A widely used print-management platform has been hit by two newly disclosed vulnerabilities. Attackers are already exploiting them, with researchers observing attempts to bypass authentication and extract database information.

A security problem involving PaperCut NG and PaperCut MF has escalated into an active attack campaign, with attackers now exploiting two vulnerabilities that were only disclosed last week.

PaperCut has issued multiple emergency updates and is urging organizations with internet-facing Application Servers to install its latest emergency release as quickly as possible. Security researchers have also observed attackers abusing the flaws to access data stored on vulnerable servers.

The software is used by more than 100 million users across over 70,000 organizations, including businesses, government agencies and educational institutions, making the incident considerably more important than a typical enterprise software vulnerability.

The two vulnerabilities are tracked as CVE-2026-81578 and CVE-2026-82078.

One provides an authentication bypass, while the second involves unsafe dynamic class loading that can ultimately allow arbitrary Java bytecode to execute on the PaperCut server. PaperCut rates the latter as critical, with a CVSS score of 9.4.

Attackers are already using the flaws

The most concerning development is that this is no longer a theoretical vulnerability.

Threat intelligence company Defused reported seeing exploitation activity in its honeypots beginning around August 29. According to the researchers, attackers were using the authentication bypass to take control of PaperCut’s external user-lookup functionality.

Rather than immediately pursuing the remote-code-execution route described in public technical research, at least one observed attacker appeared to focus on stealing information from the underlying database.

That included attempts to dump database tables through Derby, the database technology used by PaperCut in certain configurations.

The distinction matters.

A vulnerability that can execute code on a server is already serious. But once attackers begin using it against real systems and focus on extracting information, the risk shifts from a patching problem to a potential data-breach problem.

PaperCut has not attributed the attacks to a particular hacking group.

It has, however, published indicators of compromise to help defenders identify suspicious activity.

PaperCut released emergency patches in stages

PaperCut’s response has been unusually aggressive.

The company published the security advisory on August 27, followed by multiple emergency releases as its investigation progressed. The company says the first update was an emergency mitigation, while later releases added additional hardening as researchers and its security team learned more about the attacks.

The latest emergency release is particularly important for organizations that already installed an earlier fix.

PaperCut is recommending that customers with internet-facing Application Servers install Emergency Patch Release 3, even if they previously applied one of the earlier emergency releases.

That recommendation tells its own story: this isn’t a case where administrators can simply install yesterday’s patch and forget about the incident.

The security response is still evolving.

One flaw can lead to code execution

The more severe of the two vulnerabilities, CVE-2026-82078, affects PaperCut’s database connection utilities.

PaperCut says the software can instantiate database-driver classes based on configurable driver names without properly restricting those names to an approved list.

Under the right conditions, an attacker who can manipulate system configuration parameters can abuse that behavior to execute arbitrary Java bytecode already available on the application’s classpath.

PaperCut rates the flaw 9.4 out of 10, placing it firmly in the critical category.

The second vulnerability, CVE-2026-81578, is an authentication-bypass problem in the web management interface.

The combination is what makes the situation particularly uncomfortable for administrators: one vulnerability attacks authentication and access controls, while the other can provide a route toward arbitrary code execution.

Security teams therefore have to treat the two flaws as part of the same incident rather than as isolated bugs.

PaperCut has been a recurring target

This isn’t the first time attackers have shown interest in PaperCut.

The platform has been targeted by major threat groups in previous years, including attacks involving vulnerabilities that allowed attackers to gain access to PaperCut servers and subsequently move deeper into targeted environments.

In 2023, vulnerabilities in PaperCut were exploited by ransomware groups and state-backed actors. Those incidents demonstrated why print servers can become valuable entry points into corporate networks.

The latest campaign is therefore arriving against a backdrop of previous attacks rather than appearing out of nowhere.

The immediate question for organizations running PaperCut is whether vulnerable servers were exposed to the internet during the period in which exploitation was taking place.

PaperCut recommends applying the newest emergency release, while organizations that cannot immediately secure affected systems should take appropriate measures to prevent unauthorized external access.

With hundreds of PaperCut servers still reportedly visible online, attackers have plenty of potential targets to scan.

For companies using PaperCut, the lesson is straightforward: this is not a vulnerability to put into the normal patching queue for later.

The software is widely deployed, the vulnerabilities are serious, and exploitation has already been observed in the wild.

If a PaperCut server is exposed to the internet, administrators should treat the situation as an active security incident and verify both the patch level and the server’s logs for suspicious activity.

by The Tech Spot Editorial Team

Share.
Leave A Reply

Exit mobile version