PaperCut Issues Second Emergency Patch for Actively Exploited RCE Vulnerabilities
PaperCut has released a second emergency patch addressing two critical flaws, CVE-2026-81578 and CVE-2026-82078, affecting its MF and NG print management software. The vulnerabilities chain an authentication bypass with insecure dynamic class loading, allowing unauthenticated attackers to execute Java code with SYSTEM-level privileges on the server. The initial fix left residual bypass vectors, making the Release 2 update mandatory for full remediation. Active exploitation has been confirmed, with attackers observed stealing credentials, deploying additional payloads, and moving laterally within networks. Administrators are urged to apply Release 2 immediately and restrict management interface access to trusted IPs or VPNs.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in