Code Defence Cyber security

PaperCut releases second emergency patch for chained zero day flaws CVE-2026-82078 and CVE-2026-81578

Commercial print management software maintainers have deployed a second emergency security update after security researchers demonstrated multiple bypasses for initial zero-day hotfixes. Adversaries are actively chaining authentication bypass logic errors with unsafe class loading subroutines to execute arbitrary Java code on backend application servers.

The attack chain impacts PaperCut NG and PaperCut MF software releases across Windows, Linux, and macOS platforms. The exploits combine web management interface authentication bypass CVE-2026-81578 with unsafe dynamic class loading flaw CVE-2026-82078 in database connection utilities. Unauthenticated attackers transmit hex-encoded Java class files within server logs to bridge execution into the underlying operating system, running reconnaissance and shell commands under application daemon privileges.

Compromising central print management servers introduces severe internal network exposure and credential theft risks. Because print servers maintain active directory service connections and process confidential business documents, an unauthenticated host takeover allows threat actors to extract service credentials, capture print streams, and execute lateral movement routines.

– Apply PaperCut Emergency Patch Release 2 immediately across all PaperCut NG and MF application, site, and secondary servers.

– Upgrade instances running version 23 or earlier directly to current patched builds, as legacy branches do not receive backported hotfixes.

– Inspect application server logs for hex-encoded Java .class payloads or unverified administrative session triggers.

– Enforce network access control lists to restrict web management interface access exclusively to trusted internal administrative IP pools.

Print infrastructure resilience requires prompt patch deployment and strict class validation to ensure enterprise management servers remain insulated from unauthenticated remote code execution. #CodeDefence #PaperCut #ZeroDay #RCE #AuthBypass #JavaSecurity #PrintSecurity #AppSec
/

Scroll to Top