CVE Tools
Back to feed
Exploited in the wild PaperCut rce auth-bypass

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

The Hacker News·By The Hacker News··4 min read
CVE Tools coverage

Threat actors are actively exploiting a combination of two newly disclosed vulnerabilities in PaperCut NG and MF to achieve remote code execution without authentication. By chaining the improper access control flaw (CVE-2026-81578, CVSS 8.8) with an unsafe dynamic class loading issue (CVE-2026-82078, CVSS 9.4), attackers can bypass permission checks and execute arbitrary Java code on affected servers. PaperCut has released an emergency patch that includes additional hardening measures, and organizations are strongly advised to remove public exposure to these instances immediately while applying the update.