restricted to trusted IP addresses only.

What we're doing about it

What you should do about it

Additional information

CVE-2026-81578 is an improper access control vulnerability within the web management interface of both PaperCut NG and PaperCut MF, which can allow an unauthenticated remote attacker to modify system configurations. CVE-2026-82078 is an unsafe dynamic class loading flaw within the database connection utilities of the PaperCut applications, that can result in arbitrary execution of Java code. Based on the available information, the vulnerabilities could potentially be chained together to grant an unauthenticated attacker RCE capabilities.

Huntress identified exploitation of the flaws as early as August 26th, where review of PaperCut's log files revealed base-64 encoded reconnaissance commands that were performed by the attacker. Although PaperCut stated that they were aware of exploitation, no additional details were shared to confirm if these were the attacks identified by Huntress, or if further exploitation is ongoing.

At the time of writing, technical details on the vulnerabilities are limited, and there is no publicly available Proof-of-Concept (PoC) exploit code. However, Huntress noted that they were able to create a working PoC for the exploit chain. This suggests that other researchers or threat actors will likely also be able to create and release PoC in the near future, which would likely be weaponized within attacks leading to widespread exploitation.

To mitigate risk, organizations utilizing the impacted software should ensure that access to the PaperCut Application Server is restricted to trusted IP addresses only and ensure that all relevant patches are applied. Following the initial patch release, PaperCut provided another update, referred to as Emergency Patch (Release 2), which includes "additional hardening." watchTowr Labs posted that they are working with PaperCut to resolve "bypasses" within the released patches, suggesting that the initial fixes for the flaws were not sufficient, and organizations should ensure that both patches are applied. PaperCut states that they will publish "validated" indicators and further guidance as they become available.

References

  1. https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/
  2. https://www.huntress.com/blog/papercut-actively-exploited
  3. https://x.com/watchtowrcyber/status/2093345328170758218
Back to Security Advisories

Speak With A Security Expert Now

TALK TO AN EXPERT
View Most Recent Advisories