PaperCut has confirmed active exploitation and customer incidents involving CVE-2026-81578 and CVE-2026-82078 in PaperCut NG and MF. The two vulnerabilities can be chained to change privileged configuration and execute code as the PaperCut server process. CISA added both CVEs to its Known Exploited Vulnerabilities catalog on August 31, 2026.
PaperCut published Emergency Patch Release 3 on September 1. It supersedes Releases 1 and 2, fixes two regressions and adds further hardening. Administrators of internet-facing Application Servers should install Release 3 even if an earlier emergency patch is already present—and should investigate the pre-patch exposure window instead of treating the update as proof that no intrusion occurred.
What PaperCut and CISA have confirmed
CVE-2026-81578 is an improper-access-control issue in the web management interface. PaperCut says that, under specific conditions, unauthenticated remote requests can cause administrative backend actions to run before access validation is complete, allowing certain system configuration changes.
CVE-2026-82078 is an unsafe dynamic-class-loading issue in database connection utilities. If an attacker can manipulate the relevant configuration, the server may load attacker-selected Java bytecode available on its classpath. Chaining the authentication bypass with this behavior can produce remote code execution in the security context of the PaperCut service.
PaperCut says all versions of PaperCut NG and PaperCut MF are potentially affected. The company confirms customer incidents and describes observed post-compromise behavior, including the PaperCut process spawning command shells, deleted or truncated logs and, in some cases, remote-access tooling. The absence of one listed artifact does not rule out compromise because attackers may remove evidence as activity progresses.
A print server can cross several secret boundaries
PaperCut commonly connects identity, printing and business systems. Depending on the deployment, the Application Server may authenticate users, connect to a database, query directory or card systems, send email, support SAML or OAuth flows and coordinate other print infrastructure. Code execution as that service therefore creates a reachability question that is broader than the PaperCut administrator password.
This does not prove that attackers accessed print jobs, documents or integration credentials in any particular organization. It means responders should establish which files, environment variables, configuration values, service identities and adjacent systems were accessible to the compromised process, then use that evidence to set the rotation scope.
Patch, investigate and rotate in the right order
- Restrict the web interfaces immediately. Allow trusted administrative networks only and remove direct internet exposure before continuing recovery.
- Preserve evidence. Collect PaperCut, reverse-proxy, endpoint, identity, firewall and database logs before cleanup can destroy the timeline.
- Apply Emergency Patch Release 3. Verify the installed build and every Application Server or site server rather than relying on a central deployment declaration.
- Hunt for post-exploitation. Review unexpected child processes, altered or missing logs, new files, remote-access tools, persistence, unusual outbound traffic and configuration changes.
- Decide whether the host remains trustworthy. Rebuild from known-good media when code execution occurred or integrity cannot be established.
- Map secrets by reachability. Include service accounts, database credentials, directory bind accounts, SAML or OAuth material, SMTP credentials, certificates, API keys and administrative sessions available to the service.
- Rotate after containment from a clean environment. Revoke exposed sessions and old credentials, then create replacements outside the suspected host and identity path.
- Validate connected systems. Confirm that print queues, database connectors, identity integrations, administrator accounts and downstream services have no unauthorized changes.
Patching closes the known exploit chain. Hunting determines whether the chain was used, while rotation limits the value of credentials that may have been exposed before the patch. These are separate controls and should not be collapsed into one maintenance task.
Move replacement credentials through a clean channel
Incident responders should not paste replacement database passwords, OAuth client secrets or recovery codes into the same email thread, ticket or administrator endpoint that may have been exposed. Verify the recipient independently, keep authorization and custody in the incident record, and deliver the value through a short-lived path outside the suspected environment.
Secretus can deliver a replacement credential or recovery value through a one-time link so the plaintext is not retained in a long-lived collaboration archive. It cannot make a compromised browser, endpoint, identity provider or PaperCut server trustworthy. The receiving device and the administrative path must already be known clean.
What remains unknown
Public sources do not identify the attackers, the number or names of affected customers, the complete post-exploitation objectives or the data accessed. They do not establish that print jobs, user records or credentials were stolen from every exposed server. SecurityWeek reports escalation to hands-on-keyboard activity and more than 1,000 internet-exposed instances, but exposure is not the same as confirmed compromise.
