PaperCut Rushes Emergency Patches as Attackers Chain Two Zero-Day Flaws for Remote Code Execution

PaperCut Rushes Emergency Patches as Attackers Chain Two Zero-Day Flaws for Remote Code Execution

PaperCut Rushes Emergency Patches as Attackers Chain Two Zero-Day Flaws for Remote Code Execution

PaperCut has released emergency patches after confirming active, in-the-wild exploitation of a chained vulnerability pair affecting its widely used print management software. The flaws, tracked as CVE-2026-81578 and CVE-2026-82078, affect all versions of PaperCut NG and MF, according to the company's security bulletin. PaperCut has described the issue as its highest priority and disclosed that it has confirmed customer incidents tied to the exploitation.

Emergency patches are now available for versions 25 and 26, and PaperCut has issued mitigation guidance for organizations that cannot patch immediately. The urgency of the response, and the vendor's direct language around confirmed incidents, signals that this is being treated as an active, ongoing threat rather than a theoretical risk.

How the Exploit Chain Works

According to vendor and third-party technical advisories, the chained flaws allow unauthenticated remote code execution through arbitrary Java code execution on internet-exposed PaperCut Application Servers. Full technical detail about the root cause was limited at the time of initial disclosure, and many specifics continue to emerge as researchers publish additional analysis. The National Vulnerability Database lists CVSS scoring and affected version ranges for both CVEs, lending technical grounding to the severity assessments circulating in the security community.

Because exploit mechanics were still emerging at publication time, organizations are encouraged to treat this as a developing situation and to consult primary vendor and regulatory advisories directly rather than relying solely on secondary summaries.

Evidence of Active Exploitation in the Wild

Incident response firm Huntress has reported observing exploitation in at least two customer environments, describing unauthenticated remote code execution consistent with the chained flaw. Investigators have also identified anti-forensic indicators of compromise, including missing or truncated server.log files, which many observers note is consistent with deliberate attempts to obscure attacker activity.

Separately, data cited from the ShadowServer Foundation estimates that roughly 1,000 PaperCut instances remain exposed to the internet globally, with concentrations in North America and Europe. This exposure figure has been referenced across multiple security outlets as a rough measure of the potential attack surface, though PaperCut itself has not published an official exposure count.

Regulatory Response and CISA's KEV Listing

The Cybersecurity and Infrastructure Security Agency has added both CVE-2026-81578 and CVE-2026-82078 to its Known Exploited Vulnerabilities catalog, a designation that mandates remediation timelines for U.S. federal agencies. This marks the fourth and fifth PaperCut NG/MF vulnerabilities to appear in the KEV catalog, a pattern that a recurring number of security researchers have pointed to as evidence of sustained attacker interest in this class of software.

While the KEV mandate technically applies only to federal agencies, its listing is often read by private-sector security teams as a strong signal to prioritize patching, given the regulatory scrutiny and confirmed exploitation status attached to the designation.

A Familiar Pattern: PaperCut's History With Ransomware Actors

PaperCut NG/MF software has a documented history of being targeted following vulnerability disclosures. In 2023, CVE-2023-27350, which carried a CVSS score of 9.8, was exploited by ransomware affiliates associated with Cl0p and LockBit, as well as a group tracked as Lace Tempest, with some reporting linking activity to Russian threat actors.

This history has led a number of security researchers and incident responders to voice concern that the current vulnerability chain could follow a similar trajectory toward ransomware deployment. It's worth emphasizing that attacker identity and motive behind the present exploitation remain unconfirmed across all available sources, and no direct link to a specific ransomware group has been established at this time. Any assessment of follow-on risk should be treated as a possibility informed by precedent, not a confirmed outcome.

What Organizations Should Do Now

Security teams running PaperCut NG or MF are advised to apply the emergency patches for versions 25 and 26 as soon as possible. Organizations unable to patch immediately should follow the vendor's published mitigation guidance to reduce exposure in the interim.

Beyond patching, incident responders recommend auditing internet-exposed Application Servers and reviewing server logs for signs of tampering, particularly missing or truncated server.log files, as part of an immediate incident-response check. Given the unresolved questions around attacker identity and the potential for follow-on activity, organizations are encouraged to treat this as an active, evolving situation and to monitor updates from PaperCut, CISA, and independent security researchers as the story develops.

More Tech articles · CuencaLife home