Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: print-management (1 article)Clear

Attackers exploit PaperCut print server zero-days affecting all NG and MF versions

PaperCut warned that attackers are actively exploiting vulnerabilities in all versions of its widely deployed NG and MF print-management software, and confirmed real customer incidents. Two flaws are involved: CVE-2026-82078, unsafe dynamic class loading in the database connection utilities that lets an attacker run arbitrary Java bytecode, and CVE-2026-81578, an access-control flaw in the web management interface that lets an unauthenticated attacker change system configuration. PaperCut released emergency out-of-cycle patches for its version 25 and 26 branches, with a version 24 build still in progress, and later issued a hardened second release. PaperCut servers have a history of being targeted by ransomware crews.

Check
Install PaperCut's emergency patch, specifically Release 2, on all NG and MF servers now, and if a server is internet-facing, immediately restrict its web interface to trusted IP addresses.
Affected
Organizations running PaperCut NG or MF, especially internet-facing print servers (CVE-2026-82078, CVE-2026-81578); attackers are actively exploiting the flaws to change configuration and execute code, and all versions are affected.
Fix
Apply the emergency Release 2 patch, keep the Application Server off the public internet or limited to trusted IPs, investigate the pc-app process, and treat exposed unpatched servers as compromised.