CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

August 28, 2026

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication Ravie LakshmananAug 28, 2026Vulnerability / Web Security Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. "This vulnerability gives an unauthenticated attacker remote control over PaperCut's trusted configuration, which could be used to execute arbitrary Java code inside the application's process," Huntress researchers John Hammond and Andrew Brandt said. Specifically, an attacker can leverage an unauthenticated request to make changes to the server configuration and ultimately achieve code execution. Huntress has explained the flaw as follows – In unpatched versions of PaperCut NG and PaperCut MF, a…

CVEs: CVE-2026-82078, CVE-2026-81578, CVE-2026-58231