Threat actors are exploiting newly patched flaws in PaperCut NG and PaperCut MF to bypass authentication and execute arbitrary code on vulnerable servers. Huntress and watchTowr observed limited real-world activity using chained exploits, post-exploitation reconnaissance, and Java .class payloads to fingerprint systems and collect data. #PaperCutNG #PaperCutMF #CVE-2026-82078 #CVE-2026-81578
Keypoints
- Attackers are chaining two PaperCut flaws to gain remote code execution.
- CVE-2026-81578 enables authentication bypass in the web management interface.
- CVE-2026-82078 allows unsafe dynamic class loading for arbitrary code execution.
- Huntress observed Base64-encoded commands and Java .class payloads in active attacks.
- Organizations should patch immediately and restrict public access to PaperCut servers.
Read More: https://thehackernews.com/2026/08/attackers-chain-two-papercut-flaws-to.html