PaperCut Flaw Chain Enables Unauthenticated Remote Code Execution, Prompting Emergency Patch

TL;DR Summary
Hackers chained two PaperCut NG/MF flaws—CVE-2026-81578 (authentication bypass) and CVE-2026-82078 (unsafe dynamic class loading)—to trigger unauthenticated remote code execution and alter server configuration; after an emergency patch with further hardening, exploitation appears limited but active, with attackers using Base64-encoded commands to identify the victim and a Java class to enumerate processes and files. Organizations should remove public exposure, apply the latest patches, and restrict access to trusted networks while monitoring logs for compromise indicators.
- Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication The Hacker News
- PaperCut releases second emergency patch for exploited flaws BleepingComputer
- PaperCut targeted by hackers Printweek
- PaperCut Releases Emergency Patch for Exploited Zero-Day SecurityWeek
- Warning: Critical and High vulnerability in PaperCut, Patch Immediately! CCB Belgium
Reading Insights
Total Reads
0
Unique Readers
10
Time Saved
4 min
vs 5 min read
Condensed
91%
837 → 74 words
Want the full story? Read the original article
Read on The Hacker News