Threat Intelligence • CVE-2026-81578 • CVE-2026-82078

From CVE Feed to Action: Responding to Actively Exploited PaperCut Vulnerabilities

A useful security feed does not stop at “critical vulnerability.” It helps an organisation recognise a relevant product, known exploitation and credible impact—then turn those signals into an asset, exposure, containment, patching and investigation decision.

Current status: CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalogue on 31 August 2026. PaperCut reports confirmed customer incidents and published Emergency Patch Release 3 on 1 September, superseding earlier emergency patches.

Trends4You Editorial

Why the feed elevated it

Known exploitation changes the order of work

A high CVSS score describes technical severity; it does not prove that an organisation runs the affected product or that an attacker can reach it. This alert becomes operationally important when several pieces of evidence align:

Relevant technology

The organisation uses PaperCut NG or PaperCut MF, rather than an unaffected PaperCut product or no PaperCut service at all.

Known exploitation

CISA KEV and PaperCut's confirmed customer incidents show that exploitation is not merely theoretical.

Credible attack chain

An authentication bypass can allow configuration changes that make the unsafe dynamic-class-loading weakness exploitable.

Reachable service

An internet-accessible Application Server presents the clearest urgent exposure, although internal reachability and prior access still require assessment.

The feed creates a review—not a verdict

Known exploitation + product match + reachable service + high consequence warrants urgent action. If the product is absent or the identified component is unaffected, record that evidence and close the item rather than performing unnecessary change.

Confirmed technical picture

Two vulnerabilities can form one attack path

VulnerabilityConfirmed effect
CVE-2026-81578
CVSS 4.0: 8.8
Missing authentication for a critical function. Under specific conditions, an unauthenticated remote request can trigger administrative backend actions and modify certain system configurations.
CVE-2026-82078
CVSS 4.0: 9.4
Unsafe dynamic class loading in database-connection utilities. If configuration can be manipulated, arbitrary Java bytecode on the classpath can execute as the PaperCut server process.
Combined consequenceThe first weakness can provide the configuration change needed to reach the second, creating a credible unauthenticated route to code execution against a reachable vulnerable Application Server.

Product scope matters

PaperCut's active advisory applies to all versions of PaperCut NG and PaperCut MF. It states that PaperCut Hive, PaperCut Pocket, Mobility Print and Print Deploy server components are not affected by this bulletin.

Response workflow

Move from the feed card to seven evidence-led actions

1

Confirm the product and architecture

Identify PaperCut NG or MF Application Servers, operating systems, versions, hosting locations, owners and business purpose. Include Site Servers and secondary or print servers rather than checking only the primary server.

2

Establish exposure

Determine whether any PaperCut web interface is reachable from the public internet, directly or through a proxy, published service or firewall rule. Record internal routes and administrative access as well.

3

Restrict public access immediately

PaperCut instructs customers with internet-accessible Application Servers to restrict web access to trusted IP addresses using firewall, network-access or equivalent controls—even where no suspicious activity has been observed.

4

Consult the live advisory and apply the latest response

As of 1 September, Emergency Patch Release 3 supersedes Releases 1 and 2 and is cumulative. PaperCut provides it for versions 24, 25 and 26; customers on version 23 or earlier are directed to upgrade to the latest version. Recheck the advisory before acting because an official maintenance release is still in progress.

5

Preserve and review evidence

Retain relevant PaperCut logs, endpoint and network alerts, timelines and change records before they are overwritten. Review the vendor's current indicators and investigate suspicious behaviour from the Application Server process.

6

Patch every required server and validate

PaperCut says Site Servers and secondary or print servers should also be updated to a patched version. Confirm service health, version or build, authentication, print workflows and any external card lookup after change.

7

Escalate suspected compromise

Do not treat patching as eradication. Activate incident response, protect evidence and make containment decisions with service continuity in mind. PaperCut recommends securing current backups, wiping and rebuilding a suspected Application Server, and restoring a clean backup from before the suspicious activity.

Compromise assessment

Check security telemetry as well as PaperCut logs

PaperCut's indicator list is evolving. Use the live advisory as the authoritative source and preserve enough evidence to support further investigation. Current examples include:

Application processEndpoint or network alerts involving pc-app.exe or pc-app, particularly unexpected child shell processes or other post-exploitation activity.
Log integrityMissing, unexpectedly truncated or deleted server.log files, together with the database-related strings listed in the vendor advisory.
Unexpected filesUnfamiliar class, command or output files in the PaperCut server paths identified by PaperCut.
Remote-access persistenceAn unexpected “Remote Access Service,” SimpleService.exe or AnyDesk installation on the server.
Security controlsEndpoint-isolation events, blocked execution, suspicious process chains, new services and unusual outbound connections originating from the Application Server.

Absence of an indicator is not proof of safety

PaperCut notes that attackers may remove files and that environments differ. Combine available indicators with exposure, timing, endpoint telemetry, network evidence and the integrity of the server. Seek specialist incident-response support where the evidence or consequence warrants it.

Finish the response

Record both technical and operational assurance

CoverageEvery NG/MF Application Server, Site Server and secondary or print server has an owner and recorded disposition.
ExposureInternet reachability has been removed or restricted and independently rechecked from the relevant network location.
RemediationThe latest vendor response has been applied or a dated exception and compensating control has been authorised.
Service healthAuthentication, printing, SAML and any external Card/ID lookup work after change, including the scenarios affected by earlier emergency-patch regressions.
InvestigationAvailable logs and security telemetry have been reviewed for the relevant period, with uncertainties and escalation decisions recorded.
Follow-upAn owner is assigned to monitor the live advisory and move from the emergency patch to the official release when appropriate.

What the feed demonstrated

Prioritisation needs context, not vulnerability volume

Turn a signal into a decision

Detect → match assets → assess exposure → contain → remediate → investigate → evidence

The homepage feed surfaced exploitation and KEV status. Local product knowledge and service context then determine whether the item becomes an urgent incident, a controlled patch, a documented non-exposure or no action.

This is why the RACF-CC prioritisation tool does not treat a headline score as the complete decision. Exploitation evidence, exposure, service consequence, control coverage and uncertainty all matter.

RACF-CC alignment

One alert crosses several control domains

Use Domain 4 to identify, prioritise and remediate the vulnerable servers; Domain 3 to remove unnecessary exposure; Domain 6 to review and retain meaningful evidence; and Domain 7 when compromise is suspected. Domain 8 records ownership, exceptions and residual uncertainty.

Protect continuity while containing risk

Print services can support prescriptions, labels, care records, finance and day-to-day operations. Restricting or rebuilding a server may be necessary, but the decision should include an approved fallback and accountable service owner.

Primary sources

Live guidance and vulnerability records

Last checked: 1 September 2026. PaperCut describes the advisory as active and is preparing a quality-assured maintenance release. Recheck the vendor bulletin immediately before making a technical change.

Voluntary support

Found this useful? Support Trends4You

Trends4You's practical guides, RACF-CC resources and downloadable tools are provided free of charge. If they've helped you or your organisation, you can support the time and hosting that keeps them freely available.

Support is optional, handled securely by Stripe and does not provide additional access.