Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Exploited PaperCut Flaws Allow Unverified Code Execution

Exploited PaperCut Flaws Allow Unverified Code Execution

Posted on August 28, 2026 By CWS

Recent security breaches have revealed the exploitation of critical vulnerabilities in PaperCut NG and MF, enabling unauthorized code execution on affected systems. Detailed analysis by Huntress researchers highlights the potential risks associated with these flaws.

Understanding the Vulnerabilities

Huntress researchers, John Hammond and Andrew Brandt, have identified that attackers can manipulate an unauthenticated request to alter server configurations, leading to arbitrary Java code execution within PaperCut processes. This vulnerability allows unauthorized control over PaperCut’s trusted settings, posing significant security risks.

The exploitation occurs when attackers use a crafted request to access a page rendered for response while executing actions from another page. This bypasses authorization checks, granting access to sensitive endpoints and allowing malicious code execution.

Detailed Breakdown of Security Flaws

PaperCut has publicly disclosed two major vulnerabilities: CVE-2026-82078 and CVE-2026-81578. CVE-2026-82078 is a severe dynamic class loading flaw in the database connection utilities, with a CVSS score of 9.4, permitting unsafe instantiation of database driver classes.

Meanwhile, CVE-2026-81578, rated 8.8 on the CVSS scale, involves improper access control in the web management interface. It allows unauthenticated remote requests to trigger backend actions before access validation is complete, further endangering system integrity.

Impact and Response

The urgency of addressing these vulnerabilities is underscored by the release of a second emergency patch by PaperCut, aimed at further hardening systems beyond the initial fix. However, details on the malicious activities exploiting these flaws remain undisclosed.

Jake Knott from watchTowr highlights that attackers are chaining both vulnerabilities to bypass authentication, exploiting them for remote code execution. The discovery of multiple patch bypasses indicates ongoing risks, emphasizing the need for immediate system updates.

Huntress has observed limited exploitation in client environments, with attackers using Base64-encoded commands to gather user and system information. Additionally, a Java .class file has been deployed to execute cross-platform commands, creating and subsequently deleting files to cover tracks.

Recommendations for Organizations

Organizations using PaperCut NG and MF are urged to remove public exposure of their systems and apply the latest patches promptly. Restricting access to trusted IPs or using a VPN is also advised to enhance security.

Given the potential for data exfiltration through printed documents, entities must actively search for compromise indicators, such as specific database errors in log files, to mitigate the risks of these vulnerabilities.

The Hacker News Tags:authentication bypass, code execution, CVE-2026-81578, CVE-2026-82078, Cybersecurity, Huntress, PaperCut, Security, Vulnerability, WatchTowr

Post navigation

Previous Post: AI-Boosted Ransomware Analyzes Vast Data Quickly
Next Post: Android 17 Enhances Privacy with OS-Wide ECH Integration

Related Posts

Addressing Third-Party Risks: A Key Security Challenge Addressing Third-Party Risks: A Key Security Challenge The Hacker News
Hackers Use Facebook Ads to Spread JSCEAL Malware via Fake Cryptocurrency Trading Apps Hackers Use Facebook Ads to Spread JSCEAL Malware via Fake Cryptocurrency Trading Apps The Hacker News
UNC6148 Backdoors Fully-Patched SonicWall SMA 100 Series Devices with OVERSTEP Rootkit UNC6148 Backdoors Fully-Patched SonicWall SMA 100 Series Devices with OVERSTEP Rootkit The Hacker News
GhostAd Drain, macOS Attacks, Proxy Botnets, Cloud Exploits, and 12+ Stories GhostAd Drain, macOS Attacks, Proxy Botnets, Cloud Exploits, and 12+ Stories The Hacker News
Vercel Data Breach Linked to Context AI Compromise Vercel Data Breach Linked to Context AI Compromise The Hacker News
Linux KVM Bug Risks Host Security on Intel and AMD Linux KVM Bug Risks Host Security on Intel and AMD The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CenterPoint Energy Reports Customer Data Breach Incident
  • Hackuity Secures $19M to Boost AI Vulnerability Management
  • Browser Extension Risks AI Assistant Security
  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CenterPoint Energy Reports Customer Data Breach Incident
  • Hackuity Secures $19M to Boost AI Vulnerability Management
  • Browser Extension Risks AI Assistant Security
  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark