Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Active Exploitation of Pre‑Authentication RCE in PaperCut Print Management (CVE‑2026‑81578 & CVE‑2026‑82078)

PaperCut servers are under active attack: two pre‑authentication RCE flaws (CVE‑2026‑81578, CVE‑2026‑82078) are being exploited to run commands without logging in. The issue highlights the need for continuous patch monitoring and robust authorization controls to satisfy audit‑readiness requirements.

LiveThreat™ Intelligence · 📅 August 30, 2026· 📰 securityaffairs.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
4 recommended
📰
Source
securityaffairs.com

Active Exploitation of Pre‑Authentication RCE in PaperCut Print Management (CVE‑2026‑81578 & CVE‑2026‑82078)

What Happened – Researchers at Huntress confirmed that a pre‑authentication remote code execution flaw (CVE‑2026‑81578) in PaperCut NG servers is being actively probed and exploited. A second flaw (CVE‑2026‑82078) can be chained to load arbitrary Java classes, giving an attacker command‑line access without logging in.

Why It Matters for Trust & Control Assurance

  • The attack bypasses normal authorization checks, directly testing the access‑control control objective that underpins many frameworks (e.g., NIST CSF 2.0).
  • Continuous evidence of patch status and exploit detection is essential to demonstrate due‑diligence in audit‑ready environments.
  • The ACCESS_CONTROLS capability helps organizations surface unpatched assets, enforce remediation workflows, and retain defensible logs of remediation actions.

Who Is Affected – Schools, hospitals, and office environments that run PaperCut print‑management servers worldwide.

Recommended Actions

  • Verify your PaperCut version; upgrade immediately to the patched release (≥ 25.0.12).
  • Deploy a continuous patch‑management feed that flags CVE‑2026‑81578/82078 across all managed endpoints.
  • Enable detailed request‑logging and monitor for anomalous “page‑display vs. action” requests.
  • Conduct a short‑term audit of authorization logic in custom integrations.

Source: Security Affairs

Technical Notes – The vulnerability stems from an authorization mistake where the server validates the displayed page rather than the action executed. Exploitation drops a malicious Java class into the installation directory, runs commands (e.g., whoami, ver, tasklist), and deletes its own logs. No secondary malware or C2 traffic was observed.

📰 Original Source
https://securityaffairs.com/198107/uncategorized/hackers-are-probing-papercut-servers-and-47-still-have-no-patch.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Could you prove your access controls held up here?

Credential and access failures map directly to identity and access-control requirements in every major framework. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →