TL;DR — A pair of zero-day flaws in PaperCut NG/MF — the print-management software running in an estimated 70,000+ organisations — are being chained together in live attacks to take over servers with no login required. The critical half, CVE-2026-82078 (unsafe dynamic class loading, CVSS 9.4), gives remote code execution once the authentication-bypass half, CVE-2026-81578 (CVSS 8.8), opens the door. Huntress caught exploitation in the wild from 26 August 2026, PaperCut has now shipped a second emergency patch after researchers bypassed the first, and CISA added both to its KEV catalog on 31 August with a 14 September federal deadline. If you self-host PaperCut, patch to Emergency Patch Release 2 today.
What Is the PaperCut NG/MF Flaw (CVE-2026-82078)?
PaperCut NG and PaperCut MF are print-management platforms that sit quietly in the middle of enterprise, education, healthcare and government networks — metering, releasing and charging for print jobs across thousands of devices. That role makes the PaperCut Application Server an unusually valuable target: it is widely deployed, frequently exposed to internal (and sometimes external) networks, and trusted by the print, identity and finance systems around it. PaperCut estimates the software runs in more than 70,000 organisations worldwide.
CVE-2026-82078 is the dangerous half of a two-bug chain. It is an unsafe dynamic class-loading flaw (CWE-470) in PaperCut’s database-connection utilities, rated 9.4 (Critical) on CVSS 4.0, that lets an attacker load and run arbitrary Java code on the server. On its own it needs privileges — but paired with CVE-2026-81578, an improper-access-control flaw (CWE-306, CVSS 8.8) in the web management interface that lets an unauthenticated attacker change server configuration, the two combine into a pre-authentication remote-code-execution chain. PaperCut currently considers all versions of NG and MF potentially impacted.
How the PaperCut Exploit Chain Works
In plain terms: an attacker who has never logged in tricks PaperCut into accepting an admin-only request, repoints one of its database settings at a server they control, and uses that trusted database connection to make PaperCut load and run their code — ending in operating-system command execution on the print server.
The entry point abuses how PaperCut’s Apache Tapestry-based web layer handles “complex direct” requests. By crafting a request that renders a public page (Error, Exception or Home) while quietly invoking an administrative component, an attacker reaches the ConfigEditor without authentication — that is CVE-2026-81578. From there they modify PaperCut’s external user-directory / database lookup settings to point at attacker-controlled JDBC credentials. The chain then abuses Apache Derby’s foreignViews feature to open an H2 JDBC connection, deploys a JavaScript-backed trigger via H2’s INIT statement, and finally executes OS commands through the bundled Nashorn engine — the crux of CVE-2026-82078. No credentials, no user interaction, just network reach to the server.
POST /app?service=direct/... HTTP/1.1 # Tapestry "complex direct" request → ConfigEditor (no auth)
# → set external-db lookup to attacker JDBC URL (H2/Derby foreignViews)
# → H2 INIT runs JavaScript trigger → Nashorn → OS command (RCE)
Why the “Chain” Framing Matters
There is a nuance worth being honest about. Neither bug is a one-shot, single-request RCE in isolation: CVE-2026-81578 alone only lets an unauthenticated attacker change configuration, and CVE-2026-82078 alone is rated with high privileges required (PR:H in its vector). The danger is entirely in the chain — the auth-bypass supplies the privilege the class-loading bug needs, collapsing “high privileges required” down to “anyone on the network.”
That is also why the first fix was not enough. After PaperCut’s initial Emergency Patch Release on 27 August, attack-surface firm watchTowr reproduced the vulnerabilities, found multiple patch bypasses and identified an additional authentication-bypass path — forcing a second, hardened patch a day later. When the exploitable surface is a chain, closing one link is not the same as closing the door.
The auth-bypass supplies the privilege the code-execution bug needs. Individually they look survivable; chained, they turn an unauthenticated request into shell on a print server that 70,000 organisations trust.
