we_are_coded.by CODE · The world, decoded
БГ
PaperCut

Two PaperCut flaws entered the actively exploited catalogue, and they chain together

CISA · event date: 31 August 2026Security

On 31 August CISA added CVE-2026-82078 and CVE-2026-81578 in PaperCut NG and MF to the KEV catalogue. The two chain into code execution. The vendor said on 27 August that it was investigating active exploitation, and advises closing the web interface to the internet immediately.

In short
  • CVE-2026-81578 (CVSS 8.8): under specific conditions a request without a password can change certain server settings.
  • CVE-2026-82078 (CVSS 9.4): through those settings an attacker reaches Java code execution with the privileges of the PaperCut process.
  • Emergency patches have been shipping since 28 August; the first step is web interface access from trusted addresses only.
Checked on1 October 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

The print server. Nobody counts it as the perimeter, until it turns out to be on it.

PaperCut counts who prints what, and its website lists schools, universities and hospitals among its customers. Now that very server is a target.

The facts: on 31 August 2026 CISA added two vulnerabilities in PaperCut NG/MF to the Known Exploited Vulnerabilities catalogue, with a federal deadline of 14 September. CVE-2026-81578 is missing authentication for a critical function in the web management interface: under specific conditions, unauthenticated requests to administrative functions can trigger actions before access checks complete and modify certain system configurations (CVSS 4.0: 8.8). CVE-2026-82078 is unsafe dynamic class loading in the database connector: with manipulated configuration it allows execution of Java bytecode on the application classpath with the privileges of the PaperCut server process (CVSS 4.0: 9.4). CISA notes the two can be chained. PaperCut's bulletin was published on 27 August, applies to all versions of NG and MF and describes an investigation into active exploitation. An emergency patch for versions 25 and 26 shipped on 28 August, a second, hardened release of the patch and a build for version 24 followed the same day, and additional indicators of compromise were added on 30 August.

The chain is textbook, and that is exactly why it is dangerous. The first flaw can let a stranger change settings without a password. The second turns settings into code execution. Separately they are unpleasant. Together they are an open door.

The first flaw gives access to the settings. The second turns the settings into a command.

What you do today

PaperCut states the first step without hedging: if your server is reachable from the internet, restrict web interface access to trusted addresses only, immediately, even if you have seen nothing suspicious. Then the patch, then the logs.

In server.log you look for lines with No suitable driver found for jdbc:no:x and card-number lookup errors starting with VALUES CAST. Those are the traces the vendor itself gives. Their absence does not mean you are clean, and the vendor says that too.

The printer is the last place you look for a breach, which is why it is the first thing you check this week.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→CISA - Known Exploited Vulnerabilities Catalog→PaperCut - URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27.08.2026)
Original: https://wearecoded.com/en/articles/papercut-dve-dupki-v-kev.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news