AI DRAFT / HUMAN REVIEW

This briefing was produced by AI from the linked sources and is scheduled for human editorial review within 24 hours. Read the sources directly for material decisions.

EVIDENCE — CISA added CVE-2026-81578 and CVE-2026-82078 to its Known Exploited Vulnerabilities catalog on 31 August 2026 and set 14 September as the federal remediation date. PaperCut says it is investigating active exploitation of PaperCut NG and PaperCut MF and is aware of confirmed customer incidents. CISA records ransomware use as unknown, and neither CISA nor PaperCut identifies a single campaign, complete victim count, or universal post-compromise pattern.

THE CHAIN — CVE-2026-81578 is a missing-authentication flaw in the web management interface. PaperCut says that, under specific conditions, unauthenticated requests to administrative functions can trigger backend actions before access validation finishes, allowing certain configuration changes. CVE-2026-82078 sits behind that boundary: the database utilities can instantiate driver classes named in configuration without checking an approved allowlist. Chained together, control of configuration can become execution of arbitrary Java bytecode already placed on the application classpath under the PaperCut server process.

THE PATCH IS STILL AN EMERGENCY BUILD — PaperCut treats every version of NG and MF as potentially affected. Emergency Patch Release 2 is available for major versions 24, 25, and 26, and the vendor says to install it even if Release 1 was already applied. Customers on version 23 or earlier are directed to upgrade to the latest version. PaperCut says Application Servers, Site Servers, and secondary or print servers need a patched version; Print Deploy and Mobility Print are not affected. As of its 31 August update, the vendor was still working toward an official release, so defenders must keep watching the bulletin after applying the emergency patch.

OBSERVED EVIDENCE CAN DISAPPEAR — PaperCut reports suspicious child shells launched by pc-app, unexpected Java class and command-output files, altered or deleted server logs, system-discovery commands, and—in some incidents—installation of SimpleHelp or AnyDesk remote-access tooling. Huntress separately reports reproducing the pre-authentication execution chain and observing exploitation in two customer environments. Both sources warn, in effect, against treating a missing file or string as proof of safety: the attacker’s class can delete output and logs as it runs, and behavior differs by environment.

WHAT TO CHECK — Immediately restrict PaperCut Application Server web access to trusted addresses, even before patching. Inventory every NG and MF Application Server, Site Server, and secondary server; preserve the complete log directory, file metadata, configuration, endpoint process trees, network records, services, and autoruns before an upgrade or restart changes evidence; then install Release 2 using PaperCut’s official packages and verify every server actually runs the patched build. Review pc-app or Java spawning shells, unexpected five-character class or command files, missing or truncated server.log data, unfamiliar remote-access services, and configuration changes. If compromise is suspected, PaperCut recommends securing current backups, wiping and rebuilding the Application Server, and restoring a clean backup from before suspicious activity. Editorial view: authorization that runs after an action is not a boundary—it is an audit note.

Published 31 AUG 2026Back to Daily Briefs