THE article discusses ongoing attacks on PaperCut servers, with 47% of installations still using unpatched versions vulnerable to critical flaws. A recent report from Huntress confirmed that a pre-authentication remote code execution (RCE) vulnerability (CVE-2026-81578) is being actively exploited. This vulnerability allows attackers to execute actions without proper authentication, posing severe risks.
Attackers have been observed performing reconnaissance activities rather than launching full-scale attacks, leaving behind a forensic trail that can aid in defense. PaperCut's patching process was complicated, with emergency updates released rapidly, but many older versions still lack fixes, urging organizations to isolate their servers while awaiting solutions. It’s highlighted that evidence from log files should be preserved post-exploitation for investigation.