ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

PaperCut NG/MF vulnerabilities exploited in zero-day attacks

AI summary · glm-5.3-flash

PaperCut warns of active zero-day exploitation chaining CVE-2026-81578 and CVE-2026-82078 for pre-auth remote code execution in NG/MF print management.

PaperCut Software confirmed attackers are chaining two vulnerabilities in PaperCut NG and MF: CVE-2026-81578, an improper access control flaw in the web management interface allowing unauthenticated configuration changes, and CVE-2026-82078, unsafe dynamic class loading in database connection utilities enabling arbitrary Java bytecode execution. Huntress reproduced a pre-authentication remote configuration takeover and full RCE chain against PaperCut NG 25.0.11.75758 and observed limited exploitation at two customers, including post-exploitation whoami and ver commands. The vendor released Emergency Patch Release 2 with additional hardening and urged restricting Application Server web access to trusted IPs. In 2023, Clop and LockBit affiliates abused CVE-2023-27350 and CVE-2023-27351 in the same software.

  • CVE-2026-81578 allows unauthenticated config changes; CVE-2026-82078 enables bytecode execution.
  • Huntress reproduced pre-auth RCE chain against stock PaperCut NG 25.0.11.75758.
  • Emergency Patch Release 2 issued; install even if the first patch was applied.
  • Vendor urges restricting Application Server web interfaces to trusted internal IPs.
  • Clop and LockBit exploited PaperCut CVE-2023-27350/27351 in 2023.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-27350
Authentication Bypass Leading to SYSTEM RCE in PaperCut MF/NG

PaperCut MF and PaperCut NG print management software contain an improper access control flaw (CWE-284) in the SetupCompleted class that allows an unauthenticated attacker to bypass authentication and reach internal administrative functionality. The flaw is triggered by sending crafted, unauthenticated requests to the PaperCut application's web interface, without requiring valid user credentials. A successful attacker gains the ability to execute code in the context of the SYSTEM account on the PaperCut server, typically a Windows print server, giving full control of that host. Any organization running PaperCut MF or NG is potentially affected, and exposure is highest where the server's web interface is reachable from the internet or by untrusted networks. Exploitation is confirmed in the wild: CISA added the flaw to the KEV on 2023-04-21 with known ransomware use, and EPSS rates exploitation probability at 100% within 30 days.

Do: Apply the vendor's updates as instructed (this is the required action in CISA KEV) — upgrade PaperCut MF/NG to the patched releases listed in PaperCut's security advisory rather than relying on unpatched installs. Until patched, restrict network access to the PaperCut web/admin interface so it is reachable only from trusted hosts, and check the server for signs of compromise given known ransomware use. Prioritize internet-facing PaperCut servers, which public scans show are exposed in the thousands.

9.8100% KEV ransomware PoC ×3
  • PaperCut MF
  • PaperCut NG
masstens of thousands of organizations (~70k+) and millions of users; thousands of internet-exposed PaperCut servers
CVE-2023-27351
Authentication Bypass in PaperCut NG/MF Print Management Software

CVE-2023-27351 is an improper authentication flaw (CWE-287) in the SecurityRequestFilter class of PaperCut NG and MF print management software, where the authentication algorithm is improperly implemented. A remote, unauthenticated attacker can trigger it over the network with no user interaction or special privileges to bypass authentication on the affected server (CVSS 3.1: 7.5). Once authentication is bypassed, the attacker gains access to the PaperCut system; in observed campaigns this access was leveraged to deliver Cl0p and LockBit ransomware, as confirmed by Microsoft. Organizations running PaperCut NG (version 22.0.5, Build 63914, is cited in the advisory) or PaperCut MF are affected. The flaw was exploited as a zero-day, is CISA KEV-listed (added 2026-04-20) with known ransomware use, and EPSS places the 30-day exploitation probability at 78.1%.

Do: Upgrade PaperCut NG/MF to the fixed release per the vendor's emergency patch advisory, first confirming the running build (NG 22.0.5, Build 63914, is cited as affected). Restrict internet-facing access to PaperCut servers and hunt for signs of post-exploitation, given confirmed use to deliver Cl0p and LockBit ransomware. US federal agencies must apply mitigations per CISA BOD 22-01 (or vendor instructions) or discontinue use of the product if mitigations are unavailable.

7.578% KEV ransomware
  • PaperCut NG 22.0.5 (Build 63914) explicitly cited as affected; CISA lists PaperCut NG broadly without a full version range
  • PaperCut MF affected per CISA listing; no specific version range provided in the data
large≈75,000+ sites/organizations (PaperCut NG/MF is deployed at tens of thousands of organizations; public scans have found thousands of servers directly…
CVE-2026-82078
+1 in the same advisory: …81578
Unsafe Reflection RCE in PaperCut NG/MF, Chained with Auth Bypass in Attacks

CVE-2026-82078 is an unsafe dynamic class loading flaw (unsafe reflection, CWE-470) in the database connection utilities of PaperCut NG and PaperCut MF: the software instantiates a database driver class based on a configurable driver name without validating it against an allowlist of approved drivers. An attacker who can manipulate system configuration parameters can point that setting at classes of their choosing, causing the server to execute arbitrary Java bytecode residing on the application classpath in the security context of the PaperCut server process. On its own the issue is rated 9.4 (Critical) with high privileges required, but when chained with the companion authentication bypass CVE-2026-81578 it yields unauthenticated remote code execution on the print-management server. All PaperCut NG and MF deployments are in scope; affected version ranges were not specified in the available data, so administrators should consult PaperCut's advisory for fixed versions. The flaw is confirmed exploited in the wild as a zero-day: it was added to CISA's KEV catalog on 2026-08-31, and public reporting describes an AI-orchestrated campaign that compromised PaperCut servers at roughly 395 organizations (~440 servers), with EPSS currently at 1.7% (76th percentile).

Do: Upgrade PaperCut NG and MF to the patched release specified in PaperCut's security advisory (exact fixed versions were not provided in this data), prioritizing internet-exposed print servers; the KEV listing means agencies must remediate per CISA BOD 26-04 or discontinue/mitigate per its cloud-service guidance. Restrict the PaperCut web interface from direct internet exposure (VPN/allowlist), review administrator accounts and database driver configuration for tampering, and hunt for post-exploitation activity, since this flaw is being actively chained with the authentication bypass CVE-2026-81578.

9.4
group max
2% KEV
  • PaperCut NG
  • PaperCut MF
mass≈100,000+ organizations / plausibly millions of end users (vendor-cited install base); tens of thousands of on-prem servers with a smaller but significant…
Full article666 words · extracted from helpnetsecurity.com · click to collapse

Two vulnerabilities (CVE-2026-82078, CVE-2026-81578) affecting print management solutions PaperCut NG and PaperCut MF are being exploited by attackers, PaperCut Software has warned.

“We are aware of confirmed customer incidents and are treating this matter with the highest priority,” the vendor said.

What is PaperCut NG/MF?

PaperCut NG is print management software for places like offices, schools, and other organizations.

PaperCut MF (“Multi-Function”) is the upgraded version that works directly with the big all-in-one office copier machines that print, copy, scan, and fax. The software is embedded in and accessible from the machine’s touchscreen, and works with copiers from most major brands.

NG watches and manages the printing from the computer and server side, while MF does all of that, and connects to the copier machines for extra security and features.

“If your PaperCut NG/MF Application Server is accessible from the public internet, immediately restrict web access to trusted IP addresses only (e.g. internal IP addresses),” the company urged.

The Application Server is the “brain” of both PaperCut NG and MF, and there’s normally just one per organization.

Restrict access, look for signs of compromise

The vendor said they would publish specific indicators of compromise when they pinpoint them.

In the meantime, users should be on the lookout for general indicators of compromise, such as:

  • Alerts from intrusion detection, endpoint security, or network monitoring tools involving the PaperCut Application Server (particularly suspicious post-exploitation activity from pc-app.exe)
  • Missing, unexpectedly truncated, or deleted PaperCut server.log files
  • The presence of either ERROR No suitable driver found for jdbc:no:x or ERROR DatabaseUtils – Database error looking up cardID: VALUES CAST in server.log.

But even if they don’t find any, users should restrict access to the Application Server.

“Use firewall rules, network access controls, or equivalent measures to ensure the PaperCut server’s web interfaces cannot be reached from untrusted internet addresses,” the vendor advised.

In 2023, affiliates of the Clop and LockBit ransomware-as-a-service outfits leveraged two known vulnerabilitiesCVE-2023-27350 and CVE-2023-27351 for remote code execution and information disclosure – in the same software.

UPDATE (August 27, 2026, 13:20 a.m. ET):

PaperCut Software has released emergency patches for PaperCut NG and MF versions 25 and 25.

“PaperCut’s security emergency response team has used information provided by a university customer’s security team and digital forensics and incident response team. This information has enabled PaperCut to reproduce a vulnerability in the PaperCut NG and PaperCut MF code,” the company said in an update of the intial advisory.

UPDATE (August 28, 2026, 09:25 a.m. ET):

PaperCut Software has identified the two vulnerabilities chained in these attacks and urged users to install a second patch.

CVE-2026-82078 stems from unsafe dynamic class loading in the database connection utilities of PaperCut MF and PaperCut NG, and CVE-2026-81578 is an improper access control vulnerability in the web management interface of the two solutions.

The latter allows unauthenticated remote attackers to modify certain system configurations, and the former to execute arbitrary Java bytecode.

“Following further work with our internal security team and external researchers, including Huntress and watchTowr, we have released an updated Emergency Patch (Release 2) that includes additional hardening beyond the original emergency patch. We recommend all customers install Release 2, even if you have already applied the original emergency patch,” the vendor advised.

“Huntress has seen limited exploitation on two customer environments; post-exploitation activity included base64-encoded commands executed on the targeted server that decoded to commands (whoami & ver) that aimed to identify the victim’s user account and operating system,” Huntress researchers John Hammond and Andrew Brandt shared.

“Huntress also reproduced a pre-authentication, remote configuration takeover and a complete remote code execution chain against a stock installation of PaperCut NG 25.0.11.75758, the previous public version listed in PaperCut’s 25.0 release history.”

The headline and lead of this article have been changed to reflect the newest findings regarding these active attacks.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/08/27/papercut-ng-mf-vulnerability-attack/