A newly discovered PaperCut vulnerability, tracked as CVE-2026-82078 and CVE-2026-81578, presents a critical risk due to active exploitation. This zero-day exploit allows attackers to bypass authentication and execute malicious SQL for remote code execution. Key details include:
- **Affected Product:** PaperCut MF/NG
- **Severity Score:** 9.4 (Critical) for CVE-2026-82078
- **Impact:** Unsafe Dynamic Class Loading in Database Connector
- **Current Status:** Actively exploited
- **Recommended Action:** Immediate updates to versions 24.1.10, 25.0.13, or 26.0.5 are necessary.
Previous vulnerabilities in PaperCut have led to significant security threats, emphasizing the urgency for organizations to address this issue promptly.