Active Exploitation of CVE-2026-82078
This was a zero-day — exploited before a patch existed. Managed-detection firm Huntress observed exploitation in two customer environments from around 26 August 2026, describing the activity as limited and targeted rather than mass-scanning. In the observed intrusions, attackers used hex-encoded Java .class files as an RCE bridge and ran system-reconnaissance commands such as whoami, ver and tasklist — enumeration and, in some cases, log deletion, rather than immediate malware deployment or persistence. PaperCut is withholding further post-exploitation detail while its investigation continues, and the activity is not yet publicly attributed to a named group.
CISA added both CVE-2026-82078 and CVE-2026-81578 to its Known Exploited Vulnerabilities (KEV) catalog on 31 August 2026, setting a federal remediation deadline of 14 September 2026 for U.S. civilian agencies — a binding order for them and a strong signal for everyone else. PaperCut has a history worth remembering here: the 2023 PaperCut flaw (CVE-2023-27350) was seized on by ransomware operators including Cl0p and LockBit, so the runway between “targeted” and “commodity” exploitation of this chain may be short.
Remediation & Mitigation: Patching PaperCut NG/MF
Apply Emergency Patch Release 2. PaperCut shipped a first emergency patch on 27 August 2026 and a hardened second release on 28 August after researchers bypassed the first. The second release is the one to deploy — the initial patch was bypassable via the Home page. The key actions:
- Upgrade to Emergency Patch Release 2 now for PaperCut NG/MF versions 24, 25 or 26 on Windows, Linux and macOS. If you are on version 23 or earlier, upgrade to a supported, patched release rather than waiting for a back-port.
- Do not settle for the first patch. If you deployed the 27 August emergency patch, apply the 28 August release on top of it — the original fix could be bypassed.
- Do not wait for pressure to build. Both CVEs are already in CISA KEV with a 14 September federal deadline, and PaperCut is a proven ransomware magnet.
If you cannot patch immediately, reduce exposure:
- Restrict access to the PaperCut web interface to trusted management IP ranges using host firewall rules or network ACLs, and ensure the Application Server is never directly internet-facing.
- Lock down the admin and config surface — place PaperCut behind a VPN or reverse proxy that enforces authentication, and monitor the ConfigEditor and external-database settings for unexpected change.
After patching, hunt for prior compromise. Because this was exploited as a zero-day, patching does not undo an intrusion that already happened. Review PaperCut and web-server logs for anomalous POST requests to the app/config endpoints from late August 2026 onward, look for evidence of the observed recon commands (whoami, ver, tasklist), hex-encoded .class artefacts, and gaps or deletions in the logs themselves. Audit the external user-directory / database connection settings for unauthorised changes and reset them to known-good values, rotate any credentials the PaperCut service account can reach, and follow PaperCut’s published indicators of compromise as its investigation is updated.
Related ZeroDayHub Coverage
Enterprise middleware keeps turning out to be the soft underbelly of the network — trusted, widely deployed and reachable pre-authentication. See our write-ups of the Splunk Enterprise pre-auth RCE and the Kemp LoadMaster pre-auth RCE — different products, the same pattern of unauthenticated code execution against infrastructure organisations forget is exposed.
Sources & Further Reading
- PaperCut — Urgent security advisory (27 Aug 2026) and emergency patches
- Rapid7 — PaperCut NG/MF critical zero-day exploited in the wild (CVSS, vectors, attack chain)
- BleepingComputer — PaperCut releases second emergency patch for exploited flaws
- The Hacker News — PaperCut zero-day exploited in attacks, affecting all NG and MF versions
- Qualys ThreatPROTECT — PaperCut NG/MF zero-day exploited (CVE-2026-82078 & CVE-2026-81578)
- SC Media — PaperCut issues emergency patches for actively exploited critical vulnerability
- Help Net Security — PaperCut NG/MF vulnerabilities exploited in zero-day attacks
- CISA — Known Exploited Vulnerabilities Catalog





Leave a Reply