Attackers are chaining two newly disclosed PaperCut NG/MF vulnerabilities to achieve unauthenticated remote code execution on exposed print servers, prompting the vendor to ship a hardened emergency fix.[1][5] The flaws, tracked as CVE-2026-82078 and CVE-2026-81578, affect supported versions of PaperCut MF and PaperCut NG and are already being weaponized in real-world attacks against internet-facing instances.[5][1]
According to researchers analyzing live intrusions, one bug in the web management interface allows an unauthenticated remote attacker to modify trusted system configuration values, effectively granting control over how the application loads code and connects to backend services.[1][5] The companion flaw in the database connection utilities stems from unsafe dynamic class loading, which can be abused to run arbitrary Java bytecode inside the PaperCut application process once configuration has been manipulated.[5][1] Together, the pair forms a potent exploit chain that takes a low-complexity HTTP request and turns it into full server compromise without credentials or user interaction.[1][5][9]
PaperCut has acknowledged malicious activity involving these vulnerabilities and released a second emergency patch with what it describes as “additional hardening beyond the original emergency patch,” though it has yet to share detailed indicators of compromise.[1][5] Security firms including Huntress say they have observed threat actors successfully exploiting the configuration-control bug to plant malicious classes and achieve remote code execution against customer environments.[1][10] The situation echoes the 2023 PaperCut crisis around CVE-2023-27350 and related flaws, when attackers leveraged an authentication bypass to gain administrator access and execute code as SYSTEM on vulnerable servers.[6][8][9][10][12]
In that earlier campaign, US and international cyber agencies warned that CVE-2023-27350—an improper access control bug in the SetupCompleted class—enabled unauthenticated actors to run arbitrary code remotely and quickly became part of ransomware playbooks.[6][8][14] The National Vulnerability Database assigns the 2023 flaw a CVSS v3.1 score of 9.8, underscoring how an exposed PaperCut application server can serve as a high-impact entry point into corporate networks.[8][6] With the new configuration-control and dynamic class-loading issues, defenders now face a fresh pathway to similar levels of compromise unless patches and compensating controls are in place.[1][5]
PaperCut MF and NG are widely deployed in education, government and enterprise environments to manage printing and user quotas, meaning vulnerable instances often sit on networks with access to domain controllers, file shares and sensitive data.[4][10] Any server that exposes the PaperCut web management interface to the public internet, especially on the default port 9191, is at heightened risk from opportunistic scanning and exploitation.[5][10] Because the latest attack chain does not require valid credentials, even small organizations with limited remote-access controls can be compromised through a single unpatched and reachable print server.[1][5][9]
PaperCut advises administrators to upgrade to the newest supported MF/NG release incorporating the hardened emergency fix and to restrict web management access to trusted internal addresses or VPNs only.[1][5][7] Network defenders should immediately block external traffic to PaperCut management ports, audit recent configuration changes, and review logs for suspicious admin activity, new user sync rules or unusual scripts executed through print management features.[7][10][6] Given the history of rapid exploitation of PaperCut bugs, organizations that cannot patch immediately should consider temporarily disabling internet exposure of their application servers and treating any previously exposed instance as potentially compromised.[6][9][10]
References
- Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
- CVE-2023-27350: PaperCut NG/MF authentication bypass to remote …
- Unknown PaperCut NG/MF vulnerability is under active …
- Malicious Actors Exploit CVE-2023-27350 in PaperCut MF …
- URGENT MF/NG vulnerability bulletin (March 2023) – PaperCut
- CVE-2023-27350 Detail – NVD
- Exploit released for PaperCut flaw abused to hijack servers …
- Critical Vulnerabilities in PaperCut Print Management …
- 漏洞信息(CVE-2023-27350)
- To report suspicious or criminal activity related to information found in this joint Cybersecurity Advisory, contact
