Why the feed elevated it
Known exploitation changes the order of work
A high CVSS score describes technical severity; it does not prove that an organisation runs the affected product or that an attacker can reach it. This alert becomes operationally important when several pieces of evidence align:
Relevant technology
The organisation uses PaperCut NG or PaperCut MF, rather than an unaffected PaperCut product or no PaperCut service at all.
Known exploitation
CISA KEV and PaperCut's confirmed customer incidents show that exploitation is not merely theoretical.
Credible attack chain
An authentication bypass can allow configuration changes that make the unsafe dynamic-class-loading weakness exploitable.
Reachable service
An internet-accessible Application Server presents the clearest urgent exposure, although internal reachability and prior access still require assessment.
The feed creates a review—not a verdict
Known exploitation + product match + reachable service + high consequence warrants urgent action. If the product is absent or the identified component is unaffected, record that evidence and close the item rather than performing unnecessary change.
Confirmed technical picture
Two vulnerabilities can form one attack path
| Vulnerability | Confirmed effect |
|---|---|
| CVE-2026-81578 CVSS 4.0: 8.8 | Missing authentication for a critical function. Under specific conditions, an unauthenticated remote request can trigger administrative backend actions and modify certain system configurations. |
| CVE-2026-82078 CVSS 4.0: 9.4 | Unsafe dynamic class loading in database-connection utilities. If configuration can be manipulated, arbitrary Java bytecode on the classpath can execute as the PaperCut server process. |
| Combined consequence | The first weakness can provide the configuration change needed to reach the second, creating a credible unauthenticated route to code execution against a reachable vulnerable Application Server. |
Product scope matters
PaperCut's active advisory applies to all versions of PaperCut NG and PaperCut MF. It states that PaperCut Hive, PaperCut Pocket, Mobility Print and Print Deploy server components are not affected by this bulletin.
Response workflow
Move from the feed card to seven evidence-led actions
Confirm the product and architecture
Identify PaperCut NG or MF Application Servers, operating systems, versions, hosting locations, owners and business purpose. Include Site Servers and secondary or print servers rather than checking only the primary server.
Establish exposure
Determine whether any PaperCut web interface is reachable from the public internet, directly or through a proxy, published service or firewall rule. Record internal routes and administrative access as well.
Restrict public access immediately
PaperCut instructs customers with internet-accessible Application Servers to restrict web access to trusted IP addresses using firewall, network-access or equivalent controls—even where no suspicious activity has been observed.
Consult the live advisory and apply the latest response
As of 1 September, Emergency Patch Release 3 supersedes Releases 1 and 2 and is cumulative. PaperCut provides it for versions 24, 25 and 26; customers on version 23 or earlier are directed to upgrade to the latest version. Recheck the advisory before acting because an official maintenance release is still in progress.
Preserve and review evidence
Retain relevant PaperCut logs, endpoint and network alerts, timelines and change records before they are overwritten. Review the vendor's current indicators and investigate suspicious behaviour from the Application Server process.
Patch every required server and validate
PaperCut says Site Servers and secondary or print servers should also be updated to a patched version. Confirm service health, version or build, authentication, print workflows and any external card lookup after change.
Escalate suspected compromise
Do not treat patching as eradication. Activate incident response, protect evidence and make containment decisions with service continuity in mind. PaperCut recommends securing current backups, wiping and rebuilding a suspected Application Server, and restoring a clean backup from before the suspicious activity.
Compromise assessment
Check security telemetry as well as PaperCut logs
PaperCut's indicator list is evolving. Use the live advisory as the authoritative source and preserve enough evidence to support further investigation. Current examples include:
pc-app.exe or pc-app, particularly unexpected child shell processes or other post-exploitation activity.server.log files, together with the database-related strings listed in the vendor advisory.SimpleService.exe or AnyDesk installation on the server.Absence of an indicator is not proof of safety
PaperCut notes that attackers may remove files and that environments differ. Combine available indicators with exposure, timing, endpoint telemetry, network evidence and the integrity of the server. Seek specialist incident-response support where the evidence or consequence warrants it.
Finish the response
Record both technical and operational assurance
What the feed demonstrated
Prioritisation needs context, not vulnerability volume
Turn a signal into a decision
Detect → match assets → assess exposure → contain → remediate → investigate → evidenceThe homepage feed surfaced exploitation and KEV status. Local product knowledge and service context then determine whether the item becomes an urgent incident, a controlled patch, a documented non-exposure or no action.
This is why the RACF-CC prioritisation tool does not treat a headline score as the complete decision. Exploitation evidence, exposure, service consequence, control coverage and uncertainty all matter.
RACF-CC alignment
One alert crosses several control domains
Use Domain 4 to identify, prioritise and remediate the vulnerable servers; Domain 3 to remove unnecessary exposure; Domain 6 to review and retain meaningful evidence; and Domain 7 when compromise is suspected. Domain 8 records ownership, exceptions and residual uncertainty.
Protect continuity while containing risk
Print services can support prescriptions, labels, care records, finance and day-to-day operations. Restricting or rebuilding a server may be necessary, but the decision should include an approved fallback and accountable service owner.
Primary sources
Live guidance and vulnerability records
- PaperCut: Urgent Security Advisory for PaperCut NG/MF — the live source for current patches, affected components, indicators and response guidance.
- CISA: Two vulnerabilities added to the Known Exploited Vulnerabilities catalogue — active-exploitation status and KEV response context.
- CVE record: CVE-2026-81578 — authentication-bypass description and affected product data.
- CVE record: CVE-2026-82078 — unsafe dynamic-class-loading description and affected product data.
- CERT-FR: Multiple vulnerabilities in PaperCut — national CERT summary of risk, mitigation and compromise indicators.
Last checked: 1 September 2026. PaperCut describes the advisory as active and is preparing a quality-assured maintenance release. Recheck the vendor bulletin immediately before making a technical change.
Voluntary support
Found this useful? Support Trends4You
Trends4You's practical guides, RACF-CC resources and downloadable tools are provided free of charge. If they've helped you or your organisation, you can support the time and hosting that keeps them freely available.
Support is optional, handled securely by Stripe and does not provide additional access.
