This is not a theoretical bug waiting for a conference talk. CISA says attackers are already exploiting two PaperCut vulnerabilities, and PaperCut says it has confirmed incidents affecting customers.
CVE-2026-81578 lets an unauthenticated remote attacker modify certain system configuration values because an authorization check is missing. CVE-2026-82078 involves unsafe reflection and dynamic class loading. PaperCut says the flaws can be chained so a manipulated configuration causes arbitrary Java bytecode already on the server classpath to execute under the PaperCut server's privileges.
Every supported PaperCut NG and MF version is affected, according to the vendor. CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog on August 31 and set a September 14 remediation deadline for federal agencies. The catalog does not currently identify known ransomware use.
PaperCut's immediate guidance is blunt: restrict public web access to trusted source addresses, then install Emergency Patch Release 2 for versions 24, 25, or 26. Customers who installed the first emergency patch still need the second. The vendor also published indicators involving suspicious child processes from the PaperCut application and remote-access tooling that defenders can use during triage.
The lesson is bigger than print management. Configuration is executable intent in modern infrastructure. If an attacker can rewrite the values that decide what gets loaded, the line between changing a setting and running code disappears. Patch now, isolate what never needed public exposure, and check the machine's history before calling the incident closed.
LaunchPad positionRestrict public access immediately, install PaperCut's second emergency patch, and investigate for compromise. A fixed server can still be a previously owned server.
This report draws on the linked primary sources and reputable reporting. Company statements are treated as claims until independently demonstrated.
