Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
Threat actors are exploiting newly patched flaws in PaperCut NG and PaperCut MF to bypass authentication and execute arbitrary code on vulnerable servers. Huntress and watchTowr observed limited real-world activity using chained exploits, post-exploitation reconnaissance, and Java .class payloads to fingerprint systems and collect data. #PaperCutNG #PaperCutMF #CVE-2026-82078 #CVE-2026-81578

Keypoints

  • Attackers are chaining two PaperCut flaws to gain remote code execution.
  • CVE-2026-81578 enables authentication bypass in the web management interface.
  • CVE-2026-82078 allows unsafe dynamic class loading for arbitrary code execution.
  • Huntress observed Base64-encoded commands and Java .class payloads in active attacks.
  • Organizations should patch immediately and restrict public access to PaperCut servers.

Read More: https://thehackernews.com/2026/08/attackers-chain-two-papercut-flaws-to.html