Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
Reported exploitedPaperCutOur summary
Threat actors are actively exploiting a combination of two newly disclosed vulnerabilities in PaperCut NG and MF to achieve remote code execution without authentication. By chaining the improper access control flaw (CVE-2026-81578, CVSS 8.8) with an unsafe dynamic class loading issue (CVE-2026-82078, CVSS 9.4), attackers can bypass permission checks and execute arbitrary Java code on affected servers. PaperCut has released an emergency patch that includes additional hardening measures, and organizations are strongly advised to remove public exposure to these instances immediately while applying the update.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.