Affected Systems
PaperCut NG and MF print management software versions 24, 25, and 26 on Windows, Linux, and macOS. CVE-2026-81578 (CVSS 8.8) authentication bypass and CVE-2026-82078 (CVSS 9.4) unsafe class-loading vulnerability can be chained for pre-auth RCE. Version 23 and earlier also vulnerable but require upgrade to latest version.
Exploitation Status
Active exploitation confirmed in the wild. Huntress observed exploitation in two customer environments. Attackers performing reconnaissance; post-exploitation activity appears limited and targeted. Initial emergency patch bypassed by researchers; second hardened patch now available.
Business Impact
Unauthenticated remote attackers can chain CVE-2026-81578 and CVE-2026-82078 to bypass authentication and execute arbitrary code on PaperCut servers. Observed attacks involve system reconnaissance via command execution and file manipulation through hex-encoded Java class files. Threat actor attribution unknown; PaperCut withholding post-exploitation IOCs during active investigation. Historical PaperCut vulnerabilities (CVE-2023-27350) exploited by ransomware groups including Clop, LockBit, and Iranian state-backed actors.
Urgency
🔴 Immediate
Recommended Actions
- Apply PaperCut Emergency Patch Release 2 immediately to NG/MF versions 24, 25, and 26 on all primary, Site Server, and secondary/print servers; upgrade version 23 or earlier to latest patched release
- Restrict access to PaperCut web management interfaces to trusted IP addresses using firewall rules or network access controls
- Hunt for suspicious activity from pc-app.exe process, missing or truncated server.log files, and log errors containing 'No suitable driver found for jdbc:no:x' or 'DatabaseUtils - Database error looking up cardID: VALUES CAST'
- Review intrusion detection, endpoint, and network monitoring alerts tied to PaperCut Application Server processes for signs of compromise
- Monitor PaperCut advisories for indicators of compromise as they are published and correlate against historical logs
