Hackers Exploit Two PaperCut Flaws to Deploy Remote Access Tools
Attackers are actively exploiting two recently disclosed vulnerabilities in PaperCut NG and MF print management software, prompting the vendor to release a second emergency patch with additional security hardening. The flaws, tracked as CVE-2026-81578 and CVE-2026-82078, can be chained together to allow unauthenticated attackers to bypass authentication and execute arbitrary code remotely on vulnerable systems. The core issue involves a flaw in how PaperCut's authorization process validates permissions, allowing attackers to send specially crafted requests that reference one page while actually executing commands from another, effectively tricking the system into granting unauthorized access to sensitive configuration endpoints.
Security researchers from Huntress and watchTowr have observed active exploitation in the wild, though the activity appears limited so far. Attackers have been seen running reconnaissance commands to identify compromised systems and their configurations, executing Base64-encoded commands like "whoami" and "ver" to fingerprint targets. More sophisticated attacks involve deploying cross-platform Java class files that can operate on both Windows and Linux systems, creating directory listings of files and then cleaning up evidence by deleting log files. The threat actors appear to be initial access brokers or similarly motivated operators who are keying their payloads to ensure exclusive access to compromised systems.
PaperCut represents a particularly attractive target because these systems are often internet-facing and contain sensitive information from printed documents that could be exfiltrated. The software's position as a gateway into corporate networks makes it valuable for pivoting deeper into compromised environments. Researchers have discovered multiple patch bypasses affecting even the first emergency update, though the second patch addresses some of these issues. However, additional bypasses have been found that affect the latest fully patched versions, suggesting this vulnerability chain remains a significant threat.
Organizations running PaperCut NG or MF should immediately remove public internet access to these systems, apply the latest patches, and begin hunting for indicators of compromise in their environments. Recommended protective measures include restricting web access to the PaperCut Application Server to trusted IP addresses only or placing it behind a VPN. Given that exploitation has evolved from initial scanning to hands-on-keyboard activity, organizations with previously exposed systems should assume compromise and initiate full incident response procedures to ensure any existing attacker presence is completely removed from their networks.
Stay secure — stay Wavasec. 🔐