Skip to content
feed: live
>_0dayNews
threat intel
● Breaking

PaperCut Active Intrusions: CISA Adds Flaws to KEV

CISA added CVE-2026-81578 and CVE-2026-82078 to KEV on Aug 31. Active intrusions now confirmed. Federal deadline: Sep 14. Emergency Patch Release 2 required.

PaperCut Active Intrusions: CISA Adds Flaws to KEV
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
fuseMarisol "Fuse" Delgado·Published ·2 min read

Exploitation of PaperCut NG and MF has moved past initial access. SecurityWeek reports active intrusions are now confirmed, not just opportunistic scanning or isolated exploitation attempts. CISA formalized the risk on August 31 by adding both vulnerabilities to the Known Exploited Vulnerabilities catalog.

The two CVEs involved:

  • CVE-2026-82078 (CVSS 9.4, Critical): unsafe Java class-loading in PaperCut NG/MF that enables remote code execution once an attacker has bypassed authentication
  • CVE-2026-81578 (CVSS 8.8, High): the authentication bypass that makes the RCE path accessible without credentials

Both work as a chain. CVE-2026-81578 provides unauthenticated access; CVE-2026-82078 turns that into server-level code execution. The federal patch deadline under CISA’s Binding Operational Directive 22-01 is September 14, 2026.

What’s changed since August 29

The situation has escalated through three stages. Initial zero-day disclosure came August 28, followed by confirmation that PaperCut’s first emergency patch had exploitable bypasses on August 29. The current development is worse: the intrusion stage means attackers are achieving persistent access inside environments, not just testing for vulnerable servers.

Enterprise, government, and education environments are the typical PaperCut deployment profile. Print management servers often have broad internal network visibility, which makes post-exploitation movement easier.

What to do

Apply Emergency Patch Release 2. If you applied Emergency Patch Release 1 only, you remain vulnerable. EP2 addresses bypass paths identified by Huntress and watchTowr researchers that made the first patch insufficient. Patch download links and version-specific guidance are in PaperCut’s updated security bulletin.

Affected versions: PaperCut NG and MF versions 24, 25, and 26 on Windows, Linux, and macOS. Version 23 and older are out of support; upgrade to a supported release rather than expecting an emergency patch.

If patching is not immediate: restrict the PaperCut web management interface to trusted internal IPs via firewall rules. This narrows the attack surface but does not close either CVE. Treat this as a bridge measure with a short shelf life, not a substitute for patching.

Check for signs of compromise. Given confirmed intrusions, look for anomalous outbound connections from your PaperCut server, new scheduled tasks or services, and unexpected Java processes. If your environment has been running vulnerable for weeks, assume investigation is warranted before and after patching.

Priority

This is not a theoretical risk. Active intrusions from a CVSS 9.4 chain in widely deployed software with a federal patch deadline should be at the top of your queue this week.

Previously: PaperCut Issues Second Patch as Bypasses Found and PaperCut NG/MF Zero-Day Under Active Attack.

Related CVEs

Found this useful? Share it.