Security News

Cybersecurity news aggregator

CRITICAL Vulnerabilities SC Media

PaperCut issues emergency patches for actively exploited critical vulnerability

PaperCut has issued emergency patches for two actively exploited vulnerabilities, CVE-2026-82078 (CVSS 9.4) and CVE-2026-81578 (CVSS 8.8), which can be chained for unauthenticated remote code execution. The attack involves an unauthenticated attacker using the access control flaw to modify server configuration, which then triggers unsafe dynamic class loading to execute arbitrary Java code. Affected versions are PaperCut MF and NG versions prior to 20.1.8, versions 21.0.0 through 21.2.11, and versions 22.0.0 through 22.1.0, requiring an upgrade to versions 20.1.8, 21.2.12, or 22.1.1 respectively.
Read Full Article →

Vulnerability Management , Patch/Configuration Management PaperCut issues emergency patches for actively exploited critical vulnerability August 28, 2026 Share By Laura French Print management service PaperCut released emergency patches for two flaws in its software that can be chained together for unauthenticated remote code execution (RCE), which were already exploited in the wild, Huntress reported Thursday. The vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 affect all versions of PaperCut NG and PaperCut MF software prior to Aug. 27, 2026, with emergency patches available for NG/MF versions 24, 25 and 26 on Windows, Linux and macOS. The latest versions of the emergency patches were published Aug. 28 (Emergency Patch Release 2) after PaperCut worked with watchTowr and Huntress researchers to address bypasses of the earlier patches . CVE-2026-82078, which has a critical CVSS score of 9.4, involves unsafe dynamic class loading in the database connection utilities of PaperCut NG/MF. The application instantiates database driver classes based on driver names stored in PaperCut’s configuration without validating them against an allowlist. This flaw allows an attacker with control over PaperCut’s configuration to add a malicious driver class that executes arbitrary Java code located at the application classpath. This flaw becomes unauthenticated RCE when chained with CVE-2026-81578, an improper access control vulnerability in the PaperCut NG/MF web management interface that enables an unauthenticated remote attacker to edit configurations. CVE-2026-81578, which has a CVSS score of 8.8, allows an attacker to send a specially crafted request that refers to one page, which is rendered for the response, and another page that owns administrative functions to be executed, Huntress explained. PaperCut’s authorization checks would trust the rendered page while missing permission checks for the backend actions, allowing server configurations to be modified without authentication. Huntress reported that it detected exploitation of CVE-2026-82078 and CVE-2026-81578 in two customer environments as of Aug. 27. In one case, an attacker executed base64-encoded whoami and ver commands to identify the user account and operating system version, as recovered from PaperCut logs. Huntress also recovered a hex-encoded Java .class file that decodes and runs commands from the relative /data/content/ folder path to profile the system and obtain a directory listing of files. It outputs this data to a file called Udydn.out written to the same path then deletes this file and the PaperCut server.log file. In the second incident, a .class payload was used to execute base64-encoded whoami, ver and tasklist commands. Huntress also developed its own working proof-of-concept exploit for chaining the flaws, using an SMB2 share to deliver a Derby archive and trigger unauthenticated RCE with system privileges under the PaperCut Application Server (pc-app.exe). Organizations that use PaperCut are recommended to upgrade to the latest builds for PaperCut NG/MF v24, v25 and v26 and restrict web access to the PaperCut Application Server to trusted IP addresses. “Use firewall rules, network access controls, or equivalent measures to ensure the PaperCut server’s web interfaces cannot be reached from untrusted internet addresses,” PaperCut advised. For servers that were publicly exposed prior to patching, PaperCut recommends investigating any suspicious activity originating from pc-app.exe, missing, truncated or deleted server.log files and the following entries in the server.log file: ERROR No suitable driver found for jdbc:no:x ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST PaperCut is used by nearly 140 million users across 98,000 organizations in more than 195 countries, according to its website . Last year, a vulnerability in PaperCut NG/MF tracked as CVE-2023-2533 was added to the Known Exploited Vulnerabilities (KEV) catalog by the Cybersecurity and Infrastructure Security Agency (CISA). The cross-site request forgery (CSRF) flaw, originally patched in 2023, could allow for modification of security settings and arbitrary code execution. Laura French Related Vulnerability Management Ubiquiti patches 3 critical remote code execution vulnerabilities SC Staff August 26, 2026 The vulnerabilities include improper input validation in the UniFi Protect Application (CVE-2026-77537), a CRLF injection flaw in UniFi OS devices (CVE-2026-77550), and a command injection flaw in the UniFi Talk Application (CVE-2026-77554). Vulnerability Management CISA adds Oracle WebLogic bug to its list of exploited vulnerabilities Steve Zurier August 25, 2026 Experts say exploiting WebLogic middleware gives attackers access to an enterprise's core business apps. Vulnerability Management WordPress plugin vulnerabilities allow admin account takeover SC Staff August 24, 2026 The vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, can be chained together to bypass authentication. Related Events Cybercast State of Vulnerability Management Thu Sep 10 Cybercast Why Mythos is the cybersecurity crisis we need On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds

Share this article