---
title: "PaperCut NG/MF Zero-Day Exploit Chain — Authentication Bypass and Remote Code Execution (Actively Exploited)"
summary: "PaperCut has disclosed two vulnerabilities in PaperCut NG and PaperCut MF that chain into an unauthenticated remote code execution attack against the PaperCut Application Server."
severity: critical
status: active
advisoryId: "GARNET-CSIRT-2026-005"
published: 2026-09-02
affected:
  - "PaperCut NG (all versions prior to 24.1.10"
  - "25.0.13"
  - "or 26.0.5)"
  - "PaperCut MF (all versions prior to 24.1.10"
cves:
  - "CVE-2026-81578"
  - "CVE-2026-82078"
tags:
  - "papercut"
  - "kev"
  - "active-exploitation"
  - "zero-day"
  - "education-sector"
tlp: CLEAR
references:
  - title: "PaperCut · Urgent Security Advisory (27 Aug 2026)"
    url: "https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/"
  - title: "CISA KEV · CVE-2026-82078"
    url: "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-82078"
  - title: "CISA KEV · CVE-2026-81578"
    url: "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-81578"
  - title: "Rapid7 · Emergent Threat Response"
    url: "https://www.rapid7.com/blog/post/etr-papercut-ng-mf-critical-zero-day-exploited-in-the-wild/"
draft: false
---

## Summary

PaperCut has disclosed two vulnerabilities in PaperCut NG and PaperCut MF that chain into an unauthenticated remote code execution attack against the PaperCut Application Server. CVE-2026-81578 (CVSS 8.8) is an authentication-bypass flaw in the web management interface; CVE-2026-82078 (CVSS 9.4) is an unsafe dynamic class-loading vulnerability in the database connection utilities. Used together, an attacker with network access to the PaperCut Application Server web interface can reconfigure the external database lookup, cause the server to load an attacker-chosen Java class from the application classpath, and execute arbitrary code as the PaperCut server process.

The vulnerabilities were exploited as a zero-day. PaperCut confirmed customer incidents, released emergency patches on 28 August 2026, and CISA added both CVEs to the Known Exploited Vulnerabilities catalog on 31 August 2026.

## Impact

Exploitability signals: **CVSS 9.4 (CVE-2026-82078)** and **CVSS 8.8 (CVE-2026-81578)** · **zero-day exploitation confirmed by PaperCut** with customer incidents · **CISA KEV listed** 31 August 2026 · **public Metasploit module** available (`multi/http/papercut_ng_external_user_lookup_rce`) covering PaperCut 24.x/25.x/26.x with Java, Windows, and Linux payloads · unauthenticated, remote, no user interaction required.

A successful attack yields code execution on the PaperCut Application Server host under the security context of the PaperCut process. On most institutional deployments that account holds enough privilege to move laterally, read cached credentials, or stage further intrusion. **Historical context matters here:** PaperCut CVE-2023-27350 was heavily exploited in 2023 by Cl0p, LockBit, and Bl00dy ransomware operators and by Iranian state-linked groups, with universities among the most targeted victims. The exploitation profile of this new chain is similar and the sector targeting should be assumed to be identical.

## Affected systems

All versions of PaperCut NG and PaperCut MF prior to the following emergency-patched builds:

- **PaperCut NG/MF 26** — fixed in **26.0.5**
- **PaperCut NG/MF 25** — fixed in **25.0.13**
- **PaperCut NG/MF 24** — fixed in **24.1.10**

PaperCut released the initial patches for versions 25 and 26 on 28 August 2026 and a second patch the same day for version 24, adding further hardening.

## Action

1. **Patch on an emergency schedule.** Apply the fixed release for your version train (24.1.10, 25.0.13, or 26.0.5) from PaperCut's Software Center. There is no configuration workaround for the chained exploit.
2. **Get the PaperCut Application Server web interface off the public internet.** The exploit chain begins with direct HTTP(S) access to the management interface. Restrict access to institutional networks and administrative VPN ranges. This is a mitigation, not a fix — patch regardless — but it removes the fastest path in while you schedule the upgrade.
3. **Assume compromise if internet-exposed and unpatched at any point since 27 August 2026.** Exploitation predates the patch. If your PaperCut Application Server was reachable during that window and is not yet patched, treat the host as potentially compromised: engage incident response, review PaperCut's advisory for indicators of compromise, examine application logs for suspicious external database-lookup configuration changes, and audit the server's process, file, and network activity around and after that date.
4. **Rotate credentials and secrets held by or reachable from the PaperCut server** if compromise is suspected — database credentials, service accounts, any cached directory-sync credentials, and any keys stored on the host.
5. **Check for lateral movement.** PaperCut servers typically hold LDAP/AD sync credentials and network access to print infrastructure. Compromise there is a foothold, not an endpoint. Review authentication logs on integrated directory services for anomalous activity from the PaperCut host.
6. GARNET CSIRT will circulate PaperCut's published indicators of compromise separately to member SOCs. Institutions that observe matching activity or unexplained PaperCut server behaviour should [report the incident](https://csirt.garnet.edu.gh/report/) so we can correlate across the constituency.
