Particle.news

PaperCut Issues Emergency Patches After Pre‑Auth Remote Code Execution Flaws

Unauthenticated vulnerabilities let attackers run Java code and alter server settings, leaving internet‑reachable PaperCut installs exposed until patches are widely applied.

Overview

  • PaperCut disclosed on Thursday, Aug. 27 that it is investigating confirmed customer incidents and released emergency patches after researchers reported active exploitation.
  • Two linked flaws were assigned CVE‑2026‑81578, an authentication/authorization bypass that lets attackers trigger privileged actions, and CVE‑2026‑82078, unsafe dynamic Java class loading that enables arbitrary Java bytecode execution.
  • Security firms including Huntress, Rapid7 and watchTowr reproduced the full exploit chain, found evidence of attacks against at least two customers, and published forensic indicators such as malicious .class files and Derby DB log entries.
  • Despite emergency updates and a hardened follow‑up release, roughly 47% of tracked PaperCut deployments remain on older, unpatched versions and are advised to remove public internet access or place management interfaces behind VPNs.
  • Responders are urged to preserve logs before rebooting, hunt for indicators of compromise (unexpected .class files, pc-app.exe spawning system commands, and Derby entries like memory:pwn), and treat investigations as high priority while fixes for older branches are completed.