CVE Tools

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

The Hacker NewsBy The Hacker News

Reported exploitedPaperCut

Our summary

Threat actors are actively exploiting a combination of two newly disclosed vulnerabilities in PaperCut NG and MF to achieve remote code execution without authentication. By chaining the improper access control flaw (CVE-2026-81578, CVSS 8.8) with an unsafe dynamic class loading issue (CVE-2026-82078, CVSS 9.4), attackers can bypass permission checks and execute arbitrary Java code on affected servers. PaperCut has released an emergency patch that includes additional hardening measures, and organizations are strongly advised to remove public exposure to these instances immediately while applying the update.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store