TechNewsReel
Live

PaperCut Releases Stable Updates for Actively Exploited RCE Chain

New security releases for PaperCut NG/MF resolve a critical vulnerability chain used in remote code execution attacks.

TechNewsReel Newsroom · September 11, 2026

PaperCut has released security updates for PaperCut NG/MF versions 26.0.5, 25.0.13, and 24.1.10 to resolve two critical vulnerabilities. These updates address flaws that have been actively exploited in the wild to gain unauthorized control over application servers.

The vulnerabilities, identified as CVE-2026-81578 and CVE-2026-82078, create a high-risk attack vector when used together. CVE-2026-81578 involves improper access control, while CVE-2026-82078 involves unsafe dynamic class loading. When chained, these flaws allow an unauthenticated attacker to achieve remote code execution (RCE) on the PaperCut Application Server, potentially leading to a full system compromise.

The Path to Exploitation

The crisis emerged in late August 2026 as security researchers and vendors observed active exploitation of these flaws. The attack sequence begins with CVE-2026-81578, which allows an attacker to modify system configurations. This initial breach then enables the exploitation of CVE-2026-82078, allowing the attacker to load arbitrary Java bytecode into the server.

Due to the severity of the threat, the Cybersecurity and Infrastructure Security Agency (CISA) added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on August 31, 2026. This designation mandates that federal agencies patch the flaws quickly and serves as a high-priority warning for private sector organizations.

Why Stability Matters

In the immediate aftermath of the discovery, PaperCut issued a series of emergency patches to mitigate the threat. However, emergency fixes often bypass standard quality assurance and release cycles, which can lead to stability issues or incomplete remediation.

The transition to these latest official versions is critical for enterprise environments. By moving from urgent, temporary patches to fully vetted releases, organizations can ensure that the hardening against RCE is permanent and officially supported. This reduces the risk of regressions—where a previous bug returns—or the possibility that a patch was bypassed by a slightly modified attack method.

Next Steps for Administrators

Administrators running PaperCut NG/MF are urged to verify their current version and update to 26.0.5, 25.0.13, or 24.1.10 immediately. Because these flaws allow for unauthenticated access, the barrier to entry for attackers is low, making the window for patching extremely narrow.

Organizations should also review server logs for any signs of unauthorized configuration changes or unexpected Java class loading that may have occurred prior to patching. While the current releases provide a stable fix, the presence of these flaws in the CISA KEV catalog suggests that threat actors remain interested in targeting print management infrastructure.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.