MELBOURNE, AUSTRALIA — PaperCut Software has issued an urgent security warning after confirming active exploitation of vulnerabilities affecting its widely deployed PaperCut NG and PaperCut MF print management platforms, with attackers targeting internet-exposed application servers and exploiting weaknesses that can lead to unauthorized configuration changes and remote code execution.
The company said its security response team is investigating confirmed customer incidents and is treating the activity as a high-priority security emergency.
PaperCut initially warned on August 27 that all versions of PaperCut NG and PaperCut MF should be considered potentially affected while its investigation continued. The company urged customers to immediately remove PaperCut Application Server web interfaces from direct public internet exposure and restrict access to trusted IP addresses using firewall rules, network access controls, VPNs, or equivalent protections.
The vulnerabilities are tracked as CVE-2026-82078 and CVE-2026-81578.
CVE-2026-82078 is an unsafe dynamic class-loading vulnerability in PaperCut’s database connection utilities. The weakness can allow arbitrary Java bytecode to execute under the security context of the PaperCut server process when an attacker is able to manipulate affected configuration parameters.
The flaw carries a CVSS v4 score of 9.4, placing it in the critical-severity range.
CVE-2026-81578 is an improper access-control vulnerability in the PaperCut web management interface. Under certain conditions, unauthenticated remote requests can reach administrative functionality before access validation is completed, allowing an attacker to alter system configuration.
That vulnerability carries a CVSS v4 score of 8.8.
The two vulnerabilities become particularly dangerous when chained.
An attacker able to exploit the access-control weakness may be able to manipulate PaperCut configuration settings and then abuse the unsafe class-loading behavior to execute code on the underlying server.
That creates a path from an exposed web interface to control over a system that may sit inside a university, corporation, government agency, school district, healthcare organization, or other large enterprise environment.
PaperCut said information supplied by a university customer’s security team and digital-forensics personnel helped the company reproduce the underlying vulnerability and accelerate development of emergency fixes.
Security researchers have since reproduced the attack chain.
Huntress said it successfully demonstrated pre-authentication remote code execution against an unpatched PaperCut NG installation and observed exploitation activity affecting two customer environments.
During one observed incident, attackers executed encoded commands that resolved to whoami and ver, commands commonly used to determine the current user account and Windows operating system version.
In another incident, the attackers also executed tasklist, allowing them to enumerate processes running on the compromised system.
Huntress also identified malicious Java class files written into the PaperCut installation directory.
The payloads were capable of executing commands on Windows or Linux systems, collecting system information, writing output to disk, and deleting some of the files and logs associated with the activity after execution.
That behavior raises the possibility that some compromised systems may show limited forensic evidence if attackers successfully removed logs following exploitation.
PaperCut has published several indicators organizations should examine.
Administrators should investigate suspicious activity originating from the pc-app.exe PaperCut Application Server process, unexpected deletion or truncation of server.log, and specific database-related error messages appearing in the PaperCut logs.
PaperCut cautioned that the absence of those indicators does not prove that a server was unaffected.
Emergency security updates have been released for supported PaperCut NG and MF branches.
As of August 28, Emergency Patch Release 2 is available for supported versions 24, 25, and 26, while organizations running versions earlier than 24 are being directed toward upgrading to a current supported release.
NHS England’s cyber alert on the vulnerabilities also urged organizations to apply the latest emergency patch immediately and remove public internet exposure where patching cannot yet be completed.
PaperCut’s exposure is significant because its products are used to centrally manage printing, user authentication, print queues, accounting, access controls, and document workflows across large organizations.
A compromised print-management server can provide attackers with more than access to printing functions.
Depending on system architecture and permissions, the server may hold credentials, configuration data, directory integrations, administrative connections, document metadata, and trusted relationships with other enterprise systems.
That makes an exposed PaperCut server a potentially valuable foothold for lateral movement deeper into a network.
The current activity also carries historical significance.
PaperCut vulnerabilities have previously drawn the attention of ransomware operators and state-linked threat actors, reinforcing the importance of treating exposed management servers as high-value infrastructure rather than ordinary peripheral systems.
The company’s current advisory does not publicly attribute the 2026 exploitation campaign to a specific ransomware group, criminal organization, or nation-state actor.
PaperCut has also not disclosed the total number of affected customers.
Rapid7 separately reported the active exploitation and characterized the situation as a critical zero-day event involving PaperCut NG and MF.
Organizations operating PaperCut should not rely solely on whether suspicious behavior has already been detected.
PaperCut is explicitly instructing customers with internet-accessible Application Servers to restrict access immediately, even in environments where no compromise has yet been observed.
Administrators should also preserve logs and forensic evidence before restarting, upgrading, or modifying potentially compromised servers, particularly where PaperCut interfaces were exposed to the public internet.
The incident demonstrates the risk created when administrative software designed to control enterprise infrastructure becomes directly reachable from untrusted networks.
For affected organizations, the immediate priorities are clear: apply Emergency Patch Release 2, eliminate unnecessary public exposure, restrict administrative access to trusted sources, preserve forensic evidence, and investigate systems for signs of post-exploitation activity.
The exploitation campaign remains under active investigation, and PaperCut has said additional indicators of compromise and remediation guidance will be published as new information is verified.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



