PaperCut Zero-Days Under Active Exploit Despite Two Patches

CVE-2026-81578 and CVE-2026-82078 allow unauthenticated RCE on PaperCut NG/MF versions 24-26; WatchTowr found patch bypasses forcing second emergency patch.
Table of Contents
    Add a header to begin generating the table of contents

    Two zero-day vulnerabilities tracked as CVE-2026-81578 (high-severity authentication bypass) and CVE-2026-82078 (critical unsafe dynamic class loading) are being actively exploited against PaperCut NG/MF versions 24 through 26, allowing unauthenticated attackers to bypass authentication and achieve remote code execution, according to analysis published August 31 by security firms Huntress and WatchTowr following PaperCut’s August 27 security bulletin and two emergency patches released August 28. WatchTowr discovered “multiple patch bypasses and an additional authentication bypass flaw” after the first emergency patch, prompting PaperCut to release a second emergency patch the same day.

    CVE-2026-81578 Authentication Bypass and CVE-2026-82078 Unsafe Dynamic Class Loading Chained for Unauthenticated RCE

    CVE-2026-81578, rated high severity, permits authentication bypass, while CVE-2026-82078, rated critical, involves unsafe dynamic class loading. Together, the vulnerabilities allow unauthenticated attackers to bypass authentication and execute arbitrary code remotely on affected PaperCut NG and MF print management servers. Huntress and WatchTowr initially believed a single vulnerability was being exploited but later identified two distinct zero-days under active exploitation.

    The authentication bypass (CVE-2026-81578) allows attackers to gain unauthorized access to PaperCut’s administrative interface without providing valid credentials. The unsafe dynamic class loading flaw (CVE-2026-82078) permits attackers to force the application to load and execute arbitrary code by manipulating class loading mechanisms. When chained together, the two vulnerabilities enable a complete compromise: an unauthenticated attacker bypasses login protections and then uses the class loading flaw to execute malicious code on the server, achieving full remote code execution without any user interaction or privileged access required.

    WatchTowr Discovered Multiple Patch Bypasses and Additional Authentication Bypass After First August 28 Patch

    PaperCut issued its initial security bulletin on August 27 and released a first emergency patch on August 28. WatchTowr’s subsequent analysis uncovered multiple patch bypasses and an additional authentication bypass flaw, forcing PaperCut to release a second emergency patch on the same day. The rapid patch-bypass-patch cycle demonstrates sophisticated attacker capabilities and the challenge of fully remediating complex authentication and class loading vulnerabilities in a single iteration.

    The patch bypass discoveries suggest that WatchTowr reverse-engineered the first August 28 patch, identified how PaperCut attempted to close the authentication bypass and class loading flaws, and then found alternative exploitation paths that circumvented the patch logic. The discovery of an additional authentication bypass flaw—beyond the original CVE-2026-81578—indicates the authentication subsystem in PaperCut NG/MF versions 24 through 26 contains multiple distinct weaknesses that attackers can exploit to gain unauthorized access.

    Huntress and WatchTowr Analysis: Active Exploitation Against PaperCut NG/MF Versions 24 Through 26

    PaperCut NG and MF are widely deployed across enterprise and institutional environments for centralized print management and cost tracking. The combination of active exploitation, unauthenticated remote code execution, and patch bypasses creates urgent risk for organizations running affected versions 24 through 26. Researchers continue analysis for additional bypass techniques, and organizations were urged to apply the second August 28 emergency patch immediately to address both the original vulnerabilities and the bypass techniques WatchTowr identified.

    The active exploitation status means attackers are already using the vulnerabilities in real-world attacks, not just proof-of-concept demonstrations. Organizations running PaperCut NG or MF versions 24, 25, or 26 face immediate risk of compromise if they have not deployed the second August 28 emergency patch. The unauthenticated remote code execution capability allows attackers to gain full control of the print management server, which often has network access to printers, file shares, and user authentication systems across the enterprise.

    Organizations That Deployed First August 28 Patch Remain Vulnerable Until Second Patch Applied

    The patch bypass discoveries highlight a recurring pattern in critical infrastructure software vulnerabilities: attackers who invest in developing zero-day exploits often also invest in reverse-engineering initial patches to find bypass techniques before organizations complete deployment. PaperCut’s two-patch-in-one-day response reflects the vendor’s recognition that the first patch left exploitable gaps, but it also means organizations that deployed the first August 28 patch remain vulnerable until they deploy the second.

    The two-patch cycle creates a communication and deployment challenge for IT teams: organizations that moved quickly to deploy the first August 28 patch may not have realized they needed to immediately deploy a second patch released hours later. The WatchTowr analysis published August 31 provides public notice of the patch bypass issue, but organizations that do not closely monitor security advisories may remain unaware that the first patch was insufficient.

    Related Posts