Code Defence Cyber security

CISA adds chained PaperCut NG and MF zero day flaws CVE-2026-81578 and CVE-2026-82078 to KEV catalog

Federal cybersecurity regulators have formally added two chained vulnerabilities in a commercial print management platform to the Known Exploited Vulnerabilities catalog. Threat actors are weaponizing the flaws in wild attack campaigns to execute arbitrary Java code and extract sensitive enterprise print archives.

The catalog additions cover authentication bypass vulnerability CVE-2026-81578 and unsafe reflection vulnerability CVE-2026-82078 affecting PaperCut NG and PaperCut MF software. Threat actors chain the authentication bypass to modify server configuration settings, subsequently abusing unsafe class loading routines to execute arbitrary Java bytecode under the PaperCut service account context. Attackers actively target the print archiving feature to exfiltrate printed document contents. CISA mandated federal compliance under Binding Operational Directive 26-04 with a September 14 deadline.

Compromising central print management servers creates severe internal data privacy and host security exposure. Because print servers hold active directory service credentials and store unencrypted print job archives, an unauthenticated host compromise permits threat actors to extract confidential corporate documents and execute lateral movement routines.

– Force immediate installation of PaperCut Emergency Patch Release 2 across all application and secondary print servers.

– Restrict management interface access exclusively to trusted internal administrative IP pools using network access control lists.

– Inspect print server process logs for anomalous Java bytecode executions or unauthorized print archiving configuration modifications.

– Audit active directory service accounts bound to PaperCut daemons to enforce least-privilege operational rights.

Print infrastructure defense demands rapid security patch application and strict class loading isolation to ensure commercial print servers remain protected from unauthenticated remote code execution. #CodeDefence #PaperCut #ZeroDay #RCE #AuthBypass #CISA #KEV #PrintSecurity
/

Scroll to Top