importantSYS.SOURCE: The Hacker News• 2026-08-28T22:42:15+05:30
Exploitation of Chained PaperCut Vulnerabilities for Unauthenticated Remote Code Execution
Attackers are exploiting two unpatched vulnerabilities in PaperCut NG and MF to achieve unauthenticated remote code execution by chaining CVE-2026-82078 (9.4 CVSS) and CVE-2026-81578 (8.8 CVSS), prompting urgent patching recommendations from security researchers.
Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening.
"This vulnerability gives an unauthenticated attacker remote control over PaperCut's trusted configuration, which could be used to execute arbitrary Java code inside the application's
*** END OF TRANSMISSION ***