HomeMalware & ThreatsAttackers Actively Exploiting Vulnerabilities in PaperCut NG/MF

Attackers Actively Exploiting Vulnerabilities in PaperCut NG/MF

Published on

spot_img

Vendor Issues Second Set of Emergency Patches for Printer Management Software

On August 31, 2026, the well-known printer management software provider, PaperCut, took a significant step in addressing major security concerns by issuing two urgent patches as it faces ongoing exploitation of zero-day vulnerabilities in its products. The vulnerabilities have sparked considerable alarm within the cybersecurity community due to their potential to be exploited by attackers.

The urgency of this situation was outlined by PaperCut’s security response team, which stated, "We are aware of confirmed customer incidents and are treating this matter with the highest priority." This highlights the company’s commitment to safeguarding its customer base while they actively investigate the vulnerability impacting both PaperCut NG and PaperCut MF software. The security advisory was updated, underscoring the critical nature of this ongoing situation.

PaperCut serves a vast user base, with 100 million end users relying on its software, which facilitates the self-management of printers and multifunction devices. The software is prevalent across varied environments, ranging from large enterprises and universities with extensive user bases exceeding 100,000 to smaller organizations managing fewer than 50 users and a handful of printers. This broad usage makes the vulnerabilities particularly concerning, as they may affect a diverse spectrum of organizations.

At the heart of the cybersecurity threat is the potential for an unauthenticated attacker to exploit these vulnerabilities, thereby bypassing authentication protocols to gain remote code execution capabilities on affected instances. As articulated by the cybersecurity firm watchTowr, the situation is alarming, especially since exploitation is already occurring in real-world scenarios.

The vulnerabilities identified by PaperCut are said to affect all versions of their PaperCut NG and MF Application Server. In response to the crisis, the company initially released emergency patches for versions 25 and 26. Subsequently, they issued an updated set of patches that also included support for version 24, which was first introduced in October 2024. To further assist organizations in their defense, PaperCut provided indicators of compromise, enabling them to hunt for signs of possible breaches.

However, according to cybersecurity firm Huntress, a troubling statistic emerged from its analysis: nearly half of the approximately 2,500 installations of PaperCut that it monitors were operating on version 23 or earlier, versions released in October 2023 or prior, which lack available patches. Consequently, PaperCut has urged its customers to upgrade their software promptly as a preventive measure.

In addition to suggesting software upgrades, PaperCut offered valuable mitigation advice. Organizations are encouraged to restrict web access to trusted IP addresses only—specifically internal IP addresses—especially for any version of their software that is accessible via the public internet. Implementing network access controls and firewall rules is advised to prevent the PaperCut server’s web interfaces from being accessed by untrusted sources.

The emergency patches released by PaperCut address two significant flaws: CVE-2026-82078, which involves unsafe dynamic class loading in the database connector with a critical CVSS score of 9.4, and CVE-2026-81578, an improper access control vulnerability within the web management interface of the software with a high CVSS score of 8.8. The company emphasized the necessity for all its customers to install the second patch release, titled "Emergency Patch Release 2," even if the first patch had already been applied.

This second release reportedly includes additional hardening measures discovered through research collaboration with Huntress and watchTowr. This collaborative effort will provide enhanced protection for customers unable to restrict access to their PaperCut installations from public-facing networks.

WatchTowr indicated that following PaperCut’s initial disclosure of the vulnerabilities, their team was able to reproduce the issues and identify multiple bypass methods, including an additional authentication bypass vulnerability. All findings were shared with PaperCut, indicating a proactive approach to cybersecurity.

Furthermore, Huntress has developed a proof-of-concept exploit based on these vulnerabilities and has identified at least two of its clients who had already been targeted with exploits. These alarming findings highlighted post-exploitation activities, with base64-encoded commands executed on targeted servers aimed at discerning user account details and operating systems.

Notably, this is not the first time serious vulnerabilities have been uncovered in PaperCut’s management software. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has previously identified multiple vulnerabilities within PaperCut NG/MF, with some being actively targeted by ransomware attacks in the past. As threats continue to evolve, organizations utilizing PaperCut are advised to stay vigilant and proactive in their cybersecurity measures.

Source link

Latest articles

Debian Approves AI-Assisted Coding Use

The Debian Linux distribution community has officially embraced a new policy that allows the...

Aurora Ransomware Hackers Employ Cursor AI Agent for Direct Exploitation and ESXi Attacks

Aurora Ransomware Leverages AI-Driven Tools to Target Victim Organizations Recent investigations have revealed alarming activities...

Cyber Briefing – August 31, 2026: CyberMaterial

Cybersecurity Threats on the Rise: Key Incidents and Insights In recent developments, the cybersecurity landscape...

Chrome and Edge Extensions Bypass CSP and Inject JavaScript to Compromise EVM, Solana, and Tron Wallets

Investigation Uncovers Malicious Browser Extensions Targeting Google Chrome and Microsoft Edge Users A recent investigation...

More like this

Debian Approves AI-Assisted Coding Use

The Debian Linux distribution community has officially embraced a new policy that allows the...

Aurora Ransomware Hackers Employ Cursor AI Agent for Direct Exploitation and ESXi Attacks

Aurora Ransomware Leverages AI-Driven Tools to Target Victim Organizations Recent investigations have revealed alarming activities...

Cyber Briefing – August 31, 2026: CyberMaterial

Cybersecurity Threats on the Rise: Key Incidents and Insights In recent developments, the cybersecurity landscape...