All incidents

PaperCut NG/MF zero‑day RCE flaws (CVE-2026-81578, CVE-2026-82078) exploited

vulnerabilityopenAug 28, 2026 — Aug 31, 2026
PaperCut NG/MF zero‑day RCE flaws (CVE-2026-81578, CVE-2026-82078) exploited

PAPERCUT NG and MF print management systems are under active attack after two zero‑day remote code execution flaws were discovered and exploited in the wild, as reported by SecurityWeek. The vulnerabilities, tracked as CVE-2026-81578 and CVE-2026-82078, affect all versions and have left roughly one thousand internet‑facing instances exposed, mainly in North America and Europe.

The first flaw, CVE-2026-81578, is an authentication bypass that lets attackers change configuration without logging in and carries a CVSS score of 8.8. The second, CVE-2026-82078, involves unsafe class loading in the database utility component and is rated CVSS 9.4, permitting arbitrary code execution once the bypass is used. Both flaws can be chained to achieve full remote control of the PaperCut application server, as detailed by Rapid7.

Huntress researchers have confirmed that CVE-2026-81578 is being used in the wild, noting that attackers are performing reconnaissance rather than immediate payload delivery, according to their blog. Indicators of compromise include the appearance of a suspicious file named _pc-app.exe_ and unexpected modifications to _server.log_. No specific threat actor has been attributed to the activity so far.

PaperCut issued an emergency patch on 27 August and followed it with a second update after bypass attempts were observed. Despite the fixes, security researchers estimate that 47 % of installations remain unpatched, leaving about one thousand devices reachable from the internet, as highlighted by SecurityAffairs. The majority of exposed systems are located in North America and Europe, raising concerns about possible ransomware deployment.

Administrators should apply the latest PaperCut patches without delay and limit the administrative web interface to trusted IP addresses only. Monitoring server logs for the _pc-app.exe_ artefact and anomalous entries in _server.log_ can help identify ongoing compromise. If patching cannot be completed immediately, isolating the server from external networks reduces the risk of exploitation.

Given the history of PaperCut vulnerabilities being leveraged for ransomware, timely remediation is essential to protect organisational networks.

Intelligence briefing updated Aug 31, 2026

CVE-2026-82078 9.4 CVE-2026-81578 8.8
Root sourcewww.papercut.com
Timeline Coverage

Swipe to explore timeline