TL;DR — A pair of zero-day flaws in PaperCut NG/MF — the print-management software running in an estimated 70,000+ organisations — are being chained together in live attacks to take over servers with no login required. The critical half, CVE-2026-82078 (unsafe dynamic class loading, CVSS 9.4), gives remote code execution once the authentication-bypass half, CVE-2026-81578 (CVSS 8.8), opens the door. Huntress caught exploitation in the wild from 26 August 2026, PaperCut has now shipped a second emergency patch after researchers bypassed the first, and CISA added both to its KEV catalog on 31 August with a 14 September federal deadline. If you self-host PaperCut, patch to Emergency Patch Release 2 today.

CRITICALCVE-2026-82078 · CVE-2026-81578PaperCut NG/MF pre-auth RCE chainCVSS 4.09.4 Critical (RCE) · 8.8 High (auth bypass)VECTORCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:HWEAKNESSCWE-470 unsafe reflection · CWE-306 missing authAFFECTEDPaperCut NG/MF — all versions (fixes for v24/25/26)ATTACK VECTORNetwork — unauthenticated chain, no user interactionFIXED INEmergency Patch Release 2 — 28 Aug 2026 (v24/25/26)EXPLOITEDYes — in the wild (Huntress, from 26 Aug 2026)CISA KEVListed 31 Aug 2026 — patch by 14 Sep 2026
At-a-glance threat summary for the PaperCut NG/MF exploit chain (CVE-2026-82078 + CVE-2026-81578).

What Is the PaperCut NG/MF Flaw (CVE-2026-82078)?

PaperCut NG and PaperCut MF are print-management platforms that sit quietly in the middle of enterprise, education, healthcare and government networks — metering, releasing and charging for print jobs across thousands of devices. That role makes the PaperCut Application Server an unusually valuable target: it is widely deployed, frequently exposed to internal (and sometimes external) networks, and trusted by the print, identity and finance systems around it. PaperCut estimates the software runs in more than 70,000 organisations worldwide.

CVE-2026-82078 is the dangerous half of a two-bug chain. It is an unsafe dynamic class-loading flaw (CWE-470) in PaperCut’s database-connection utilities, rated 9.4 (Critical) on CVSS 4.0, that lets an attacker load and run arbitrary Java code on the server. On its own it needs privileges — but paired with CVE-2026-81578, an improper-access-control flaw (CWE-306, CVSS 8.8) in the web management interface that lets an unauthenticated attacker change server configuration, the two combine into a pre-authentication remote-code-execution chain. PaperCut currently considers all versions of NG and MF potentially impacted.

How the PaperCut Exploit Chain Works

In plain terms: an attacker who has never logged in tricks PaperCut into accepting an admin-only request, repoints one of its database settings at a server they control, and uses that trusted database connection to make PaperCut load and run their code — ending in operating-system command execution on the print server.

The entry point abuses how PaperCut’s Apache Tapestry-based web layer handles “complex direct” requests. By crafting a request that renders a public page (Error, Exception or Home) while quietly invoking an administrative component, an attacker reaches the ConfigEditor without authentication — that is CVE-2026-81578. From there they modify PaperCut’s external user-directory / database lookup settings to point at attacker-controlled JDBC credentials. The chain then abuses Apache Derby’s foreignViews feature to open an H2 JDBC connection, deploys a JavaScript-backed trigger via H2’s INIT statement, and finally executes OS commands through the bundled Nashorn engine — the crux of CVE-2026-82078. No credentials, no user interaction, just network reach to the server.

POST /app?service=direct/... HTTP/1.1   # Tapestry "complex direct" request → ConfigEditor (no auth)
# → set external-db lookup to attacker JDBC URL (H2/Derby foreignViews)
# → H2 INIT runs JavaScript trigger → Nashorn → OS command (RCE)

Why the “Chain” Framing Matters

There is a nuance worth being honest about. Neither bug is a one-shot, single-request RCE in isolation: CVE-2026-81578 alone only lets an unauthenticated attacker change configuration, and CVE-2026-82078 alone is rated with high privileges required (PR:H in its vector). The danger is entirely in the chain — the auth-bypass supplies the privilege the class-loading bug needs, collapsing “high privileges required” down to “anyone on the network.”

That is also why the first fix was not enough. After PaperCut’s initial Emergency Patch Release on 27 August, attack-surface firm watchTowr reproduced the vulnerabilities, found multiple patch bypasses and identified an additional authentication-bypass path — forcing a second, hardened patch a day later. When the exploitable surface is a chain, closing one link is not the same as closing the door.

The auth-bypass supplies the privilege the code-execution bug needs. Individually they look survivable; chained, they turn an unauthenticated request into shell on a print server that 70,000 organisations trust.

ATTACK CHAIN1Bypass authentication (CVE-2026-81578)A Tapestry “complex direct” request renders a public page while invoking an admin component.2Reach ConfigEditor unauthenticatedThe attacker POSTs to modify server configuration with no login required.3Point the DB lookup at an attacker serverExternal user-directory settings are rewritten to malicious JDBC credentials.4Load hostile classes via Derby → H2 (CVE-2026-82078)Derby foreignViews opens an H2 JDBC connection; H2’s INIT statement runs a JS trigger.5Execute OS commands via NashornThe bundled Nashorn engine runs shell commands — observed recon: whoami, ver, tasklist.
From one unauthenticated request to operating-system command execution on the PaperCut server.

Active Exploitation of CVE-2026-82078

This was a zero-day — exploited before a patch existed. Managed-detection firm Huntress observed exploitation in two customer environments from around 26 August 2026, describing the activity as limited and targeted rather than mass-scanning. In the observed intrusions, attackers used hex-encoded Java .class files as an RCE bridge and ran system-reconnaissance commands such as whoami, ver and tasklist — enumeration and, in some cases, log deletion, rather than immediate malware deployment or persistence. PaperCut is withholding further post-exploitation detail while its investigation continues, and the activity is not yet publicly attributed to a named group.

CISA added both CVE-2026-82078 and CVE-2026-81578 to its Known Exploited Vulnerabilities (KEV) catalog on 31 August 2026, setting a federal remediation deadline of 14 September 2026 for U.S. civilian agencies — a binding order for them and a strong signal for everyone else. PaperCut has a history worth remembering here: the 2023 PaperCut flaw (CVE-2023-27350) was seized on by ransomware operators including Cl0p and LockBit, so the runway between “targeted” and “commodity” exploitation of this chain may be short.

DISCLOSURE TIMELINE26 Aug 2026Huntress detects the chain exploited in the wild as a zero-day27 Aug 2026PaperCut issues an urgent bulletin and Emergency Patch Release 128 Aug 2026watchTowr finds patch bypasses; Emergency Patch Release 2 ships31 Aug 2026CISA adds both CVEs to the KEV catalog14 Sep 2026Federal KEV remediation deadline for U.S. civilian agencies
Exploited before a fix existed — and the first patch needed a second pass within a day.

Remediation & Mitigation: Patching PaperCut NG/MF

Apply Emergency Patch Release 2. PaperCut shipped a first emergency patch on 27 August 2026 and a hardened second release on 28 August after researchers bypassed the first. The second release is the one to deploy — the initial patch was bypassable via the Home page. The key actions:

  • Upgrade to Emergency Patch Release 2 now for PaperCut NG/MF versions 24, 25 or 26 on Windows, Linux and macOS. If you are on version 23 or earlier, upgrade to a supported, patched release rather than waiting for a back-port.
  • Do not settle for the first patch. If you deployed the 27 August emergency patch, apply the 28 August release on top of it — the original fix could be bypassed.
  • Do not wait for pressure to build. Both CVEs are already in CISA KEV with a 14 September federal deadline, and PaperCut is a proven ransomware magnet.

If you cannot patch immediately, reduce exposure:

  • Restrict access to the PaperCut web interface to trusted management IP ranges using host firewall rules or network ACLs, and ensure the Application Server is never directly internet-facing.
  • Lock down the admin and config surface — place PaperCut behind a VPN or reverse proxy that enforces authentication, and monitor the ConfigEditor and external-database settings for unexpected change.

After patching, hunt for prior compromise. Because this was exploited as a zero-day, patching does not undo an intrusion that already happened. Review PaperCut and web-server logs for anomalous POST requests to the app/config endpoints from late August 2026 onward, look for evidence of the observed recon commands (whoami, ver, tasklist), hex-encoded .class artefacts, and gaps or deletions in the logs themselves. Audit the external user-directory / database connection settings for unauthorised changes and reset them to known-good values, rotate any credentials the PaperCut service account can reach, and follow PaperCut’s published indicators of compromise as its investigation is updated.

Related ZeroDayHub Coverage

Enterprise middleware keeps turning out to be the soft underbelly of the network — trusted, widely deployed and reachable pre-authentication. See our write-ups of the Splunk Enterprise pre-auth RCE and the Kemp LoadMaster pre-auth RCE — different products, the same pattern of unauthenticated code execution against infrastructure organisations forget is exposed.

Sources & Further Reading

Leave a Reply

Trending

Discover more from Zerodayhub

Subscribe now to keep reading and get access to the full archive.

Continue reading