Two zero-day vulnerabilities hit PaperCut NG/MF: emergency for 200,000 global installations
PaperCut Software has issued an urgent security advisory regarding two zero-day vulnerabilities (CVE-2026-82078 and CVE-2026-81578) actively exploited in attacks against PaperCut NG and PaperCut MF print management solutions. The vulnerabilities affect versions 25 and 25.1 of the software, widely used in corporate, educational, and institutional environments.
Quick Response
- Vulnerabilities CVE-2026-82078 and CVE-2026-81578 allow remote code execution and unauthorized changes to system configurations
- PaperCut has released emergency patches for versions 25 and 25.1 of the software
- The attacks exploit the PaperCut Application Server, the core component of the system
- Organizations must immediately restrict access to the Application Server from untrusted IPs
Technical details of the vulnerabilities
The vulnerability CVE-2026-82078 stems from unsafe dynamic loading of classes in the database connection utilities of PaperCut MF and NG. This flaw allows attackers to execute arbitrary Java bytecode. The second vulnerability, CVE-2026-81578, is an access control issue that allows remote, unauthenticated attackers to modify certain system configurations.
Compromise indicators
PaperCut has identified several indicators of compromise to monitor:
- Suspicious activity detected by intrusion detection tools, endpoint security, or network monitoring, especially post-exploitation activity from pc-app.exe
- Missing, anomalously truncated, or deleted server.log files
- Presence of specific errors in server logs such as "ERROR No suitable driver found for jdbc:no:x" or "ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST"
Immediate mitigation measures
The vendor recommends immediately implementing the following countermeasures:
- Restrict access to the Application Server via firewall rules or network access controls
- Ensure that server web interfaces are not reachable from untrusted IP addresses
- Install the emergency patches released by PaperCut, particularly the updated version (Release 2) that includes additional security improvements
History and previous attacks
This is not the first attack against PaperCut NG/MF. In 2023, affiliates of the Clop and LockBit ransomware groups exploited two other vulnerabilities (CVE-2023-27350 and CVE-2023-27351) to execute remote code and disclose information. These vulnerabilities had been publicly reported, but the current situation involves zero-day flaws previously unknown.
Analysis of current attacks
Huntress Labs, a cybersecurity company involved in incident response, reported observing limited exploitation activity in two customer environments. The attackers executed base64-encoded commands that decoded into system commands like "whoami" and "ver" to identify the victim's user account and operating system. Huntress also implemented additional security measures to protect their customers.
Challenges in incident response
Organizations are facing difficulties in precisely identifying suspicious activities. System logs often do not fully capture interactions with the Application Server, making it difficult to reconstruct the timeline of events. To address this gap, some companies are implementing advanced logging solutions like Wazuh or Graylog, which offer more granular visibility into system activities.
Another obstacle is the fragmentation of IT environments. Many organizations use different versions of PaperCut NG/MF, some still on obsolete, unsupported versions. This creates a heterogeneous landscape where some machines may be protected while others remain exposed, complicating mitigation efforts.
Legal and insurance implications
Cyber insurance companies are reviewing their policies in response to these vulnerabilities. Some have begun requiring organizations to demonstrate the application of the latest patches as a condition for coverage. An insurance provider reported a 30% increase in risk assessment requests related to print management solutions.
From a legal perspective, companies may face claims of liability for data breaches, although it is not yet clear if the current attacks have led to actual breaches. Privacy lawyers are advising organizations to meticulously document all mitigation efforts to demonstrate "due diligence" in case of future litigation.
Technological innovations in response
Some companies are exploring alternative print management solutions that may offer a more robust security profile. Among these, PaperCut is considering the integration of hardware-based multi-factor authentication (MFA) technologies, such as YubiKey, for administrative interfaces. This additional measure could make it more difficult for attackers to exploit vulnerabilities even if they gain initial access.
Another innovative approach is the use of containerization to isolate the Application Server. Some organizations are experimenting with implementing PaperCut within Docker environments with strict network restrictions, thereby limiting the potential impact of any compromises.
Preparation for the future
Cybersecurity experts recommend that organizations adopt a proactive approach to risk management. This includes regularly simulating attack scenarios, training personnel on print infrastructure security, and creating dedicated response teams. A consulting firm has developed a specific framework for assessing the risk of print management solutions, which is gaining popularity among large enterprises.
Finally, it is crucial to maintain open lines of communication with the vendor. PaperCut has established a security coordination center where users can report incidents and receive real-time updates. This level of transparency and collaboration is essential for effectively addressing evolving threats like the current ones.
Additional resources
For more information, users can consult:
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not engage in real-time information activities.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the improper use of the information published.
In the Crypto sector, every investment involves risks: readers are invited to always inform themselves independently before making any decision.