Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
ID: 657a0feb-e7c2-5f6f-a80f-887f9b85865e
STIX ID: report--657a0feb-e7c2-5f6f-a80f-887f9b85865e
Feed Name: The Hacker News
A pair of critical flaws in PaperCut NG/MF (CVE-2026-82078 and CVE-2026-81578) have been publicly disclosed and patched after evidence of limited in-the-wild exploitation; attackers chain an authentication bypass to modify configuration and trigger unsafe dynamic class loading to achieve remote code execution. Observed post-exploitation includes Base64-encoded commands, a platform-agnostic Java .class that fingerprints hosts and lists files, and deletion of log/artifact files (e.g., Udydn.out, server.log, derby.log). Organizations are urged to remove public exposure, apply emergency patches, restrict admin access to trusted networks, and hunt for specific IOCs and log errors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
