Security and TerrorismSecurity ThreatsTech

PaperCut servers under active attack: Release 3 patch and warning signs explained

PaperCut has issued a third emergency patch for an actively exploited attack chain affecting PaperCut NG and PaperCut MF. The vendor’s security bulletin, updated September 2, says confirmed customer incidents have occurred and a second wave is targeting servers that remain publicly accessible and are not fully patched.

The US Cybersecurity and Infrastructure Security Agency added both vulnerabilities to its Known Exploited Vulnerabilities catalogue on August 31, with a federal remediation due date of September 14. CISA inclusion is based on evidence of exploitation; it does not mean every PaperCut server has been compromised.

The two vulnerabilities

CVE-2026-81578 is an authentication-bypass flaw in the web management interface. PaperCut says specially formed unauthenticated requests can reach administrative functions before access checks finish and modify some configuration.

CVE-2026-82078 involves unsafe dynamic class loading in database-connection utilities. If an attacker can manipulate the relevant configuration, Java bytecode already placed on the application classpath can be executed under the PaperCut server process.

PaperCut rates the authentication bypass 8.8 and the unsafe-reflection issue 9.4 under CVSS 4.0. The danger comes from chaining the two behaviours: bypassing access controls, changing configuration and reaching code execution.

What administrators should do now

  1. Restrict public access. If an NG/MF Application Server is reachable from the internet, allow only trusted IP addresses using firewall or network controls.
  2. Install Emergency Patch Release 3. It supersedes Releases 1 and 2 and includes their fixes. PaperCut says customers who installed Release 2 should still install Release 3.
  3. Cover related servers. Site Servers and secondary or print servers should also run a patched version, not only the primary Application Server.
  4. Upgrade old releases. Release 3 is provided for supported v24, v25 and v26 installations. PaperCut advises customers on v23 or earlier to upgrade.

PaperCut says Mobility Print and Print Deploy server components, PaperCut Hive and PaperCut Pocket are not affected by this bulletin.

Indicators that require investigation

Potential warning signs include missing or unexpectedly shortened server.log files, unusual database-driver errors, randomly named .class, .cmd or .out files in PaperCut directories, and the PaperCut application process launching command shells. PaperCut also advises checking for an unexpected Windows service named “Remote Access Service” and unapproved AnyDesk installations.

The absence of those signs does not prove a system is clean because attackers may remove files or logs. If compromise is suspected, PaperCut recommends preserving relevant backups, activating the organisation’s incident-response process, wiping and rebuilding the Application Server, and restoring a verified clean backup from before the suspicious activity.

Sources: PaperCut urgent security advisory; CISA Known Exploited Vulnerabilities catalogue.

Screenshot of the official advisory updated September 2, 2026. Source: PaperCut.

Related Articles

Back to top button

Adblock Detected

Please consider supporting us by disabling your ad blocker