PaperCut CVE-2026-81578 and CVE-2026-82078: A Two-Flaw Chain That Ran at Agent Speed
The two entries and the deadline
CISA added CVE-2026-81578 and CVE-2026-82078 to the Known Exploited Vulnerabilities catalog on 2026-08-31, both with a federal remediation deadline of 2026-09-14. The catalog names the first a missing authentication for critical function vulnerability and the second an unsafe reflection vulnerability, both in PaperCut NG/MF.
NVD rates CVE-2026-81578 at 9.8 with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H and describes an improper access control vulnerability in the web management interface of PaperCut MF and PaperCut NG. CVE-2026-82078 is rated 9.1 with the vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H and describes unsafe dynamic class loading in the database connection utilities, which is the part that turns a configuration change into executable code in the application process.
How the chain works and why the second flaw matters
The access control flaw allows unauthenticated requests to reach management functionality in the web interface before authorization is evaluated. The first flaw is the way in. The class loading flaw is the payload path: the database connection utility instantiates a driver class named in configuration without validating it against an allowlist. Change the configuration through the first flaw, and the second flaw then loads a class the attacker controls.
The result is code execution inside the paper management service. On Windows deployments this service commonly runs as SYSTEM, which makes the printing server an unusually direct route into the rest of the domain.
What made this campaign different
Public reporting on this campaign describes a foreign agent operated intrusion that reached hundreds of internet-exposed instances across dozens of countries in a short period, with education among the most affected sectors. The observed tooling is standard for this kind of operation: credential extraction from memory and the registry, lateral movement using the credentials obtained, and directory database replication to collect account material.
The distinguishing feature described in the reporting is not a novel technique. It is throughput. When the entire chain is automatable and the target list is public, the limiting factor becomes how quickly the operator can iterate rather than how many analysts it can employ.
Remediation and configuration verification
Upgrade to a fixed PaperCut NG/MF release. The vendor shipped emergency patches for the affected branches and later a further patch for systems that had already applied an earlier one, so confirm the currently recommended patch level rather than the first one published.
Then verify the configuration that the chain depends on. The class loading flaw is reachable through the database connection settings, so review the database driver configuration for values that do not correspond to a supported database, and check the application's configuration files for driver or class names that administrators did not set.
Investigation priorities
This chain leads to credentials. Prioritize the questions that follow from that: which accounts the service could read, whether administrative control over the host was achieved, whether credentials from the host were used elsewhere, and whether directory service accounts need rotation. Because the service commonly runs with high privilege and is joined to the domain, the credentials it holds are worth more than the print data it manages.
Retention matters as well. Attackers who obtain administrative control select what the host records. Export application and operating system logs to a system the PaperCut host cannot modify, and preserve authentication records for long enough to answer questions about a campaign that ran weeks ago.
Reading the reporting responsibly
Public accounts of this campaign describe tooling and outcomes rather than providing a complete intrusion narrative, and the number of affected organizations continues to be revised. What can be stated with confidence is narrower than the reporting and enough for planning: two flaws in a widely deployed self-hosted service can be chained into pre-authentication code execution, the service usually holds domain-relevant privilege, and the exploited list entry carries a deadline that has already passed.
References
- CISA Known Exploited Vulnerabilities Catalog, catalog version 2026.09.23: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- NVD, CVE-2026-81578 (CVSS 3.1 base 9.8): https://nvd.nist.gov/vuln/detail/CVE-2026-81578
- NVD, CVE-2026-82078 (CVSS 3.1 base 9.1): https://nvd.nist.gov/vuln/detail/CVE-2026-82078
- PaperCut product and patch information: https://www.papercut.com/
Top comments (0)