Summary
PaperCut has disclosed two vulnerabilities in PaperCut NG and PaperCut MF that chain into an unauthenticated remote code execution attack against the PaperCut Application Server. CVE-2026-81578 (CVSS 8.8) is an authentication-bypass flaw in the web management interface; CVE-2026-82078 (CVSS 9.4) is an unsafe dynamic class-loading vulnerability in the database connection utilities. Used together, an attacker with network access to the PaperCut Application Server web interface can reconfigure the external database lookup, cause the server to load an attacker-chosen Java class from the application classpath, and execute arbitrary code as the PaperCut server process.
The vulnerabilities were exploited as a zero-day. PaperCut confirmed customer incidents, released emergency patches on 28 August 2026, and CISA added both CVEs to the Known Exploited Vulnerabilities catalog on 31 August 2026.
Impact
Exploitability signals: CVSS 9.4 (CVE-2026-82078) and CVSS 8.8 (CVE-2026-81578) · zero-day exploitation confirmed by PaperCut with customer incidents · CISA KEV listed 31 August 2026 · public Metasploit module available (multi/http/papercut_ng_external_user_lookup_rce) covering PaperCut 24.x/25.x/26.x with Java, Windows, and Linux payloads · unauthenticated, remote, no user interaction required.
A successful attack yields code execution on the PaperCut Application Server host under the security context of the PaperCut process. On most institutional deployments that account holds enough privilege to move laterally, read cached credentials, or stage further intrusion. Historical context matters here: PaperCut CVE-2023-27350 was heavily exploited in 2023 by Cl0p, LockBit, and Bl00dy ransomware operators and by Iranian state-linked groups, with universities among the most targeted victims. The exploitation profile of this new chain is similar and the sector targeting should be assumed to be identical.
Affected systems
All versions of PaperCut NG and PaperCut MF prior to the following emergency-patched builds:
- PaperCut NG/MF 26 — fixed in 26.0.5
- PaperCut NG/MF 25 — fixed in 25.0.13
- PaperCut NG/MF 24 — fixed in 24.1.10
PaperCut released the initial patches for versions 25 and 26 on 28 August 2026 and a second patch the same day for version 24, adding further hardening.
Action
- Patch on an emergency schedule. Apply the fixed release for your version train (24.1.10, 25.0.13, or 26.0.5) from PaperCut’s Software Center. There is no configuration workaround for the chained exploit.
- Get the PaperCut Application Server web interface off the public internet. The exploit chain begins with direct HTTP(S) access to the management interface. Restrict access to institutional networks and administrative VPN ranges. This is a mitigation, not a fix — patch regardless — but it removes the fastest path in while you schedule the upgrade.
- Assume compromise if internet-exposed and unpatched at any point since 27 August 2026. Exploitation predates the patch. If your PaperCut Application Server was reachable during that window and is not yet patched, treat the host as potentially compromised: engage incident response, review PaperCut’s advisory for indicators of compromise, examine application logs for suspicious external database-lookup configuration changes, and audit the server’s process, file, and network activity around and after that date.
- Rotate credentials and secrets held by or reachable from the PaperCut server if compromise is suspected — database credentials, service accounts, any cached directory-sync credentials, and any keys stored on the host.
- Check for lateral movement. PaperCut servers typically hold LDAP/AD sync credentials and network access to print infrastructure. Compromise there is a foothold, not an endpoint. Review authentication logs on integrated directory services for anomalous activity from the PaperCut host.
- GARNET CSIRT will circulate PaperCut’s published indicators of compromise separately to member SOCs. Institutions that observe matching activity or unexplained PaperCut server behaviour should report the incident so we can correlate across the constituency.
This advisory is published with a detached PGP signature against the CSIRT key. Confirm it is genuine and unmodified before acting:
Downloads: source .md · signature .md.asc · public key. Check the fingerprint (684C7B7DA77E4F1B68AED3ECE84B541C6184CC6F) on the PGP page — if gpg reports a “Good signature” from that key, this advisory is authentic.
Think a system in the community is affected or compromised?Report an incident