CVE Tools
Back to feed
Exploited in the wild PaperCut NG zero-day PaperCut MF PaperCut rce

Хакеры атакуют 0-day-уязвимости в PaperCut

Хакер (xakep.ru)·By Мария Нефёдова··3 min read
CVE Tools coverage

Threat actors are actively exploiting two zero-day vulnerabilities in PaperCut NG and PaperCut MF to achieve remote code execution without authentication. The combined flaws involve an access control defect identified as CVE-2026-81578 and a dynamic class loading issue labeled CVE-2026-82078, allowing attackers to manipulate backend processes and load arbitrary Java bytecode. Because the initial urgent patch released on August 28, 2026, was incomplete, the vendor issued a second critical fix for Windows, Linux, and macOS users running versions 24 through 26. Administrators should immediately apply this latest update, remove the web interface from public networks, and restrict access to trusted IPs.