Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
PaperCut Releases Urgent Patch for Zero-Day Vulnerabilities

PaperCut Releases Urgent Patch for Zero-Day Vulnerabilities

Posted on August 31, 2026 By CWS

PaperCut Software has issued a crucial second emergency patch to address newly discovered zero-day vulnerabilities in its NG and MF print management software. These vulnerabilities have been actively exploited, prompting the company to enhance its security measures.

Details of the Vulnerability Exploits

Unauthenticated attackers can leverage these zero-day vulnerabilities to bypass authentication mechanisms and execute remote code on compromised PaperCut NG/MF systems. The initial security advisory was released by PaperCut on August 27, followed by a first emergency patch the subsequent day. A second patch was also released to provide further security reinforcements, extending support to version 24 and offering indicators of compromise (IoCs).

Earlier assumptions suggested a single vulnerability was exploited; however, PaperCut, along with security firms Huntress and WatchTowr, confirmed that two distinct zero-days were targeted. The first, CVE-2026-81578, is a high-severity flaw that enables unauthenticated remote attackers to alter system configurations. The second, CVE-2026-82078, involves unsafe dynamic class loading, posing critical risks.

Security Measures and Discoveries

PaperCut’s advisory elaborated on the potential consequences of these exploits, emphasizing the risk of arbitrary Java bytecode execution within the security context of the server process. The company is actively working on an official patch to address both vulnerabilities fully.

WatchTowr identified multiple patch bypasses and an additional authentication flaw, which necessitated the release of the second emergency patch. Huntress reported observing early exploitation attempts as of August 26, indicating system reconnaissance activities, though no secondary malware or persistent threats have been detected so far.

Current Impact and Outlook

The identity and motives of the threat actors exploiting these zero-days remain unknown. However, the exploitation of vulnerabilities in PaperCut NG/MF is not unprecedented, as highlighted by CISA’s Known Exploited Vulnerabilities catalog, which lists similar past incidents, including ransomware attacks.

According to ShadowServer Foundation data, around 1,000 PaperCut instances are exposed online, primarily in North America and Europe. Cybersecurity stakeholders urge vigilance and recommend all users apply the latest patches to safeguard their systems against potential attacks.

As the situation develops, PaperCut continues to update stakeholders and works towards a comprehensive fix for the identified security flaws. Users are advised to stay informed and apply security updates promptly to mitigate risks.

Security Week News Tags:authentication bypass, CVE-2026-81578, CVE-2026-82078, Cybersecurity, Huntress, IoCs, PaperCut, remote code execution, security patch, Shadowserver Foundation, Vulnerabilities, WatchTowr, zero-day

Post navigation

Previous Post: Cyberattack Targets Claude AI with Infostealer Malware
Next Post: DoJ Revises China Hacking Statement, Targets Identified

Related Posts

Four Arrested in UK Over M&S, Co-op Cyberattacks Four Arrested in UK Over M&S, Co-op Cyberattacks Security Week News
Google DeepMind Identifies Web Threats to AI Agents Google DeepMind Identifies Web Threats to AI Agents Security Week News
Microsoft Says Chinese APTs Exploited ToolShell Zero-Days Weeks Before Patch Microsoft Says Chinese APTs Exploited ToolShell Zero-Days Weeks Before Patch Security Week News
Surf AI Secures M for Innovative Security Operations Surf AI Secures $57M for Innovative Security Operations Security Week News
RondoDox Botnet Expands to 174 Vulnerabilities RondoDox Botnet Expands to 174 Vulnerabilities Security Week News
Security Firm Andy Frain Says 100,000 People Impacted by Ransomware Attack Security Firm Andy Frain Says 100,000 People Impacted by Ransomware Attack Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Security Vulnerability in Composer Exposes Sensitive Files
  • DoJ Revises China Hacking Statement, Targets Identified
  • PaperCut Releases Urgent Patch for Zero-Day Vulnerabilities
  • Cyberattack Targets Claude AI with Infostealer Malware
  • TerminalFix Exploits Fake CAPTCHAs to Install Backdoor

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Security Vulnerability in Composer Exposes Sensitive Files
  • DoJ Revises China Hacking Statement, Targets Identified
  • PaperCut Releases Urgent Patch for Zero-Day Vulnerabilities
  • Cyberattack Targets Claude AI with Infostealer Malware
  • TerminalFix Exploits Fake CAPTCHAs to Install Backdoor

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark