
PAPERCUT Software has confirmed that a critical zero‑day flaw affecting its NG and MF print management platforms is being actively exploited in the wild, prompting the release of an emergency patch on 27 August 2026 (PaperCut's advisory). The vulnerability permits unauthenticated attackers to bypass login controls and execute arbitrary code on vulnerable servers, putting any internet‑facing installation at immediate risk. According to the vendor’s advisory, the flaw resides in the Application Server component that handles web‑based administration and job submission, and all supported releases are impacted.
Two CVE identifiers have been assigned to the flaw: CVE‑2026-81578 covers the authentication bypass mechanism, while CVE‑2026-82078 describes an unsafe dynamic class loading vector that together enable remote code execution via the Application Server web interface. Exploitation does not require valid credentials; an attacker can send specially crafted HTTP requests that trick the server into loading malicious classes and executing them with the privileges of the PaperCut service.
Although CVSS scores have not yet been published, the vendor rates the issue as critical and notes that successful exploitation can lead to full system compromise.
Researchers at Rapid7 (reported seeing exploit attempts against exposed PaperCut instances shortly after the advisory was issued, a finding echoed by SecurityAffairs (which noted the appearance of a suspicious file named _pc-app.exe_ and unexpected changes to server.log files on compromised hosts. SecurityWeek (highlighted) that roughly one thousand PaperCut deployments remain accessible from the internet, increasing the pool of potential targets, while SecurityOnline (explained) that the attack leverages the public‑facing web component and does not require valid credentials. The indicators of compromise include the creation of _pc-app.exe_ in the server’s working directory and the addition of anomalous entries to server.log that indicate unauthorized class loading. Although no specific threat actor has been linked to the current campaign, the speed and scale of the observed activity suggest that automated scanners are already probing for vulnerable installations.
PaperCut NG and MF are widely deployed across educational institutions, healthcare providers and government agencies, making the flaw an attractive target for ransomware groups that have previously leveraged similar vulnerabilities in the product line. Past incidents involving PaperCut have shown how attackers can move from a compromised print server to domain controllers, using the access to deploy ransomware payloads. While the current exploit has not yet been tied to a specific malware family, the potential for follow‑on activity remains high given the privilege level of the PaperCut service.
Administrators should immediately apply the emergency patches available from PaperCut's advisory (here) and, where possible, restrict access to the Application Server web interface to trusted IP addresses or disable it entirely until the update can be applied. In addition, organisations are advised to review firewall rules to ensure that the PaperCut server is not reachable from untrusted networks, to enable detailed logging of authentication attempts and to monitor for the indicators of compromise mentioned in the security bulletins. It is also prudent to check for the presence of _pc-app.exe_ in the server’s file system and to investigate any new or unexpected processes running under the PaperCut account. If patch