Vulnerability
Published 2026-08-27
Verified 2026-09-19

PaperCut NG/MF: MR 26.0.5/25.0.13/24.1.10 replace EPR; AI-agent wave; KEV (CVE-2026-82078/81578)

PaperCut Software's 27 August 2026 (AEST) security bulletin, last updated 10 September 2026, published Security Maintenance Releases on 10 Sep 2:00pm AEST: NG/MF 26.0.5, 25.0.13 and 24.1.10 are Regular Maintenance Releases that completed full QA, include all fixes from Emergency Patch Releases 1–3 plus extra hardening, and replace the emergency patches as the recommended builds. Earlier context: says its response team is investigating active exploitation of PaperCut NG and PaperCut MF, with confirmed customer incidents. The advisory applies to all versions of both products. Immediate action: if the Application Server is reachable from the public internet, restrict web access to trusted addresses now. Emergency Patch Release 2 went out for NG/MF v24, v25 and v26 (Windows, Linux and macOS) with extra hardening after work with Huntress and watchTowr. Versions before v24 should upgrade to the latest. The bulletin lists CVE-2026-82078 (unsafe dynamic class loading in the database connector, CVSS 4.0 9.4 Critical) and CVE-2026-81578 (authentication bypass that can let an unauthenticated remote attacker modify certain system configurations, CVSS 4.0 8.8 High). Site Servers and secondary/print servers should be updated, not only the primary Application Server. Print Deploy and Mobility Print are not affected. Vendor-listed possible indicators include suspicious post-exploitation from pc-app.exe; missing, truncated or deleted server.log files; and server.log lines "ERROR No suitable driver found for jdbc:no:x" or "ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST". Absence of those lines is not proof the server is clean. On 29 August 4:35pm AEST PaperCut added that some sites report the external-database Card/ID number lookup feature and SAML are not working as expected after the patch. Card/ID lookup from an external database is off by default after Release 2; sites that still need it must set security.card-number-lookup.enabled=Y in server/security.properties and restart the Application Server. On 30 August 10:34am AEST the vendor said customers using SQL Server for external card lookups with the legacy SourceForge jTDS driver should move to the latest supported Microsoft SQL JDBC driver; engineering is still working toward an official release and support remains available. On 30 August 3:35pm AEST PaperCut added further indicators of compromise: server.log strings such as DB URL jdbc:derby:memory:pwn;create=true, Database error looking up cardID: VALUES CAST(X'cafebabe, Database error looking up cardID: VALUES CAST(', and DB URL jdbc:no:x with a 5-character random DB Driver name; files under install/server/lib/<5-char-name>.class and install/server/data/content/<5-char-name>.cmd or .out (attackers may remove those files). Observed post-compromise behaviour includes pc-app.exe or pc-app spawning cmd.exe for whoami and ver, then reconnaissance and downloads of remote-access tooling (including a Windows service named Remote Access Service running SimpleService.exe from a JWrapper-Remote Access path, and unexpected AnyDesk under C:/ProgramData). Absence of those indicators is not proof a server is clean. On 31 August 2026 4:21pm AEST PaperCut posted a status update with no new technical information. On 1 September 2026 11:18am AEST it added FAQ clarifications, and at 2:10pm AEST it added build numbers to download links. PaperCut published Emergency Patch (Release 3) on 1 September 2026 at 6:22pm AEST. It supersedes Release 2, is an accumulation of all emergency releases, addresses two known regressions (broken SAML login flows; restored support for legacy Microsoft SQL Server drivers for external card lookup), and adds additional hardening and mitigation against potential attack chains. Customers with internet-facing Application Servers should install Release 3 even if they already applied Release 2 or an earlier emergency release. Download tables now show R3 builds (MF v26 76531, v25 76532, v24 76534; NG v26 76530, v25 76533, v24 76535). BleepingComputer (1 September) reported that Defused observed CVE-2026-81578 / CVE-2026-82078 honeypot activity since late 29 August UTC; an actor abused the auth bypass to hijack PaperCut's external user-lookup and dump database tables via Derby (a data-theft path, distinct from the public RCE writeups). SecurityWeek (1 September) quoted WatchTowr's Jake Knott: activity has shifted from exploratory probes to hands-on-keyboard exploitation, with attackers keying in-memory payloads so only they can reuse the host; WatchTowr says that looks like initial-access-broker or other aggressive-outcome operators. CISA added CVE-2026-81578 and CVE-2026-82078 to the Known Exploited Vulnerabilities catalog on 31 August 2026. WA SOC advisory 20260901001 (1 September, TLP:CLEAR) points operators at the same vendor bulletin, lists the two CVEs (CVSS 9.4 and 8.8), and says it has not received reports of exploitation on Western Australian Government networks at the time of writing. On 2 September 2026 at 4:38pm AEST PaperCut added an 'Updates from the field' note to Current Status: it says a second wave of attacks is hitting servers that are not fully patched and remain publicly available, and that this wave appears to involve more sophisticated post-compromise behaviour than the first days of the incident. The vendor again stresses installing Emergency Patch Release 3 or keeping the Application Server off the public internet. Bulletin page header last-updated date moved to 5 September 2026; Current Status at 5 September 2026 10:30am AEST reported no new vendor technical information (work continues toward the official release); EPR3 remains the current emergency build (no EPR4 in this update). The Hacker News (5 September 2026) summarises Arctic Wolf Adversary Research Team observations: attackers exploiting CVE-2026-81578 and CVE-2026-82078 against education-sector PaperCut servers in the United States and Europe (K-12 through universities) for command execution, reconnaissance and privileged-account creation, with post-exploitation including Windows registry hive collection tools (including lsa_collect.exe used to reconstruct BootKey/SAM access paths), Metasploit/Meterpreter-related Java payloads, and host/user/process enumeration. Arctic Wolf published related pack alerts at github.com/rtkwlf/wolf-tools (202609-papercut-cve-exploitation). Still: keep Application Servers off the public internet or on EPR3; monitor pc-app.exe spawning cmd.exe/powershell and the vendor IoCs already on this card. NEW 10 September 2026 (BleepingComputer citing GreyNoise; The Hacker News also citing Blackpoint Cyber): a likely Russian-speaking actor used hundreds of AI agents (OpenAI Codex and DeepSeek plus commodity tools) to build and refine exploits for CVE-2026-81578 and CVE-2026-82078, generating target lists via Netlas. GreyNoise reports at least 440 PaperCut instances at 395 organisations across 48 countries compromised; credentials from 280 victims, OS/domain secrets from 147, and administrator privileges at 12 organisations; roughly half of victims in education; top countries US, UK, France, Spain, Canada. First RCE under four hours from an empty workspace; domain admin about two hours later. Still: EPR3 or take Application Servers off the public internet; monitor the vendor IoCs already on this card.

Product
PaperCut NG and PaperCut MF
Versions
All versions of NG and MF
CVSS
(CVE-2026-82078, CVSS 4.0, PaperCut); 8.8 (CVE-2026-81578, CVSS 4.0)
Exploited in Australia?
unknown
Patch to
Install Regular Maintenance Releases 26.0.5 / 25.0.13 / 24.1.10 (replace all EPRs); restrict public web access; upgrade pre-v24 to latest

Primary: PaperCut security bulletin (27 Aug 2026) · Vendor: PaperCut (vendor) · CVE: CVE-2026-82078, CVE-2026-81578 · CISA KEV (31 Aug 2026)

vulnerabilities australia