PaperCut NG/MF (CVE-2026-81578)
CVE-2026-81578CWE-305CWE-306OWASP A07:2021CVSS 9.8Updated October 1, 20263 min read
CVE-2026-81578 is an authentication bypass in the web interface of PaperCut NG and MF that lets an unauthenticated attacker change the server's configuration. Chained with CVE-2026-82078 it becomes remote code execution. It was exploited the day before PaperCut's advisory, and within a week one actor had compromised at least 440 servers, according to GreyNoise.
- Affected
- PaperCut NG and PaperCut MF before 24.1.10, 25.0.13 and 26.0.5, including every version 23 and older
- Patched in
- PaperCut NG/MF 26.0.5, 25.0.13 and 24.1.10 (10 September 2026); there is no fix for version 23 and older
- Actively exploited
- yes
On 27 August 2026 PaperCut warned its customers that attackers were exploiting its print management server. Huntress had already seen an attack the day before. Within a week, one actor using AI agents had broken into hundreds of PaperCut servers, nearly half of them in education.
What is CVE-2026-81578
Organisations use PaperCut NG and MF to track, charge and manage printing, copying and scanning. In the administrators’ web interface, unauthenticated requests aimed at administrative functions could trigger actions before the access check had finished. Huntress, which reproduced the attack, found that a crafted request could name one page to render and another page that owns the action, and the authorisation check trusted the first. Anyone who can reach the interface can therefore change the server’s configuration without logging in: broken authentication in its plainest form.
On its own that only changes settings. The second flaw, CVE-2026-82078, removes the limit: PaperCut loads a database driver class by whatever name the configuration holds, without checking it against a list of approved drivers, so an attacker who controls the configuration can run Java code. Together that is remote code execution without an account. On Windows PaperCut runs as SYSTEM by default and is usually joined to the domain, GreyNoise notes. PaperCut publishes only a CVSS v4.0 score of 8.8 for this flaw; NVD scores it 9.8 under CVSS v3.1.
What the attackers did
Huntress saw exploitation as early as 26 August, the day before the advisory, which makes this a zero-day. That attack lasted under two minutes: a Java class file ran whoami & ver, then deleted its own output and the server’s log file. Where endpoint protection did not step in, PaperCut saw attackers look up the domain controllers, install the remote access tool SimpleHelp as a service and download AnyDesk.
A larger wave followed the patches. According to GreyNoise, a “likely Russian-speaking” actor compared the patched and unpatched versions on 31 August, built an exploit with AI and set hundreds of AI agents to work. Between 31 August and 2 September GreyNoise counted at least 440 compromised servers at 395 identified organisations in 48 countries. Its country table lists 15 victims in Germany and 9 in the Netherlands; 204 of the 440 were in education. At 12 organisations the actor became domain administrator and copied every credential in Active Directory.
The Dutch NCSC urged organisations on 28 August to update immediately; CISA added both flaws to its catalogue of exploited vulnerabilities on 31 August. As of 1 October 2026, PaperCut’s latest status update, dated 10 September, says that servers still reachable and unpatched continue to be targeted.
Why PaperCut keeps getting hit
This is the second time in three years. In 2023 CVE-2023-27350, also a route past PaperCut’s login to code execution, was patched in March and exploited from mid-April. According to FBI and CISA, the Bl00dy Ransomware Gang used it against the education sector. PaperCut is common in education: in 2023 CISA found that schools and universities held about 68% of the exposed PaperCut servers in the US, and GreyNoise thinks this year’s concentration of education victims most likely reflects that customer base.
What is new is the speed. GreyNoise reports that the actor went from an empty workspace to code execution at a real victim in just under four hours, and since 3 September the chain has been available as a public Metasploit module. The gap between patch and working exploit is no longer measured in weeks. Old versions make it worse: Huntress found that 47% of the roughly 2,500 PaperCut installations it tracks run version 23 or older, for which no patch exists. That is the risk of outdated components in practice.
What to do now
- Upgrade to PaperCut NG/MF 26.0.5, 25.0.13 or 24.1.10, including site servers and secondary servers. The earlier emergency patches report the same version number as the unpatched release, so only these builds can be verified by version.
- Keep the PaperCut web interface off the internet and limit it to internal addresses or a VPN. On version 23 or older there is no patch: move to a supported version line and restrict access until you have.
- If the server was reachable from the internet before you patched, look for traces: unexpected
.classfiles inserver\lib, missing or truncatedserver.logfiles,pc-app.exestartingcmd.exe, and new remote access services such as SimpleHelp or AnyDesk. - If a domain-joined PaperCut server was compromised, rebuild it and treat the domain’s credentials as stolen.
Sources
- PaperCut: URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026)papercut.com
- NVD: CVE-2026-81578nvd.nist.gov
- Huntress: PaperCut Actively Exploited: A Pre-Auth RCE Chainhuntress.com
- GreyNoise: Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MFgreynoise.io
- NCSC: Kwetsbaarheden in PaperCut MF en NG met actief misbruik: update onmiddellijkncsc.nl
- CISA: Malicious Actors Exploit CVE-2023-27350 in PaperCut MF and NGcisa.gov
Frequently asked questions
Who is behind the attacks?
As of 1 October 2026, no government agency or incident response firm has attributed them to a known group. GreyNoise describes the actor behind the largest wave only as likely Russian-speaking. Huntress, which saw the first attacks, named no one.
Are we safe if PaperCut is not reachable from the internet?
Safer, not safe. Anyone who can reach the web interface from the internal network can still use the flaw. PaperCut advises every customer to upgrade, whether or not the server is on the public internet.
Is patching enough?
Only if nobody got in first. Attackers deleted log files and installed remote access tools, and an upgrade removes neither. PaperCut advises wiping and rebuilding a compromised server and restoring a backup taken before the suspicious activity.
Related articles
- GlossaryZero-dayA zero-day is a vulnerability still unknown to the vendor, meaning no patch exists yet. Learn how zero-day exploits work and how to limit the risk they pose.
- VulnerabilitiesCWE-287A07:2021Broken authenticationBroken authentication explained: how attackers take over accounts through brute force, leaked passwords and predictable session tokens, and how to stop them.
- VulnerabilitiesCWE-1104A06:2021Outdated and vulnerable componentsAn outdated library or web server carries publicly known vulnerabilities with ready-made exploits. Learn how to keep that manageable.
- VulnerabilitiesCWE-94A03:2021Remote code execution (RCE)Remote code execution (RCE) explained: how attackers run their own commands or code on your server through unvalidated input, and how to prevent it.