CISA Warns of Active Exploitation of Critical PaperCut Print Software Flaws
A vulnerability chain allowing remote code execution has forced emergency patching for widely used print management systems.
Threat actors are actively exploiting a critical vulnerability chain in PaperCut NG and MF print management software to gain unauthorized access to application servers. The exploit allows unauthenticated attackers to execute arbitrary commands, potentially leading to full system compromise and lateral movement within corporate or institutional networks.
The attack relies on chaining two specific flaws: CVE-2026-81578, which provides an authentication bypass, and CVE-2026-82078, which enables remote code execution (RCE). By combining these, attackers can modify server configurations and deploy malicious Java bytecode to execute commands or install backdoors. The severity of the threat was underscored on August 31, 2026, when the Cybersecurity and Infrastructure Security Agency (CISA) added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog.
Patching Challenges
PaperCut NG and MF are ubiquitous print management solutions utilized across a variety of corporate and educational environments. The urgency of the situation was heightened when an initial emergency patch released by the vendor was found to be insufficient. Security researchers discovered that the first fix could be bypassed, necessitating a second, more robust update. In response, PaperCut released "Emergency Patch Release 2" on August 28, 2026, to effectively close the security gaps.
Industry Implications
Because the exploit chain allows for pre-authentication remote code execution, the impact is significant. An attacker does not need valid credentials to enter the system, making the print server a primary entry point into a broader network. Once the server is compromised, attackers can steal sensitive administrative credentials, which often serve as a stepping stone for larger-scale data breaches or the deployment of ransomware across the organization's infrastructure.
Current Outlook
Organizations using PaperCut NG or MF are urged to verify that they have applied Emergency Patch Release 2 immediately. While the technical details of the CVE chain are confirmed, security teams should remain vigilant for signs of unauthorized Java class files or unexpected configuration changes on their print servers. The primary focus for administrators now is ensuring that no legacy versions of the software remain exposed to the internet, as the CISA KEV listing confirms that these flaws are being actively weaponized in the wild.