AI Stories on SHORT INFO are generated & curated with AI
3 linked sources 30 Aug, 16:11

Two chained PaperCut zero-day flaws are under active exploitation, forcing a second emergency patch

PaperCut says hackers are actively exploiting two chained vulnerabilities in its NG and MF print management software to bypass authentication and run code on servers. A second emergency patch shipped after researchers found ways around the first fix. Per BleepingComputer, The Hacker News and PaperCut's own security advisory.

PaperCut disclosed that two chained vulnerabilities, CVE-2026-81578 (authentication bypass, CVSS 8.8) and CVE-2026-82078 (unsafe dynamic class-loading enabling remote code execution, CVSS 9.4), are being actively exploited against PaperCut NG and MF print management servers. PaperCut shipped an initial emergency patch on August 27, 2026, but researchers at watchTowr and Huntress found multiple ways to bypass it within a day, forcing a second emergency patch, Release 2, on August 28. Huntress says it observed exploitation in two customer environments and reproduced the full pre-authentication remote-code-execution chain; commands captured in server logs so far look like reconnaissance rather than ransomware deployment. PaperCut has not disclosed who is behind the current attacks. A 2023 flaw in the same software was separately exploited by Russian threat actors and the Lace Tempest group to deliver Clop and LockBit ransomware. Sources: BleepingComputer, The Hacker News, PaperCut security advisory.

#cyber
Published on