Summary
PaperCut Software published an emergency security advisory on August 27, 2026 confirming active zero-day exploitation of vulnerabilities in PaperCut NG and PaperCut MF, the print management platforms deployed across enterprise, education, and government environments worldwide. A second emergency patch superseding the first was released on August 28 after collaboration with Huntress and watchTowr identified additional hardening requirements. The two vulnerabilities, CVE-2026-81578 and CVE-2026-82078, can be chained to achieve unauthenticated remote code execution on any vulnerable PaperCut server. CVE-2026-81578, rated CVSS 8.8, is an improper access control vulnerability in the PaperCut NG/MF web management interface. Under specific conditions, an unauthenticated request can target administrative functions and trigger backend actions before access validation completes. This grants access to sensitive endpoints that should require authentication. CVE-2026-82078, rated CVSS 9.4, is an unsafe dynamic class loading vulnerability in PaperCut's database connection utilities. The application loads database driver classes based on configurable driver names without validating them against an approved allowlist. An attacker who can manipulate system configuration parameters through the authentication bypass in CVE-2026-81578 can use CVE-2026-82078 to execute arbitrary Java bytecode on the PaperCut server process. Huntress confirmed exploitation against two customer environments on August 26. The exploitation activity in one incident lasted under two minutes and left artifacts in the PaperCut server.log file. Shadowserver Foundation tracks approximately 1,000 internet-exposed PaperCut instances, primarily in North America and Europe. All versions of PaperCut NG and PaperCut MF are affected. PaperCut urges all customers to install Release 2 of the emergency patch even if they have already applied the original.
Timeline
| Date | Event |
|---|---|
| Aug 26, 2026 | Huntress observes exploitation against two customer environments — activity lasts under two minutes in first incident |
| Aug 27, 2026 | PaperCut publishes emergency security advisory — confirms active exploitation of all NG and MF versions |
| Aug 27, 2026 | PaperCut releases first emergency patch for v25 and v26 branches at 02:10 AEST |
| Aug 28, 2026 | CVE-2026-81578 and CVE-2026-82078 assigned — technical details published |
| Aug 28, 2026 | PaperCut releases Release 2 emergency patch with additional hardening after collaboration with Huntress and watchTowr |
| Aug 28, 2026 | 1,000 internet-exposed PaperCut instances tracked by Shadowserver Foundation — patch status unknown |
Domain Intelligence
| Domain | Score | DKIM | SPF | DMARC | Status |
|---|---|---|---|---|---|
| papercut.com | 61.59 | ✓ | ✓ | ✓ | Live |
Context
papercut.com scores 61.59 — a low-trust range score for a print management platform deployed in thousands of enterprise and educational institutions worldwide. PaperCut has now appeared in CISA's Known Exploited Vulnerabilities catalog three times. The 2023 exploitation of CVE-2023-27350 involved multiple threat actor groups including ransomware operators and drew a joint CISA/FBI advisory. The pattern of PaperCut being targeted in significant exploitation campaigns reflects its deployment profile: a widely installed, internet-accessible application server managing authentication and printing workflows across organizational networks. The two-emergency-patch sequence — a first release followed by a hardened second release within hours — reflects the ongoing nature of the investigation. Organizations should install Release 2, not Release 1, and treat any PaperCut server with internet exposure as a priority incident response case pending patch installation.
The Trust Observatory · thetrustobservatory.com · August 28, 2026