Exploited in the wild PaperCut NG zero-day PaperCut MF PaperCut rce
Хакеры атакуют 0-day-уязвимости в PaperCut
CVE Tools coverage
Threat actors are actively exploiting two zero-day vulnerabilities in PaperCut NG and PaperCut MF to achieve remote code execution without authentication. The combined flaws involve an access control defect identified as CVE-2026-81578 and a dynamic class loading issue labeled CVE-2026-82078, allowing attackers to manipulate backend processes and load arbitrary Java bytecode. Because the initial urgent patch released on August 28, 2026, was incomplete, the vendor issued a second critical fix for Windows, Linux, and macOS users running versions 24 through 26. Administrators should immediately apply this latest update, remove the web interface from public networks, and restrict access to trusted IPs.