Pre-auth RCE chain in PaperCut NG and MF (CVE-2026-81578, CVE-2026-82078) is actively exploited in the wild, dropping Java payloads that execute discovery commands and delete logs. Two CVEs chain improper access control and unsafe class-loading to enable unauthenticated remote code execution in PaperCut Application Server. Huntress confirmed exploitation in two customer environments where attackers dropped Java .class files executing whoami, ver, and tasklist as SYSTEM. Payloads delete server.log and themselves. Patches exist for v25 and v26; v24 fixes in progress; v23 and older have no patch.
papercut-ng
2 posts
PaperCut Actively Exploited: A Pre-Auth RCE Chain CISA Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2026-81578, CVE-2026-82078) CISA added two actively exploited vulnerabilities affecting PaperCut NG/MF to its Known Exploited Vulnerabilities Catalog. CVE-2026-81578 is a missing authentication for critical function vulnerability and CVE-2026-82078 is an unsafe reflection vulnerability. Federal agencies are required to remediate these under BOD 26-04, and CISA recommends all organizations prioritize patching.