Close-up of a finger with a small paper cut, resting near a keyboard and printed documents.

CISA Mandates PaperCut Patch After Chained RCE Bugs Hit KEV List

CISA’s KEV listing now gives federal agencies until Sept. 14 to patch unauthenticated code execution on PaperCut servers.

Two chained PaperCut NG/MF vulnerabilities that hand unauthenticated attackers full remote code execution on print servers have escalated into a federal patch mandate, with CISA adding both flaws to its Known Exploited Vulnerabilities catalog Aug. 31 and setting a Sept. 14 deadline for federal civilian agencies after confirming active exploitation.

PaperCut’s own advisory warns it is “aware of confirmed customer incidents” and is treating the matter as a security emergency. The company has not disclosed who is behind the exploitation or what the attackers’ end goal is.

The flaws affect PaperCut’s print-management software, which the company says is deployed by more than 85,000 organizations and 125 million individual users worldwide. However, only a fraction of those users are exposed to the attack chain, according to the KEV description (CVE-2026-81578). A single exposed server can equate to anywhere from a small office of users to an entire hospital network.

Beyond the Break weekly cybersecurity newsletter — Subscribe

The ShadowServer Foundation counts roughly 1,000 PaperCut servers reachable from the open internet, concentrated in North America and Europe.

Organizations running internet-facing PaperCut NG/MF Application Servers should apply the second emergency patch, covering versions 24, 25 and 26, and restrict web access to trusted IP addresses in the meantime.

One (CVE-2026-81578) of the flaws is an authentication-bypass bug that carries a CVSS score of 8.8 and impacts PaperCut’s web management interface. The second flaw, tracked as CVE-2026-82078 with a CVSS rating of 9.4, is an unsafe dynamic-class-loading flaw in PaperCut’s database connection utilities.

PaperCut’s own security bulletin says an attacker who manipulates those configuration parameters can then force the server to execute “arbitrary Java bytecode residing on the application classpath.” That means attacker-supplied code runs with the same privileges as the PaperCut server process itself and not in a sandboxed or restricted context.

Chained together, the two bugs give an attacker pre-authentication remote code execution on any internet-exposed PaperCut Application Server.

PaperCut first disclosed the issue Aug. 27 and shipped an emergency patch the next day. A second emergency release followed hours later after researchers at watchTowr and Huntress found ways around the initial fix. [note: “Huntress” here has no direct link of its own — the only Huntress link in the piece is attached to “issue Aug. 27” above, two sentences earlier. Consider whether Huntress deserves its own citation at the actual claim it’s making — the patch-bypass finding.] Huntress said it observed exploitation in two customer environments as of Aug. 27 and separately reproduced the full attack chain against a stock PaperCut NG installation.

PaperCut’s last major exploited vulnerability, CVE-2023-27350, was published in May 2023 and ultimately linked to multiple ransomware operations, including Clop and LockBit, as well as Iranian state-backed hacking groups and the Bl00dy gang. CISA’s KEV catalog currently lists three prior PaperCut flaws, two of which carry confirmed ransomware ties.

PaperCut’s 2023 authentication-bypass vulnerability, CVE-2023-27350, became a go-to initial-access vector for ransomware crews within weeks of disclosure. The fact that Huntress needed a second patch to close the hole suggests defenders are on a shorter runway than usual.

The same KEV-to-ransomware pipeline played out with Palo Alto’s PAN-OS firewalls earlier this year. Yet to be seen is whether ransomware affiliates treat the most recent chained vulnerabilities as a fresh opportunity the way they did when promptly exploiting the 2023 bug, or whether defenders have time to get ahead of exploitation for once.

Total
0
Shares
Previous Article
Weathered highway billboard reading “Please Clean Up Active Directory” above congested traffic, illustrating basic cybersecurity weaknesses amid growing AI cyber threats.

The AI Cybersecurity Revolution Meets the Default Password

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading