PaperCut Zero-Day Under Active Attack, Second Patch Out

PaperCut has confirmed that attackers are actively exploiting two vulnerabilities in its NG and MF print management software, prompting the company to ship a second emergency patch within days.
The flaws can be chained together: CVE-2026-81578 (CVSS 8.8) is an authentication bypass in the web management interface that lets unauthenticated requests trigger administrative backend actions before access checks complete. CVE-2026-82078 (CVSS 9.4) is a more severe issue in the software's database connection utilities, which load database driver classes without validating them against an approved list — allowing an attacker to execute arbitrary Java bytecode on the server.
Security firm Huntress said it observed exploitation in two customer environments, where attackers used hex-encoded Java files primarily for reconnaissance rather than deploying malware or establishing persistence. PaperCut says the versions affected are 24, 25 and 26 across Windows, Linux and macOS; customers still on version 23 or earlier are advised to upgrade rather than wait for a patch.
PaperCut released an initial emergency patch and followed up on August 28 with a hardened "Release 2" patch that adds further mitigations. The company is urging all customers to install Release 2 even if they already applied the first patch, and recommends restricting the PaperCut Application Server so it is reachable only from trusted IP addresses via firewall rules. Administrators are advised to check for indicators of compromise, including suspicious activity from the pc-app.exe process and missing or truncated server log files.
Related
OpenAI Agent Breached Medicare Portal; Australia Told 84 Days Later
996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
Arista VeloCloud Zero-Day at CVSS 10.0; Patch Due Sept. 25
Check Point: VPN Flaw Under Attack Since Sept. 12, Patch by Sept. 25
Malware Lets 4 AI Models Vote on Its Next Attack Move
Microsoft Shuts Down AI Phishing Service That Hit 12,000 Inboxes
F5 Patches Exploited BIG-IP Flaw; CISA Deadline Is Sept. 25
Trending now
- US-China Trade Truce Extended to Jan. 10 as Xi Visits
- Amoeba Breeds at 63°C, Past the 60°C Limit for Complex Life
- 996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
- Oracle Invokes Force Majeure on 2.45GW Stargate Data Center
- Diller Drops $18B MGM Bid; Stock Falls 9.5% to February Levels
- Taylor Swift Adds 4 Songs to ‘Showgirl’ in Sept. 25 Encore
- Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
- Rivian Recalls 98,828 EVs Over Rearview Camera Fault
Comments
No comments yet. Be the first.