logo

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

ID: 657a0feb-e7c2-5f6f-a80f-887f9b85865e

STIX ID: report--657a0feb-e7c2-5f6f-a80f-887f9b85865e

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-08-28

Date Updated: 2026-08-29

Author: [email protected] (The Hacker News)

...
...

A pair of critical flaws in PaperCut NG/MF (CVE-2026-82078 and CVE-2026-81578) have been publicly disclosed and patched after evidence of limited in-the-wild exploitation; attackers chain an authentication bypass to modify configuration and trigger unsafe dynamic class loading to achieve remote code execution. Observed post-exploitation includes Base64-encoded commands, a platform-agnostic Java .class that fingerprints hosts and lists files, and deletion of log/artifact files (e.g., Udydn.out, server.log, derby.log). Organizations are urged to remove public exposure, apply emergency patches, restrict admin access to trusted networks, and hunt for specific IOCs and log errors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.