Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Exploited PaperCut Flaws Allow Unverified Code Execution

Exploited PaperCut Flaws Allow Unverified Code Execution

Posted on August 28, 2026 By CWS

Recent security breaches have revealed the exploitation of critical vulnerabilities in PaperCut NG and MF, enabling unauthorized code execution on affected systems. Detailed analysis by Huntress researchers highlights the potential risks associated with these flaws.

Understanding the Vulnerabilities

Huntress researchers, John Hammond and Andrew Brandt, have identified that attackers can manipulate an unauthenticated request to alter server configurations, leading to arbitrary Java code execution within PaperCut processes. This vulnerability allows unauthorized control over PaperCut’s trusted settings, posing significant security risks.

The exploitation occurs when attackers use a crafted request to access a page rendered for response while executing actions from another page. This bypasses authorization checks, granting access to sensitive endpoints and allowing malicious code execution.

Detailed Breakdown of Security Flaws

PaperCut has publicly disclosed two major vulnerabilities: CVE-2026-82078 and CVE-2026-81578. CVE-2026-82078 is a severe dynamic class loading flaw in the database connection utilities, with a CVSS score of 9.4, permitting unsafe instantiation of database driver classes.

Meanwhile, CVE-2026-81578, rated 8.8 on the CVSS scale, involves improper access control in the web management interface. It allows unauthenticated remote requests to trigger backend actions before access validation is complete, further endangering system integrity.

Impact and Response

The urgency of addressing these vulnerabilities is underscored by the release of a second emergency patch by PaperCut, aimed at further hardening systems beyond the initial fix. However, details on the malicious activities exploiting these flaws remain undisclosed.

Jake Knott from watchTowr highlights that attackers are chaining both vulnerabilities to bypass authentication, exploiting them for remote code execution. The discovery of multiple patch bypasses indicates ongoing risks, emphasizing the need for immediate system updates.

Huntress has observed limited exploitation in client environments, with attackers using Base64-encoded commands to gather user and system information. Additionally, a Java .class file has been deployed to execute cross-platform commands, creating and subsequently deleting files to cover tracks.

Recommendations for Organizations

Organizations using PaperCut NG and MF are urged to remove public exposure of their systems and apply the latest patches promptly. Restricting access to trusted IPs or using a VPN is also advised to enhance security.

Given the potential for data exfiltration through printed documents, entities must actively search for compromise indicators, such as specific database errors in log files, to mitigate the risks of these vulnerabilities.

The Hacker News Tags:authentication bypass, code execution, CVE-2026-81578, CVE-2026-82078, Cybersecurity, Huntress, PaperCut, Security, Vulnerability, WatchTowr

Post navigation

Previous Post: AI-Boosted Ransomware Analyzes Vast Data Quickly

Related Posts

New ‘Plague’ PAM Backdoor Exposes Critical Linux Systems to Silent Credential Theft New ‘Plague’ PAM Backdoor Exposes Critical Linux Systems to Silent Credential Theft The Hacker News
ServiceNow Security Breach Allows Unauthorized Access ServiceNow Security Breach Allows Unauthorized Access The Hacker News
Chinese Hackers Use Fake Tax Tools in India to Deploy DcRAT Chinese Hackers Use Fake Tax Tools in India to Deploy DcRAT The Hacker News
Hackers Exploiting Triofox Flaw to Install Remote Access Tools via Antivirus Feature Hackers Exploiting Triofox Flaw to Install Remote Access Tools via Antivirus Feature The Hacker News
Critical Flaw in ChatGPT Agents Allows Rogue AI Deployment Critical Flaw in ChatGPT Agents Allows Rogue AI Deployment The Hacker News
New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Exploited PaperCut Flaws Allow Unverified Code Execution
  • AI-Boosted Ransomware Analyzes Vast Data Quickly
  • Russian Hackers Exploit New Malware to Target European Entities
  • APT28’s HOOKEDGE Backdoor Targets European Entities
  • Cybersecurity Roundup: Log4j Concerns, Minimus Closure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Exploited PaperCut Flaws Allow Unverified Code Execution
  • AI-Boosted Ransomware Analyzes Vast Data Quickly
  • Russian Hackers Exploit New Malware to Target European Entities
  • APT28’s HOOKEDGE Backdoor Targets European Entities
  • Cybersecurity Roundup: Log4j Concerns, Minimus Closure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark