PaperCut issues emergency patches as threat actors target chained vulnerabilities
PaperCut released an emergency patch on Friday to fix critical vulnerabilities in its print management software. The company confirmed that multiple customers were targeted in directed attacks and collaborated with security researchers from Huntress and watchTowr in response. The vulnerabilities involve improper access control and insecure dynamic class loading, which can be chained to achieve unauthorized full compromise.

PaperCut issued emergency patches on Friday to address critical vulnerabilities in its print-management software.
The company confirmed in a security advisory that multiple customers were successfully targeted and that it is working with security researchers at Huntress and watchTowr to respond to the attacks.
The vulnerabilities include an improper access-control flaw in PaperCut MF and PaperCut NG. Tracked as CVE-2026-81578, this flaw enables an unauthenticated attacker to modify certain system configurations. An unsafe dynamic class loading flaw, tracked as CVE-2026-82078, enables an attacker to execute arbitrary Java bytecode.
“The exploit technique is chaining these two flaws together for a “point and shoot” full compromise,” John Hammond, senior principal security researcher at Huntress, told Cybersecurity Dive.
Hammond said two confirmed exploitation cases last week involved early-stage reconnaissance. He warned that exploitation could quickly escalate, as no username or password is required, and an attacker needs only a target IP address or hostname to fully compromise the server.
Huntress was able to reproduce a proof-of-concept exploit and uncovered a bypass route against the first set of patches issued by PaperCut. Hammond confirmed that the second set of patches are holding up against the Huntress proof of concept.
Huntress is urging any users to remove the application server from the public-facing internet and limit any access to trusted networks.
Researchers at watchTowr were also able to reproduce the vulnerabilities and discovered bypasses of the initial patches, according to a LinkedIn post.
Cybersecurity firm Rapid7 also confirmed it has multiple customers that have been compromised. Researchers have seen hackers take additional actions once they gain access to a compromised host.
“We have observed threat actors bringing their own remote-management tools to maintain persistence, elevate privileges, and attempt to laterally move,” Seth Lazarus, senior manager, detection and response services at Rapid7, told Cybersecurity Dive.
PaperCut previously came under serious attack in 2023. At the time, the FBI and Cybersecurity and Infrastructure Security Agency warned about multiple threat actors targeting a critical vulnerability in the software.
CISA on Friday added CVE-2026-81578 to its Known Exploited Vulnerabilities catalog, further adding CVE-2026-82078 on Monday. The agency gave a Sept. 11 deadline for Federal Civilian Branch Agencies to remediate for the first flaw and Sept. 14 for the second.
If a customer believes their server has been compromised, PaperCut recommends securing existing server backups, wiping and rebuilding the application server and restoring a clean backup.
On Monday, researchers from watchTowr confirmed they are seeing an escalation in threat activity. Hackers are engaged in hands-on-keyboard interaction, moving well beyond the probing activity observed last week.
Huntress researchers said the number of infected devices reached about a dozen. The main sectors being targeted are education, healthcare and construction. Most of the confirmed cases are in the U.S., and some are in Denmark and Ireland.
PaperCut on Tuesday announced the release of a third emergency patch, noting the update addressed all known security issues in the two earlier patches.
The new patch specifically addresses broken login flows in Security Assertion Markup Language. In addition, the patch restores support for anyone using legacy Microsoft SQL Server drivers for external-card lookup.
The company also released a detailed breakdown of the incident, which unfolded Aug. 27 after an education-sector customer reported a suspected compromise.
Researchers at Shadowserver Foundation said compromises in the software have been confirmed since Aug. 27. Shadowserver says 204 instances were still at risk of remote code execution Monday. About 60 of those are in the U.S
Editor’s note: Updates with new information from watchTowr, Huntress, PaperCut and Shadowserver Foundation.